This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log - Cleanup Tips Requested

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.97.7
Scan saved at 1:23:55 PM, on 11/23/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe
C:\WINDOWS\system32\??chost.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLServiceHost.exe
C:\Program Files\SmartPopupBlocker\SmartPopupBlockerTray.exe
C:\WINDOWS\system32\XtawJ.exe
C:\WINDOWS\system32\Sdj6LsN.exe
C:\WINDOWS\system\eulamain.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Martin Fischler\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50093
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: (no name) - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\Program Files\SmartPopupBlocker\PopupBlockerBHO.dll
O2 - BHO: (no name) - {4D8B1227-9A32-5BCE-DD05-615509F1284B} - C:\WINDOWS\system32\bmxpalyr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_066b.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\niamalue.dat
O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\picbdo.dat
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Eda76.exe
O4 - HKLM\..\Run: [inetmp3] C:\WINDOWS\inetmp3.exe
O4 - HKLM\..\Run: [*inetmp3] C:\WINDOWS\inetmp3.exe
O4 - HKLM\..\Run: [*bascat] C:\WINDOWS\security\logs\bascat.exe
O4 - HKLM\..\Run: [*wavedos] C:\WINDOWS\wavedos.exe
O4 - HKLM\..\Run: [*svrsvc] C:\WINDOWS\msagent\chars\svrsvc.exe
O4 - HKLM\..\Run: [*kbrun] C:\WINDOWS\system\kbrun.exe
O4 - HKLM\..\Run: [*dnsexp] C:\WINDOWS\Cursors\dnsexp.exe
O4 - HKLM\..\Run: [*crbas] C:\WINDOWS\Tasks\crbas.exe
O4 - HKLM\..\Run: [drvfont] C:\WINDOWS\drvfont.exe
O4 - HKLM\..\Run: [*netxml] C:\WINDOWS\system\netxml.exe
O4 - HKLM\..\Run: [*nutbin] C:\WINDOWS\system\nutbin.exe
O4 - HKLM\..\Run: [*anticr] C:\WINDOWS\security\Database\anticr.exe
O4 - HKLM\..\Run: [*doskey] C:\WINDOWS\msagent\doskey.exe
O4 - HKLM\..\Run: [*inetmain] C:\WINDOWS\security\inetmain.exe
O4 - HKLM\..\Run: [*odbcip] C:\WINDOWS\msagent\chars\odbcip.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [zeozuh] C:\WINDOWS\rpwsib.exe
O4 - HKLM\..\Run: [rfq] C:\documents and settings\martin fischler\local settings\temp\rfq.exe
O4 - HKLM\..\Run: [rbddublka] C:\WINDOWS\System32\ddawua.exe
O4 - HKLM\..\Run: [qsng3mh] acldmgr.exe
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [mswspl] C:\WINDOWS\rpwsib.exe
O4 - HKLM\..\Run: [mipropw] C:\WINDOWS\System32\mipropw.exe
O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AutoLoaderqF461acTIKaW] "C:\WINDOWS\System32\iyuaysvr.exe" /PC="AM.WILD" /HideUninstall
O4 - HKLM\..\Run: [d53] C:\documents and settings\martin fischler\local settings\temp\d53.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"
O4 - HKLM\..\Run: [*inetwin] C:\WINDOWS\Fonts\inetwin.exe
O4 - HKLM\..\Run: [7Eix18] c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe
O4 - HKLM\..\Run: [*eulamain] C:\WINDOWS\system\eulamain.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100877459\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [bB4mRgN7T] reft01.exe
O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe
O4 - HKCU\..\Run: [Gqfnvt] C:\WINDOWS\system32\??chost.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKLM\..\RunOnce: [*eulamain] C:\WINDOWS\system\eulamain.exe rerun
O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\abrfax.exe ren time:1101135485
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: AOL Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/d/4…0367/wmavax.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
Greetings and welcome to TomCoyote.org!

You have a "Stopguard" infection. Please do not reboot until told to do so. Each reboot can make the infection harder to remove.

If you have rebooted since you posted the log, DO NOT ATTEMPT THIS FIX. Instead post another log file and leave your machine on.


Download Killbox.zip

Extract it from the zip file then double-click on Killbox.exe to run it. In the 'Paste Full Path of File to Delete' box, copy and paste this entry:

C:\DOCUMENTS AND SETTINGS\Martin Fischler\LOCAL SETTINGS\Temp\niamalue.dat

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". In the window that opens up, click on the File menu and choose "Add File". The file should show up in the window. Then repeat the process, this time adding:

C:\DOCUMENTS AND SETTINGS\Martin Fischler\LOCAL SETTINGS\Temp\picbdo.dat

If that's successful you should have the two files listed. Then repeat so that these files appear in the list as well:

C:\documents and settings\martin fischler\local settings\temp\rfq.exe
C:\documents and settings\martin fischler\local settings\temp\d53.exe
c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe
C:\WINDOWS\inetmp3.exe
C:\WINDOWS\wavedos.exe
C:\WINDOWS\drvfont.exe
C:\WINDOWS\Cursors\dnsexp.exe
C:\WINDOWS\Fonts\inetwin.exe
C:\WINDOWS\msagent\chars\odbcip.exe
C:\WINDOWS\msagent\chars\svrsvc.exe
C:\WINDOWS\msagent\doskey.exe
C:\WINDOWS\rpwsib.exe
C:\WINDOWS\security\Database\anticr.exe
C:\WINDOWS\security\inetmain.exe
C:\WINDOWS\security\logs\bascat.exe
C:\WINDOWS\system\abrfax.exe
C:\WINDOWS\system\kbrun.exe
C:\WINDOWS\system\eulamain.exe
C:\WINDOWS\system\netxml.exe
C:\WINDOWS\system\nutbin.exe
C:\WINDOWS\System32\ddawua.exe
C:\WINDOWS\System32\mipropw.exe
C:\WINDOWS\Tasks\crbas.exe
C:\WINDOWS\system32\hostx.exe

When they are all there (and double check!), in the same window choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

Please download the latest version of Hijack This!

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://spywarewarrior.com/files/HijackThis.exe
http://tomcoyote.org/hjt/HijackThis.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50093

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50093

O2 - BHO: (no name) - {4D8B1227-9A32-5BCE-DD05-615509F1284B} - C:\WINDOWS\system32\bmxpalyr.dll

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_066b.dll

O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\niamalue.dat

O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\picbdo.dat

O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Eda76.exe

O4 - HKLM\..\Run: [inetmp3] C:\WINDOWS\inetmp3.exe

O4 - HKLM\..\Run: [*inetmp3] C:\WINDOWS\inetmp3.exe

O4 - HKLM\..\Run: [*bascat] C:\WINDOWS\security\logs\bascat.exe

O4 - HKLM\..\Run: [*wavedos] C:\WINDOWS\wavedos.exe

O4 - HKLM\..\Run: [*svrsvc] C:\WINDOWS\msagent\chars\svrsvc.exe

O4 - HKLM\..\Run: [*kbrun] C:\WINDOWS\system\kbrun.exe

O4 - HKLM\..\Run: [*dnsexp] C:\WINDOWS\Cursors\dnsexp.exe

O4 - HKLM\..\Run: [*crbas] C:\WINDOWS\Tasks\crbas.exe

O4 - HKLM\..\Run: [drvfont] C:\WINDOWS\drvfont.exe

O4 - HKLM\..\Run: [*netxml] C:\WINDOWS\system\netxml.exe

O4 - HKLM\..\Run: [*nutbin] C:\WINDOWS\system\nutbin.exe

O4 - HKLM\..\Run: [*anticr] C:\WINDOWS\security\Database\anticr.exe

O4 - HKLM\..\Run: [*doskey] C:\WINDOWS\msagent\doskey.exe

O4 - HKLM\..\Run: [*inetmain] C:\WINDOWS\security\inetmain.exe

O4 - HKLM\..\Run: [*odbcip] C:\WINDOWS\msagent\chars\odbcip.exe

O4 - HKLM\..\Run: [zeozuh] C:\WINDOWS\rpwsib.exe

O4 - HKLM\..\Run: [rfq] C:\documents and settings\martin fischler\local settings\temp\rfq.exe

O4 - HKLM\..\Run: [rbddublka] C:\WINDOWS\System32\ddawua.exe

O4 - HKLM\..\Run: [qsng3mh] acldmgr.exe

O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll

O4 - HKLM\..\Run: [mswspl] C:\WINDOWS\rpwsib.exe

O4 - HKLM\..\Run: [mipropw] C:\WINDOWS\System32\mipropw.exe

O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe

O4 - HKLM\..\Run: [AutoLoaderqF461acTIKaW] "C:\WINDOWS\System32\iyuaysvr.exe" /PC="AM.WILD" /HideUninstall

O4 - HKLM\..\Run: [d53] C:\documents and settings\martin fischler\local settings\temp\d53.exe

O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"

O4 - HKLM\..\Run: [*inetwin] C:\WINDOWS\Fonts\inetwin.exe

O4 - HKLM\..\Run: [7Eix18] c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe

O4 - HKLM\..\Run: [*eulamain] C:\WINDOWS\system\eulamain.exe

O4 - HKCU\..\Run: [bB4mRgN7T] reft01.exe

O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe

O4 - HKCU\..\Run: [Gqfnvt] C:\WINDOWS\system32\??chost.exe

O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"

O4 - HKLM\..\RunOnce: [*eulamain] C:\WINDOWS\system\eulamain.exe rerun

O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\system\abrfax.exe ren time:1101135485

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

acldmgr.exe <— file

c:\documents and settings\martin fischler\application data\rncr.exe <— file

c:\windows\drvfont.exe <— file

c:\windows\fash.exe <— file

c:\windows\inetmp3.exe <— file

c:\windows\rpwsib.exe <— file

c:\windows\system32\bmxpalyr.dll <— file

c:\windows\system32\ddawua.exe <— file

c:\windows\system32\eda76.exe <— file

c:\windows\system32\iyuaysvr.exe <— file

c:\windows\system32\mipropw.exe <— file

c:\windows\system32\pdfupd.dll <— file

c:\windows\system32\sdj6lsn.exe <— file

c:\windows\system32\sfg_066b.dll <— file

c:\windows\system32\xtawj.exe <— file

reft01.exe <— file

Delete all files in this folder:

C:\DOCUMENTS AND SETTINGS\Martin Fischler\LOCAL SETTINGS\temp <— FOLDER

Reboot in normal mode.

Please download the Peper Uninstaller

You have to remain online to run it.

Run it, then reboot

Run it again, and reboot once more, and "copy/paste" a new log file into this thread. :)
I have rebooted since the last log - here is an updated log - PLEASE ADVISE

Logfile of HijackThis v1.97.7
Scan saved at 12:30:06 PM, on 11/24/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLHOS~1.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\WINDOWS\system32\Vok3Ru.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\Lfv9.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Documents and Settings\Martin Fischler\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: (no name) - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\Program Files\SmartPopupBlocker\PopupBlockerBHO.dll
O2 - BHO: (no name) - {4D8B1227-9A32-5BCE-DD05-615509F1284B} - C:\WINDOWS\system32\bmxpalyr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_066b.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\niamalue.dat (file missing)
O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\picbdo.dat (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Eda76.exe
O4 - HKLM\..\Run: [inetmp3] C:\WINDOWS\inetmp3.exe
O4 - HKLM\..\Run: [*inetmp3] C:\WINDOWS\inetmp3.exe
O4 - HKLM\..\Run: [*bascat] C:\WINDOWS\security\logs\bascat.exe
O4 - HKLM\..\Run: [*wavedos] C:\WINDOWS\wavedos.exe
O4 - HKLM\..\Run: [*svrsvc] C:\WINDOWS\msagent\chars\svrsvc.exe
O4 - HKLM\..\Run: [*kbrun] C:\WINDOWS\system\kbrun.exe
O4 - HKLM\..\Run: [*dnsexp] C:\WINDOWS\Cursors\dnsexp.exe
O4 - HKLM\..\Run: [*crbas] C:\WINDOWS\Tasks\crbas.exe
O4 - HKLM\..\Run: [drvfont] C:\WINDOWS\drvfont.exe
O4 - HKLM\..\Run: [*netxml] C:\WINDOWS\system\netxml.exe
O4 - HKLM\..\Run: [*nutbin] C:\WINDOWS\system\nutbin.exe
O4 - HKLM\..\Run: [*anticr] C:\WINDOWS\security\Database\anticr.exe
O4 - HKLM\..\Run: [*doskey] C:\WINDOWS\msagent\doskey.exe
O4 - HKLM\..\Run: [*inetmain] C:\WINDOWS\security\inetmain.exe
O4 - HKLM\..\Run: [*odbcip] C:\WINDOWS\msagent\chars\odbcip.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [zeozuh] C:\WINDOWS\rpwsib.exe
O4 - HKLM\..\Run: [rfq] C:\documents and settings\martin fischler\local settings\temp\rfq.exe
O4 - HKLM\..\Run: [rbddublka] C:\WINDOWS\System32\ddawua.exe
O4 - HKLM\..\Run: [qsng3mh] acldmgr.exe
O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
O4 - HKLM\..\Run: [mswspl] C:\WINDOWS\rpwsib.exe
O4 - HKLM\..\Run: [mipropw] C:\WINDOWS\System32\mipropw.exe
O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AutoLoaderqF461acTIKaW] "C:\WINDOWS\System32\iyuaysvr.exe" /PC="AM.WILD" /HideUninstall
O4 - HKLM\..\Run: [d53] C:\documents and settings\martin fischler\local settings\temp\d53.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"
O4 - HKLM\..\Run: [*inetwin] C:\WINDOWS\Fonts\inetwin.exe
O4 - HKLM\..\Run: [7Eix18] c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe
O4 - HKLM\..\Run: [*eulamain] C:\WINDOWS\system\eulamain.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100877459\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [bB4mRgN7T] reft01.exe
O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe
O4 - HKCU\..\Run: [Gqfnvt] C:\WINDOWS\system32\??chost.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra 'Tools' menuitem: MaxSpeed (HKLM)
O9 - Extra button: AOL Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/d/4…0367/wmavax.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
If you have rebooted since you posted the log, DO NOT ATTEMPT THIS FIX. Instead post another log file and leave your machine on.

Download Killbox.zip

Extract it from the zip file then double-click on Killbox.exe to run it. In the 'Paste Full Path of File to Delete' box, copy and paste this entry:

C:\WINDOWS\inetmp3.exe

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". In the window that opens up, click on the File menu and choose "Add File". The file should show up in the window. Then repeat the process, this time adding:

C:\WINDOWS\security\logs\bascat.exe

If that's successful you should have the two files listed. Then repeat so that these files appear in the list as well:

C:\documents and settings\martin fischler\local settings\temp\rfq.exe
C:\documents and settings\martin fischler\local settings\temp\d53.exe
c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe
C:\WINDOWS\wavedos.exe
C:\WINDOWS\drvfont.exe
C:\WINDOWS\Cursors\dnsexp.exe
C:\WINDOWS\Fonts\inetwin.exe
C:\WINDOWS\msagent\chars\odbcip.exe
C:\WINDOWS\msagent\chars\svrsvc.exe
C:\WINDOWS\msagent\doskey.exe
C:\WINDOWS\rpwsib.exe
C:\WINDOWS\security\Database\anticr.exe
C:\WINDOWS\security\inetmain.exe
C:\WINDOWS\system\kbrun.exe
C:\WINDOWS\system\eulamain.exe
C:\WINDOWS\system\netxml.exe
C:\WINDOWS\system\nutbin.exe
C:\WINDOWS\System32\ddawua.exe
C:\WINDOWS\System32\mipropw.exe
C:\WINDOWS\Tasks\crbas.exe
C:\WINDOWS\system32\hostx.exe

When they are all there (and double check!), in the same window choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

Please download the latest version of Hijack This!

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://spywarewarrior.com/files/HijackThis.exe
http://tomcoyote.org/hjt/HijackThis.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

O2 - BHO: (no name) - {4D8B1227-9A32-5BCE-DD05-615509F1284B} - C:\WINDOWS\system32\bmxpalyr.dll

O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_066b.dll

O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

O2 - BHO: (no name) - {C69FA570-7FDE-4C49-A7BC-CB1CF24BE66B} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\niamalue.dat (file missing)

O2 - BHO: (no name) - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARTIN~1\LOCALS~1\Temp\picbdo.dat (file missing)

O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Eda76.exe

O4 - HKLM\..\Run: [inetmp3] C:\WINDOWS\inetmp3.exe

O4 - HKLM\..\Run: [*inetmp3] C:\WINDOWS\inetmp3.exe

O4 - HKLM\..\Run: [*bascat] C:\WINDOWS\security\logs\bascat.exe

O4 - HKLM\..\Run: [*wavedos] C:\WINDOWS\wavedos.exe

O4 - HKLM\..\Run: [*svrsvc] C:\WINDOWS\msagent\chars\svrsvc.exe

O4 - HKLM\..\Run: [*kbrun] C:\WINDOWS\system\kbrun.exe

O4 - HKLM\..\Run: [*dnsexp] C:\WINDOWS\Cursors\dnsexp.exe

O4 - HKLM\..\Run: [*crbas] C:\WINDOWS\Tasks\crbas.exe

O4 - HKLM\..\Run: [drvfont] C:\WINDOWS\drvfont.exe

O4 - HKLM\..\Run: [*netxml] C:\WINDOWS\system\netxml.exe

O4 - HKLM\..\Run: [*nutbin] C:\WINDOWS\system\nutbin.exe

O4 - HKLM\..\Run: [*anticr] C:\WINDOWS\security\Database\anticr.exe

O4 - HKLM\..\Run: [*doskey] C:\WINDOWS\msagent\doskey.exe

O4 - HKLM\..\Run: [*inetmain] C:\WINDOWS\security\inetmain.exe

O4 - HKLM\..\Run: [*odbcip] C:\WINDOWS\msagent\chars\odbcip.exe

O4 - HKLM\..\Run: [zeozuh] C:\WINDOWS\rpwsib.exe

O4 - HKLM\..\Run: [rfq] C:\documents and settings\martin fischler\local settings\temp\rfq.exe

O4 - HKLM\..\Run: [rbddublka] C:\WINDOWS\System32\ddawua.exe

O4 - HKLM\..\Run: [qsng3mh] acldmgr.exe

O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll

O4 - HKLM\..\Run: [mswspl] C:\WINDOWS\rpwsib.exe

O4 - HKLM\..\Run: [mipropw] C:\WINDOWS\System32\mipropw.exe

O4 - HKLM\..\Run: [fash] C:\WINDOWS\fash.exe

O4 - HKLM\..\Run: [AutoLoaderqF461acTIKaW] "C:\WINDOWS\System32\iyuaysvr.exe" /PC="AM.WILD" /HideUninstall

O4 - HKLM\..\Run: [d53] C:\documents and settings\martin fischler\local settings\temp\d53.exe

O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"

O4 - HKLM\..\Run: [*inetwin] C:\WINDOWS\Fonts\inetwin.exe

O4 - HKLM\..\Run: [7Eix18] c:\documents and settings\martin fischler\local settings\temp\7Eix18.exe

O4 - HKLM\..\Run: [*eulamain] C:\WINDOWS\system\eulamain.exe

O4 - HKCU\..\Run: [bB4mRgN7T] reft01.exe

O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Martin Fischler\Application Data\rncr.exe

O4 - HKCU\..\Run: [Gqfnvt] C:\WINDOWS\system32\??chost.exe

O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_066b.dll"

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

acldmgr.exe <— file

c:\documents and settings\martin fischler\application data\rncr.exe <— file

c:\windows\fash.exe <— file

c:\windows\system32\bmxpalyr.dll <— file

c:\windows\system32\ddawua.exe <— file

c:\windows\system32\eda76.exe <— file

c:\windows\system32\iyuaysvr.exe <— file

c:\windows\system32\lfv9.exe <— file

c:\windows\system32\mipropw.exe <— file

c:\windows\system32\pdfupd.dll <— file

c:\windows\system32\sfg_066b.dll <— file

c:\windows\system32\vok3ru.exe <— file

reft01.exe <— file

Delete all files in this folder:

C:\DOCUMENTS AND SETTINGS\Martin Fischler\LOCAL SETTINGS\temp <— FOLDER

Reboot in normal mode.

Please download the Peper Uninstaller

You have to remain online to run it.

Run it, then reboot

Run it again, and reboot once more, and "copy/paste" a new log file into this thread. :)
Here it is - I couldn't find all the files you wanted me to delete. How does this look so far? What did the Pepper uninstaler do? What can I do to prevent more probs? THanks soooo much for your time.

Logfile of HijackThis v1.98.2
Scan saved at 4:35:50 PM, on 11/24/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110087~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Martin Fischler\Desktop\HijackThis-1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: PopupBlockerBHO.CPopupBlockerBHO - {0D929918-C804-4756-B0AC-640EF3F061E9} - C:\Program Files\SmartPopupBlocker\PopupBlockerBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100877459\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKCU\..\Run: [PopUpStopperCompanion] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSComp.exe"
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AOL Instant Messenger (SM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
EXCELLENT JOB!!!

Most of the time a computer as "infected" as yours was requires 2 or 3 rounds of "fixes" before all the malware is defeated.

You did it on the 1st try!!! :thumbup:

The "Peper Uninstaller" removes the "Peper Trojan" from your machine.

This is evidence of a Peper Trojan:

O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Eda76.exe

Anyway, the log looks really great, and following are some things to ponder to help keep this from happening again.

GOD bless you and yours!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Thanks sooo much - you were a great help - don't know what I would have done without you. I really want to learn more about this stuff because alot of my friends come to me with similar issues - how do I start?
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI