This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Backdoor-bdi, Help Please

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am posting my HijackThis log file in hopes that someone can help me get rid of this pesky trojan. I have tried many adware/spyware removers to no avail. Any guidance will be much appreciated. Thanks in advance - Gloria

Logfile of HijackThis v1.99.0
Scan saved at 10:52:19 AM, on 2/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Bpt\bpt.exe
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\system32\secure.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\okftx\rnddh.exe
C:\WINDOWS\system32\wers\kbyr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Flash Enhancer - {7CD20E91-1F31-41da-8379-479EA31DF969} - c:\Program Files\XML\XML.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINDOWS\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\system32\winupdtl.exe
O4 - HKLM\..\Run: [rjcypc] C:\WINDOWS\system32\rjcypc.exe
O4 - HKLM\..\Run: [rerrsc] C:\WINDOWS\system32\rerrsc.exe
O4 - HKLM\..\Run: [x77X3ni] cssvtmsg.exe
O4 - HKLM\..\Run: [bcflbm] C:\WINDOWS\system32\mxrxdjd\bcflbm.exe
O4 - HKLM\..\Run: [pjlndwcm] C:\WINDOWS\system32\pqrpxda\pjlndwcm.exe
O4 - HKLM\..\Run: [iqamv] C:\WINDOWS\system32\vkrp\iqamv.exe
O4 - HKLM\..\Run: [dwcxx] C:\WINDOWS\system32\jbaybeue\dwcxx.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [bgpjnqd] C:\WINDOWS\system32\tpga\bgpjnqd.exe
O4 - HKLM\..\Run: [hqgrkcr] C:\WINDOWS\system32\opjh\hqgrkcr.exe
O4 - HKLM\..\Run: [yxts] C:\WINDOWS\system32\iavycl\yxts.exe
O4 - HKLM\..\Run: [sbjdn] C:\WINDOWS\system32\xrtqovbj\sbjdn.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [kdvpx] C:\WINDOWS\system32\tnfs\kdvpx.exe
O4 - HKLM\..\Run: [yvem] C:\WINDOWS\system32\wqwxltur\yvem.exe
O4 - HKLM\..\Run: [hfwje] C:\WINDOWS\system32\wxrtnw\hfwje.exe
O4 - HKLM\..\Run: [rjmttne] C:\WINDOWS\system32\ugvnajvm\rjmttne.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\secure.exe
O4 - HKLM\..\Run: [mzajyvol] c:\windows\system32\mzajyvol.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common Files\Java\bptre.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe

Scanning With Ad-Aware SE :


1. Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan

2.Close ALL windows except Ad-Aware SE

3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window

1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days


2) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file


3) Click on the ‘Advanced’ button on the left and select in green:

Under Shell Integration:
*Move deleted files to recycle bin

Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information

Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT


4) Click the ‘Tweak’ button and select in green:

Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only


Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot


Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile


5. Click on ‘Proceed’ to save the settings.

6. Click ‘Start’

*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.

8. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window

9. Save the log file when it asks and then click ‘finish’

10. REBOOT to complete the removal of what Ad-Aware SE found




Scanning in Spybot Search and Destroy:


1. Downloaded and Install Spybot S&D, accepting the Default Settings

2. In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.

3. Close ALL windows except Spybot S&D

4. Click the button to ‘Search for Updates’ then download and install the Updates.

5. Next click the button ‘Check for Problems’

6. When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window

7. Make certain there is a check mark beside all of the RED entries ONLY.

8. Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.

9.REBOOT to complete the scan and clear memory.





Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall

Panda ActiveScan
Note any thing that can't be fixed
Reboot when done. Rescan with HJT and post a new log here.
little eagle, thanks for the help. I have completed all of the scans and still have the BackDoor-BDI trojan. Here is the latest HijackThis log. Thanks, Gloira

Logfile of HijackThis v1.99.0
Scan saved at 6:18:29 AM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Bpt\bpt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\wers\kbyr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\okftx\rnddh.exe
C:\WINDOWS\system32\secure.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [rjcypc] C:\WINDOWS\system32\rjcypc.exe
O4 - HKLM\..\Run: [rerrsc] C:\WINDOWS\system32\rerrsc.exe
O4 - HKLM\..\Run: [x77X3ni] cssvtmsg.exe
O4 - HKLM\..\Run: [bcflbm] C:\WINDOWS\system32\mxrxdjd\bcflbm.exe
O4 - HKLM\..\Run: [pjlndwcm] C:\WINDOWS\system32\pqrpxda\pjlndwcm.exe
O4 - HKLM\..\Run: [iqamv] C:\WINDOWS\system32\vkrp\iqamv.exe
O4 - HKLM\..\Run: [dwcxx] C:\WINDOWS\system32\jbaybeue\dwcxx.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [bgpjnqd] C:\WINDOWS\system32\tpga\bgpjnqd.exe
O4 - HKLM\..\Run: [hqgrkcr] C:\WINDOWS\system32\opjh\hqgrkcr.exe
O4 - HKLM\..\Run: [yxts] C:\WINDOWS\system32\iavycl\yxts.exe
O4 - HKLM\..\Run: [sbjdn] C:\WINDOWS\system32\xrtqovbj\sbjdn.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [kdvpx] C:\WINDOWS\system32\tnfs\kdvpx.exe
O4 - HKLM\..\Run: [yvem] C:\WINDOWS\system32\wqwxltur\yvem.exe
O4 - HKLM\..\Run: [hfwje] C:\WINDOWS\system32\wxrtnw\hfwje.exe
O4 - HKLM\..\Run: [rjmttne] C:\WINDOWS\system32\ugvnajvm\rjmttne.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\secure.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
Still not looking any better.


Download the trial version of TDS-3
Install it, but do not launch it yet

Update it hereright click, select "save as"

Save it to the directory where you installed TDS-3, overwriting the previous radius.td3.

Then launch TDS-3. in the top bar of tds window click system testing> full system scan.
detections will appear in the lower pane of tds window. after the scan is finished ( it'll take a while )
right click the list> select save as txt. save it and post the contents of the scandump.txt here.

After posting the scandump go ahead and right click the list of detections again. this time select delete!
Only delete those with positive identification.
little eagle, Here is the TS scan dump. I was unable to delete the file c:\windows\system32\dolsp.dll. It was identified as a Trojan downloader. Is there a next step? Again, many thanks for your help on this. Thanks, Gloria Scan Control Dumped @ 13:06:30 13-02-05 (DELETED) Positive identification: Adware.Broadcap.a File: c:\program files\bpt\bpt.exe (DELETED) Positive identification: Adware.DealHelper.v File: c:\windows\system32\secure.exe (DELETED) Positive identification: Adware.DealHelper.t File: c:\documents and settings\gloria admin\local settings\temp\13a.tmp (DELETED) Positive identification: Adware.DealHelper.t File: c:\documents and settings\gloria admin\local settings\temp\15.tmp (DELETED) Positive identification: Adware.DealHelper.t File: c:\documents and settings\gloria admin\local settings\temp\1a.tmp (DELETED) Positive identification: Adware.DealHelper.t File: c:\documents and settings\gloria admin\local settings\temp\1c.tmp (DELETED) Positive identification: Adware.DealHelper.t File: c:\documents and settings\gloria admin\local settings\temp\47.tmp (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf1b9glf1b9.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf1c9glf1c9.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf2fglf2f.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf42glf42.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf4eglf4e.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glf9dglf9d.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glfd2glfd2.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\documents and settings\gloria admin\local settings\temp\glfe2glfe2.exe (DELETED) Positive identification: Adware.BetterInternet File: c:\documents and settings\gloria admin\local settings\temp\drtemp\thnall1b.exe.tcf Suspicious Filename: Dual extensions File: c:\documents and settings\gloria admin\my documents\art project ideas\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: c:\documents and settings\gloria admin\my documents\art project ideas\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: c:\documents and settings\gloria admin\my documents\stuff for sean\document scrap 'all_ double_ dou…'.shs (DELETED) Positive identification: Adware.Broadcap.a File: c:\program files\bpt\bpt.exe (DELETED) Positive identification: Adware.Broadcap.a Dropper.a File: c:\program files\bpt\bptre_inst.exe (DELETED) Positive identification: Adware.Broadcap.a File: c:\program files\common files\java\bpt.cfg (DELETED) Positive identification: Riskware.ProcessRestart File: c:\program files\logitech\desktop messenger\8876480\6.1.4.36-8876480l\program\restart.exe (DELETED) Positive identification : Possible WebDownloader File: c:\program files\online services\msn50\msnboot.exe (DELETED) Positive identification: Riskware.Proxy.Hltv File: c:\sierra\half-life\hltv.exe (DELETED) Positive identification (DLL): Adware.BiSpy.t (dll) File: c:\windows\btgrab.dll.tcf (DELETED) Positive identification (DLL): Adware.BiSpy.t (dll) File: c:\windows\btgrab.dll7620.tcf (DELETED) Positive identification: TrojanDropper.Win32.Small.mr File: c:\windows\bundles\saie1101.exe.tcf (DELETED) Positive identification: TrojanDownloader.Win32.Small.wj File: c:\windows\bundles\shopinst.exe (DELETED) Positive identification: TrojanDropper.Win32.SurfSide.a File: c:\windows\bundles\ssk_b5.exe (DELETED) Positive identification: Adware.BetterInternet File: c:\windows\bundles\thin-8-1-x-x.exe.tcf (DELETED) Positive identification: TrojanDownloader.Win32.Small.wj File: c:\windows\bundles\videoinst.exe (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\aspartners.dll (DELETED) Positive identification: Adware.BetterInternet File: c:\windows\system32\betterinternet1.exe.tcf (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\c8002idmg80a2.dll (DELETED) Positive identification: TrojanDownloader.Win32.Agent.hc File: c:\windows\system32\crysrcwp.exe.tcf Positive identification (DLL): TrojanDownloader.Win32.Agent.br2 (dll) File: c:\windows\system32\dolsp.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\en00l1dm1.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\en6sl1j71.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\fbtlib.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\fp6003jme.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\guard.tmp (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\hrpm0571e.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\l60ulgd9160.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\m4460ehseh460.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\m4nq0e55eh.dll (DELETED) Positive identification: Trojan.Win32.Agent.ay File: c:\windows\system32\mzajyvol.exe.tcf (DELETED) Positive identification: Trojan.Win32.Agent.ay File: c:\windows\system32\mzajyvol.exe6626.tcf (DELETED) Positive identification: Adware.Adstart.c2 File: c:\windows\system32\rerrsd.exe (DELETED) Positive identification (DLL): Adware.Adstart.c2 (dll) File: c:\windows\system32\rjcyp.dll (DELETED) Positive identification: Adware.Adstart.c2 File: c:\windows\system32\rjcypd.exe (DELETED) Positive identification: Adware.Adstart.b2 File: c:\windows\system32\rjcypf.exe (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\sci_ci.dll (DELETED) Positive identification: Adware.DealHelper.v File: c:\windows\system32\secure.exe (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\windows\system32\targetsavers.exe (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\vjgaview.dll (DELETED) Positive identification (DLL): Adware.Look2Me.u (dll) File: c:\windows\system32\wnnmm.dll (DELETED) Positive identification: TrojanDownloader.Win32.TSUpdate.f Dropper.b File: c:\windows\system32\mssysapps\targetsavers.exe (DELETED) Positive identification: Adware.DelphinMediaViewer.c File: c:\windows\system32\vmss\vmss.exe.tcf (DELETED) Positive identification (DLL): Adware.DelfinMediaViewer (dll) File: c:\windows\system32\wsxsvc\wsx.ocx (DELETED) Positive identification: Adware.DelphinMediaViewer.c1 File: c:\windows\system32\wsxsvc\wsxsvc.exe.tcf (DELETED) Positive identification: Adware.BetterInternet File: c:\windows\temp\drtemp\mm_reco.exe.tcf (DELETED) Positive identification: Adware.BetterInternet File: c:\windows\temp\drtemp\wupdsnff.exe.tcf Suspicious Filename: Dual extensions File: d:\c\david office backup\drivers\hpdeskjetg85xi\cdimage\setup\motive\install.wse.exe Suspicious Filename: Dual extensions File: d:\c\drivers\hpdeskjetg85xi\cdimage\setup\motive\install.wse.exe Suspicious Filename: Dual extensions File: d:\c\hp\bin\python-2.2.1.exe (DELETED) Positive identification: Riskware.ProcessRestart File: d:\c\program files\backweb\backweb client\6.2.3.66\program\restart.exe (DELETED) Positive identification : Possible WebDownloader File: d:\c\program files\common files\microsoft shared\office11\msoxmled.exe Suspicious Filename: Dual extensions File: d:\c\program files\installshield installation information\pc-doctor\reln1.05.011.doc Suspicious Filename: HTA file in suspicious location File: d:\c\program files\microsoft money\system\discover.hta Suspicious Filename: HTA file in suspicious location File: d:\c\program files\microsoft money\system\lnpg.hta (DELETED) Positive identification : Possible WebDownloader File: d:\c\program files\microsoft office\office11\msohtmed.exe (DELETED) Positive identification (DLL): Adware.WebEx (dll) File: d:\c\program files\webex\ieatgpc.dll Suspicious Filename: Dual extensions File: d:\c\recycler\s-1-5-21-1643855648-901463496-641774078-1003\dc4\docuprep\readme_files\image002.jpg.vbs Suspicious Filename: Dual extensions File: d:\c\winpointinstallfolder\install\docuprep\readme_files\image002.jpg.vbs Suspicious Filename: Dual extensions File: d:\gloria's backups\(20a660f6) my documents\art project ideas\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\(20a660f6) my documents\art project ideas\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\(20a660f6) my documents\art projects\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\(20a660f6) my documents\art projects\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\(20a660f6) my documents\stuff for sean\document scrap 'all_ double_ dou…'.shs Suspicious Filename: Dual extensions File: d:\gloria's backups\gloria strauss\my documents\art projects\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\gloria strauss\my documents\art projects\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\gloria strauss\my documents\stuff for sean\document scrap 'all_ double_ dou…'.shs Suspicious Filename: Dual extensions File: d:\gloria's backups\my documents\art project ideas\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\my documents\art project ideas\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\my documents\art projects\collage ninabagleydesign.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\my documents\art projects\www.cafeshops.com.doc Suspicious Filename: Dual extensions File: d:\gloria's backups\my documents\stuff for sean\document scrap 'all_ double_ dou…'.shs
little eagle, here is the latest Hijack log.

Logfile of HijackThis v1.99.0
Scan saved at 1:36:40 PM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\okftx\rnddh.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\TDS3\tds-3.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [rjcypc] C:\WINDOWS\system32\rjcypc.exe
O4 - HKLM\..\Run: [rerrsc] C:\WINDOWS\system32\rerrsc.exe
O4 - HKLM\..\Run: [x77X3ni] cssvtmsg.exe
O4 - HKLM\..\Run: [bcflbm] C:\WINDOWS\system32\mxrxdjd\bcflbm.exe
O4 - HKLM\..\Run: [pjlndwcm] C:\WINDOWS\system32\pqrpxda\pjlndwcm.exe
O4 - HKLM\..\Run: [iqamv] C:\WINDOWS\system32\vkrp\iqamv.exe
O4 - HKLM\..\Run: [dwcxx] C:\WINDOWS\system32\jbaybeue\dwcxx.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [bgpjnqd] C:\WINDOWS\system32\tpga\bgpjnqd.exe
O4 - HKLM\..\Run: [hqgrkcr] C:\WINDOWS\system32\opjh\hqgrkcr.exe
O4 - HKLM\..\Run: [yxts] C:\WINDOWS\system32\iavycl\yxts.exe
O4 - HKLM\..\Run: [sbjdn] C:\WINDOWS\system32\xrtqovbj\sbjdn.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [kdvpx] C:\WINDOWS\system32\tnfs\kdvpx.exe
O4 - HKLM\..\Run: [yvem] C:\WINDOWS\system32\wqwxltur\yvem.exe
O4 - HKLM\..\Run: [hfwje] C:\WINDOWS\system32\wxrtnw\hfwje.exe
O4 - HKLM\..\Run: [rjmttne] C:\WINDOWS\system32\ugvnajvm\rjmttne.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\secure.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\dolsp.dll' missing
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
Did you reboot after the scans? Reboot in safe mode and get a log from hijackthis. Save it Reboot again and save another log. Post both of them back here.

Should you need instructions for ;
Showing hidden files and folders in Windows.
Reboot in safe mode.
How to set up a HijackThis folder correctly to make backups.
Scan with Spybot S&D and Ad-Aware
How To Print Fix Instructions
Click the underlined links above.



If they are still there

Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes:

C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\okftx\rnddh.exe


Exit the Task Manager when finished


Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.
O2 - BHO: BTGrabObj Class - {00000000-F09C-02B4-6EC2-AD0300000000} - C:\WINDOWS\BTGrab.dll (file missing)
O4 - HKLM\..\Run: [Dvx] C:\WINDOWS\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [rjcypc] C:\WINDOWS\system32\rjcypc.exe
O4 - HKLM\..\Run: [rerrsc] C:\WINDOWS\system32\rerrsc.exe
O4 - HKLM\..\Run: [x77X3ni] cssvtmsg.exe
O4 - HKLM\..\Run: [bcflbm] C:\WINDOWS\system32\mxrxdjd\bcflbm.exe
O4 - HKLM\..\Run: [pjlndwcm] C:\WINDOWS\system32\pqrpxda\pjlndwcm.exe
O4 - HKLM\..\Run: [iqamv] C:\WINDOWS\system32\vkrp\iqamv.exe
O4 - HKLM\..\Run: [dwcxx] C:\WINDOWS\system32\jbaybeue\dwcxx.exe
O4 - HKLM\..\Run: [BPT] "C:\Program Files\Bpt\bpt.exe"
O4 - HKLM\..\Run: [bgpjnqd] C:\WINDOWS\system32\tpga\bgpjnqd.exe
O4 - HKLM\..\Run: [hqgrkcr] C:\WINDOWS\system32\opjh\hqgrkcr.exe
O4 - HKLM\..\Run: [yxts] C:\WINDOWS\system32\iavycl\yxts.exe
O4 - HKLM\..\Run: [sbjdn] C:\WINDOWS\system32\xrtqovbj\sbjdn.exe
O4 - HKLM\..\Run: [kdvpx] C:\WINDOWS\system32\tnfs\kdvpx.exe
O4 - HKLM\..\Run: [yvem] C:\WINDOWS\system32\wqwxltur\yvem.exe
O4 - HKLM\..\Run: [hfwje] C:\WINDOWS\system32\wxrtnw\hfwje.exe
O4 - HKLM\..\Run: [rjmttne] C:\WINDOWS\system32\ugvnajvm\rjmttne.exe
O4 - HKLM\..\Run: [Tsl] C:\PROGRA~1\COMMON~1\tsa\tsl.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\secure.exe


The following activeX controls( Download Program Files)will reinstall when(and if) you revisit that website,
UNLESS you know they are from a safe source, check to remove.

Reboot in safe mode.
Delete the following file(s) listed.
Then click start>my computer>local disk
(then follow the path)
or useWindows Explorer, locate the following files/folders, and delete them:

C:\WINDOWS\system32\wsxsvc
C:\WINDOWS\system32\rjcypc.exe
C:\WINDOWS\system32\rerrsc.exe
cssvtmsg.exe(do a search for this one. It'll probably be in c:\windows or c:\windows\system32.)
C:\WINDOWS\system32\mxrxdjd\bcflbm.exe
C:\WINDOWS\system32\pqrpxda\pjlndwcm.exe
C:\WINDOWS\system32\vkrp\iqamv.exe
C:\WINDOWS\system32\jbaybeue\dwcxx.exe
C:\WINDOWS\system32\tpga\bgpjnqd.exe
C:\WINDOWS\system32\opjh\hqgrkcr.exe
C:\WINDOWS\system32\iavycl\yxts.exe
C:\WINDOWS\system32\xrtqovbj\sbjdn.exe
C:\WINDOWS\system32\tnfs\kdvpx.exe
C:\WINDOWS\system32\wqwxltur\yvem.exe
C:\WINDOWS\system32\wxrtnw\hfwje.exe
C:\WINDOWS\system32\ugvnajvm\rjmttne.exe
C:\WINDOWS\system32\secure.exe

Delete the folder(s) listed

C:\Program Files\Bpt
C:\PROGRA~1\COMMON~1\tsa


Still In safe mode navigate to the
C:\Windows\Temp folder. Open the Temp folder and go to
Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Do not delete the folder it self!!

Next navigate to the
C:\Documents and Settings\(EVERY USER)\Local Settings\Temp folder.
Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Again do not deleete the folder it self!!

Finally go to Control Panel > Internet Options.
On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

You may want to Download and install CCleaner
Under windows tab check internet explorer, windows explorer, and system.
then click Run Cleaner.

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves now.
little eagle,
I have completed all of the tasks in your last post. Here are a few notes and the new HijackThis log.

- unable to find files: cssvtmsg.exe, rerrsc.exe
- ran CCleaner
- since HijackThis could not delete the file doslp.dll, I renamed it and after rebooting I could not access the internet and received a message that I had only limited access (on our home network). After renaming it to doslp.dll, I had full access to my network and the internet. Don't know what that means, but thought it might be helpful.
-After completing the tasks and rebooting and while I was typing this, McAfee popped up and said it found BackDoor-BDI trojan, ugh!

Continued thanks for all of the help - Gloria
Here is the log:

Logfile of HijackThis v1.99.0
Scan saved at 3:42:18 PM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\wers\kbyr.exe
C:\WINDOWS\system32\okftx\rnddh.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
Download LSPfix here: http://www.cexx.org/lspfix.htm

Start the program and then check the I know what I'm doing box.

Move all instances of
dolsp.dll
(and nothing else), to the Remove pane.
Click the Finish Button and reboot.

Find and delete the file c:\windows\system32\dolsp.dll


Sorry if you fix this any other way you may not be able to access the internet . ;)
Guess you found that out . B)

Then post another log.
Well little eagle, the good news is, I still have internet access. The bad news is that doslp.dll file is gone, but the Backdoor-BDI still showed up after rebooting. Here is the latest Hijack file. I'm not ready to reformat yet! any further ideas?

Thanks, Gloria

Logfile of HijackThis v1.99.0
Scan saved at 5:25:05 PM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\wers\kbyr.exe
C:\WINDOWS\system32\okftx\rnddh.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe

Reboot in SAFE MODE.
Some of these files and folders might have hidden atributes.
Delete the following file(s) listed in
C:\WINDOWS\system32\ofanqs\plkor.exe
C:\WINDOWS\system32\jyds\jgcexls.exe
C:\WINDOWS\system32\wers\kbyr.exe
C:\WINDOWS\system32\okftx\rnddh.exe


Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O4 - HKLM\..\Run: [agrdyo] C:\WINDOWS\system32\bnoyqj\agrdyo.exe
O4 - HKLM\..\Run: [plkor] C:\WINDOWS\system32\ofanqs\plkor.exe
O4 - HKLM\..\Run: [jgcexls] C:\WINDOWS\system32\jyds\jgcexls.exe
O4 - HKLM\..\Run: [kbyr] C:\WINDOWS\system32\wers\kbyr.exe
O4 - HKLM\..\Run: [rnddh] C:\WINDOWS\system32\okftx\rnddh.exe


Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment


If this doesn't work will bring out another tool.

;)
little eagle,
we are making progress!! I have been surfing for about 10 minutes after doing the last fixes and NO trojans have popped up. The only thing that came in was a window that is an "auto complete" window popup type thing. This has been popping up since about the same time as the backdoor BDI showed up.
I can't tell you how much I apprecaite your help getting rid of that ugly backdoor trojan. :D Any ideas on what that "auto complete" thing migh be?

Gloria

btw - do you ever sleep? I have seen your postings since early AM.

latest HJ log
Logfile of HijackThis v1.99.0
Scan saved at 6:22:57 PM, on 2/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\TrojanHunter 4.1\THGuard.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
C:\WINDOWS\System32\Tablet.exe
C:\Program Files\Common Files\pestpatrol\PPMCActiveDetection.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Xerox WorkCentre 470cx Monitor] RUNDLL32.EXE C:\WINDOWS\System32\X470SHLL.DLL,AutoUpdatePnPValue
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.1\THGuard.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\Wtablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: WebWorks Help 2.0 - file://C:\Program Files\procreate Painter Classic\Help\wwhelp2.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://65.192.112.220/cams/AxisCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…406/mcfscan.cab
O23 - Service: CA License Client - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Event Log Watch - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\pestpatrol\ppRemoteService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe

btw - do you ever sleep? I have seen your postings since early AM.

I post replies when I drink coffee. Then do new logs when I have time. B)
Then try to repy to new ones before I go to bed. Today I was just making changes to my PC all day.


This log looks clean. Can you boot in safe mode and get another log.
If you have teatimer running turn it off and then start it up again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI