This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Review & Help Me Clean Up

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.0
Scan saved at 10:16:39 PM, on 1/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\updatetc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\vmss\vmss.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\Temp\WTuninst.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\tmp\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL

= http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://keyword.netscape.com/keyword/%s
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -

{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV

Media\TvmBho.dll
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} -

C:\WINNT\system32\qtbhjwvl.dll
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} -

C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} -

C:\WINNT\system32\ipobxzo.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} -

C:\WINNT\system32\smiehlp.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -

{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} -

(no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -

C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: BA Toolbar - {952EC978-4920-4F18-8237-91D69B54C580} -

C:\Program Files\SearchLocate\sidebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI

Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program

Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD

Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program

Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power

Scan\powerscan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint

Manager\ViewMgr.exe
O4 - HKLM\..\Run: [tpcupdater] C:\WINNT\updatetc.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program

Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [function setCookie(name, value) ]

c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire

= new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today =

new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 *

24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60

* 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ]

c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ]

c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ]

c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset +=

search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end

== -1)
O4 - HKLM\..\Run: [end = document.cookie.length ]

c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset,

end)) ] c:\WINNT\System32\return

unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function

mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa]

c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function

FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu]

c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function

exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window

horizontally centered, rou] c:\WINNT\System32\var pos_left =

(screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1

pixel below the bottom of sc] c:\WINNT\System32\var pos_top =

(screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3,

'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]

c:\WINNT\System32\window.open(URL3,

'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' +

pos_top);
O4 - HKLM\..\Run:

c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else

{c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl]

c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function

redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2,

'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]

c:\WINNT\System32\window.open(URL2,

'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +

pos_top);
O4 - HKLM\..\Run: [window.open(URL,

'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]

c:\WINNT\System32\window.open(URL,

'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +

pos_top);
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINNT\ARUpdate.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common

Files\Java\bcre.exe"
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\}
O4 - HKLM\..\Run: [ top.location.replace(strTe]

c:\WINNT\System32\ top.location.replace(strTemp);
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone

Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe

/remove
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]

"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function

redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe]

c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program

Files\Digital Line Detect\DLG.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program

Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone

Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel

present
O8 - Extra context menu item: &AIM Search - res://C:\Program

Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program

Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program

Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug -

{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program

Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet

Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess -

http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker -

http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 -

http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -

http://public.windupdates.com/get_file.php…0cfd84064750d9f

f670ca95bb207a82492892b3b9ab0b150d34825d6c1f4faa5632c97c7c30f0d562bb0

995df42c0e856e17f438bb38f5ace6de305:6a2feff70aa50e4b3d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -

http://ak.imgfarm.com/images/nocache/funwe…/SmileyCentralI

nitialSetup1.0.0.8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control)

-

http://a840.g.akamai.net/7/840/537/2004061…l.trendmicro.co

m/housecall/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -

http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller

Class) -

http://download.zonelabs.com/bin/promotion…ector/WebSWK.ca

b
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan

Installer Class) -

http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4}

(IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX

Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =

STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =

STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =

STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown -

C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom

Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS

Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. -

C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE

C:\WINNT\System32\bcmwltry.exe (file missing)
Okay. I ran Adware & Spybot
Here's the new hijack log

Logfile of HijackThis v1.99.0
Scan saved at 6:32:11 PM, on 1/8/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\updatetc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\vmss\vmss.exe
C:\WINNT\Temp\WTuninst.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\wuauclt.exe
C:\tmp\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} - C:\WINNT\system32\qtbhjwvl.dll
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} - C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} - C:\WINNT\system32\ipobxzo.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINNT\system32\smiehlp.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: BA Toolbar - {952EC978-4920-4F18-8237-91D69B54C580} - C:\Program Files\SearchLocate\sidebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [tpcupdater] C:\WINNT\updatetc.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [function setCookie(name, value) ] c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire = new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today = new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ] c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ] c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ] c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset += search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end == -1)
O4 - HKLM\..\Run: [end = document.cookie.length ] c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset, end)) ] c:\WINNT\System32\return unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa] c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu] c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window horizontally centered, rou] c:\WINNT\System32\var pos_left = (screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of sc] c:\WINNT\System32\var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else {c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl] c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: [window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINNT\ARUpdate.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bcre.exe"
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\}
O4 - HKLM\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [DI2] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\27.exe\27.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…etup1.0.0.8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE C:\WINNT\System32\bcmwltry.exe (file missing)
famreeks

Posting help to other people hijackthis logs - is a offence here unless you have permission to do so. The response is normally to BAN the member doing so.

Every posting page carries the following warning:-

DO Not post help or your HijackThis Log to another user's hijackthis log unless you have been given permission to do so,
not following this guideline can get you banned from this forum


So tell me why you have done so, and why you should not be banned from the forum.

Please read
http://forums.tomcoyote.org/index.php?showtopic=10110
&
http://forums.tomcoyote.org/index.php?showtopic=1421

gwinslow

Now that someone else has replied to your log it could get overlooked. Our staff are told to search for posts in the last week that have zero replies. this one obviously now has replies so your topic would get overlooked.

I will arrange for one of our staff to take on your topic.
Hi Gwinslow
I will take over and help you.

Preliminaries:

1. Please copy the instructions or preferably print them. How to Print the Fix Instructions

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. It looks as if your copy of HijackThis is in a temporary folder. It needs to be in a permanent folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. For this reason it cannot be run from a Zip file or from Temporary folders because the backups will be deleted. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!

a. Please go to "My Computer" and find C:\tmp
b. Highlight the folder hijack and right click it.
c. Select "cut".
d. Open "My Documents" and go to an empty area in the folder. Right click and select "paste".
e. Check that you find HijakThis in the Hijack folder under "My Documents".

Start the cleanup:

5. Go to Start –> Settings –> Control Panel –>Add/Remove Programs and remove
TVMedia
180 Soluion if you can find it.
In both cases the could be slight variations of the name.


OPTIONAL
Do you use "WildTangent" on purpose? I see it in your log, but it's considered a resource hog and is slowing down your startup unnecessary. Decide if you want to keep it or not. If you decide to remove it, uninstall it by going to Start - Control Panel - Add/Remove Programs.


Reboot

6. Please download the latest version of Ad-Aware SE & Spybot Search & Destroy . Then follow the instructions in the links below to run the programs.
Spybot Tutorial
Ad-Aware Tutorial
Reboot after each Scan is finished to let the programs finish deleting what they found.

7. I would like you to do a free online virus scan at Trend Micro Houscall
Let Houscall fix anything it finds.

8. Now I would like you to do a virus scan at Panda free virus scan
Click "Scan your PC". In the Window that opens follow the instructions. Let Panda fix anything it finds.

9. Download “a Squared” . It has a free version. (The download button is at the bottom of the page). Install it.
Run and activate your free version with a Squared and then select
Scan your computer for malware infections .
Then select any/all drives.
Finally Scan selected folders.

10. Download a trial version of “Trojan Hunter” and run it to remove any traces of trojans.

Rebbot

11. Have you or an administrator set any policies or did you activate the 'Lock homepage from changes' option in some kind of anti-spyware tool? Please give me your answer with the next post.

12.* Close ALL windows except HJT
* SCAN with HJT
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH
* POST the new log in this thread using "Add Reply" Post a new HijackThis log. Close all windows and browsers.

How to post a HijackThis log.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button instead of "Do a system scan" that is OK. Just click it.
When the scan is finished, the "Scan" button will change into a "Save Log" button. Click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V". Click "Add Reply" to post.


Elrond
Thanks for your help.
Before your reply I had downloaded & Run AVG Free version anti-virus.
I've tried to follow the instructions exactly.
The new hijackthis log is below.
You also asked if I had set any policies or locked my homepage. I may have, but don't recall. I also don't know how to check. Would that be in Zone Alarm?

Logfile of HijackThis v1.99.0
Scan saved at 2:15:23 PM, on 1/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} - (no file)
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} - C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} - C:\WINNT\system32\ipobxzo.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [function setCookie(name, value) ] c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire = new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today = new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ] c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ] c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ] c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset += search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end == -1)
O4 - HKLM\..\Run: [end = document.cookie.length ] c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset, end)) ] c:\WINNT\System32\return unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa] c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu] c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window horizontally centered, rou] c:\WINNT\System32\var pos_left = (screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of sc] c:\WINNT\System32\var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else {c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl] c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: [window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\{
O4 - HKLM\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…etup1.0.0.8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE C:\WINNT\System32\bcmwltry.exe (file missing)
Hi gwinslow
Thanks for your quick answer.
As I do not see any of the programs that would lock your home page will fix the entries that made me ask.

Should you need instructions for:
Showing hidden files and folders in Windows.
Reboot in safe mode. If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.
How to print the fix instructions
Click the underlined links above.

This will be a long post and you really need to print or copy this so that you can check that you catch everything.

OK let's start.

1. I missed one item in the last post. It is an optional fix. If you want to keep it go to point 2.

Go to: Start > Control Panel > Add/Remove Programs, and remove:

Viewpoint Manager (It is considered "spyware")

Reboot.

2. Please configure your computer to show hidden files.

3. Reboot in safe mode

4. Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button instead of "Do a System Scan Only" that is OK. In that case click "Scan".) When the scan is finished put a check mark by the items that are listed in bold below. If you can not find an item, that is OK. Just continue but inform me with your next post. Do not click fix until instruct you to do so: The items that do not have an empty line between them should be next to each other.

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} - (no file)
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} - C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} - C:\WINNT\system32\ipobxzo.dll (file missing)

O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe

O4 - HKLM\..\Run: [function setCookie(name, value) ] c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire = new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today = new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60 * 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ] c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ] c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ] c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset += search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end == -1)
O4 - HKLM\..\Run: [end = document.cookie.length ] c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset, end)) ] c:\WINNT\System32\return unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa] c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu] c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window horizontally centered, rou] c:\WINNT\System32\var pos_left = (screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of sc] c:\WINNT\System32\var pos_top = (screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL3, 'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else {c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl] c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL2, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);
O4 - HKLM\..\Run: [window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t] c:\WINNT\System32\window.open(URL, 'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_top);

O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\{
O4 - HKLM\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);

O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [DI2] "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\27.exe\27.exe"

O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…etup1.0.0.8.cab

O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx

O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab


OPTIONAL.

These are ActiveX files that will reload if and when they are needed.

O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab

O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab

O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab


Now CLOSE ALL PROGRAMS and BROWSERS that are running, except HijackThis and then click the "fix" button.

5. Please delete these files in BOLD if they still exist:
C:\WINNT\system32\wzmtsrwz.dll
C:\WINNT\system32\ipobxzo.dll You probarbly will not find it.

Please delete these folders in BOLD if they still exist
C:\Program Files\Bcpc
C:\Program Files\Power Scan
C:\Program Files\AWS\WeatherBug
C:\WINNT\system32\vmss
C:\WINNT\system32\wsxsvc

Reboot

6. We need to clean out the temporary files. Some malware is hiding there.
Please download System Security Suite
Mark the page under the "Items to Clean Tab" like this . Run the program.

It will reboot the computer.

* Close ALL windows except HJT
* SCAN with HJT
* POST the new log in this thread using "Add Reply"
Thanks again!
I did the all steps you specified, and erased all of the optional ones also.
Here's the latest Hijackthis.log

Logfile of HijackThis v1.99.0
Scan saved at 8:46:11 PM, on 1/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE C:\WINNT\System32\bcmwltry.exe (file missing)
Hi gwinslow

Well done. It look much better. There is really only one bad group left. Let's try to get rid of it the same way as the rest of junk.

Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button instead of "Do a System Scan Only" that is OK. In that case click "Scan".) When the scan is finished put a check mark by the items that are listed in bold below. If you can not find an item, that is OK. Just continue but inform me with your next post. Do not click fix until instruct you to do so:

O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe] c:\WINNT\System32\ top.location.replace(strTemp);


Now CLOSE ALL PROGRAMS and BROWSERS that are running, except HijackThis and then click the "fix" button.

Reboot.

* Close ALL windows except HJT
* SCAN with HJT
* POST the new log in this thread using "Add Reply"

Also inform me of any problems you still see with your computer.

Elrond
Elrond-
The computer seems to be working well.
Isn't bogged down or having anymore pop-ups
GREAT JOB!! Thanks so much.
Here's the latest Hijackthis log. What's the meaning of last line "file missing"?

Logfile of HijackThis v1.99.0
Scan saved at 11:54:00 AM, on 1/16/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\System32\bcmwltry.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Administrator\My Documents\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE C:\WINNT\System32\bcmwltry.exe (file missing)
Hi gwinslow.

Your log looks clean.

Normally when HijackThis reports file missing it means that the file has been removed by some program, often a cleaning program that did not fix the registry entry properly. In this case it could be that you removed support for a wireless card or that HijackThis can not find the files for some reason but they do exist.
Leave it be as it does no harm but if you fix it you could lose your internet connection if you are using a wireless ditto.

Now that your computer is free of malware, I want you to take some precautions to avoid being re-infected.

Settings and maintenance

1. Clean out temporary files.
Go to "Start" > "Run" and type cleanmgr
Make sure the following are selected:
* Temporary Internet Files
* Recycle Bin
* Temporary Files
Click "OK'.
Repeat for each user account on the computer.
You should do this every few weeks to avoid buildup of unnecessary junk.


2. You reconfigured Windows to show hidden files and you should reset this to its original state useing the instructions from here except that
1. Under the "Hidden files and folders" heading put a mark for "Do not show hidden files and folders".
2. Uncheck "Display content of system folders"
3. Check the "Hide protected operating system files (recommended)" option.


3. Make your Internet Explorer more secure
This can be done by following these simple instructions that apply to all "Windows" except "Windows XP with SP2". In SP2 many of those setting are the default settings but check your settings anyhow. The settings can become restrictive but you should use them anyhow. If there are sites that will not show up right with those settings and that you rely on to be free of malware place them in the trusted zone.

1. Click "Start". Open "Control Panel".
2. Select the "Internet Options"
3. Select "Security" Tab and select the following settings.

* ActiveX controls and plug-ins
• Download signed ActiveX controls: Disable
• Download unsigned ActiveX controls: Disable
• Initialize and script ActiveX controls not marked as safe: Disable
• Run ActiveX controls and plug-ins: Disable
• Script ActiveX controls marked safe for scripting: Disable

* Downloads
• Font Download: Disable

* Microsoft VM
• Java permissions: Disable Java

* Miscellaneous
• Allow META REFRESH: Disable
• Display mixed content: Disable
• Drag and drop or copy and paste files: Disable
• Installation of desktop items: Disable
• Launching programs and files in an IFRAME: Disable
• Navigate sub-frames across different domains: Disable
• Software channel permissions: High Safety
• Userdata persistence: Disable

* Scripting
• Active scripting: Disable
• Allow paste operations via script: Disable
• Scripting of Java applets: Disable

* User Authentication
• Logon: Prompt for username and password

4. When all these settings have been made, click on the OK button.
5. If it prompts you as to whether or not you want to save the settings, press the Yes button.
6. Next press the Apply button and then the OK to exit the Internet Properties page.


These are a must to protect yourself from malware.
1. You have a good anti-virus..
KEEP IT UPDATED

2. You have a good firewall.

Be restrictive with access to the internet. If you are unsure if the program really needs the access, test it by denying the access and see if this has any negative effects. If not make the block permanent.

3. MOST IMPORTANT: You Need to keep “Windows” and "Internet Explorer” updated. Open ‘Internet Explorer” and go to”Start”> "Tools" > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates.

If you are running Microsoft Office, or any portion thereof you must keep it updated as well. Go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed. Update MS Office here.

4. Download and install “SpywareBlaster”
Run it. Click "Updates" at the left and click "Check for Updates". After updating click "Protection" at the left and towards the bottom click "Enable All Protection". You should now be protected from all known bad ActiveX. You should occasionally check for updates.

5. Download and install "SpywareGuard"

Further tools

I highly recommend downloading and installing the newest versions of “AdAware SE Personal” and “Spybot Search and Destroy”
After installing remember to update the definition files for each program.
I also suggest that you visit this website and follow the instructions on how to configure both programs for best detection. These instructions are correct even though they refer to a cleanup of an infected computer.

There are many other programs that will add extra layers of protection to your computer as well.
I recommend “IE-Spyad” By default, it is unzipped to "C:\ie-spyad". Find out how to install it by going to the "ReadMe.txt". You should occasionally get updates by using the bat file or by uninstalling and deleting the old files and returning to the site to get the new version.

A Trojan scanner would be also be helpful. You can download a trial version of “Trojan Hunter” and run it to remove any traces of trojans.

The ”a Squared” trojan Scanner has a free version. It is an onboard trojan scanner that is installed much like Spybot/AdAware but handles trojans. Nice to add to your armor if you wish.
Download free from “a Squared” (The download button is at the bottom of the page). Install it.
Run and activate your free version with a Squared and then select
Scan your computer for malware infections .
Then select any/all drives.
Finally Scan selected folders.

It is worth while to take a look at "So how did I get infected in the first place? for some good advice.

A good source of information about computer secutiy can be found at this website . ChrisRLG is an Administrator and Classroom Teacher at Tom Coyote.

Update all protective programs regularly - Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Best of luck and clean computing

Elrond
Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI