This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Difficult Vx2 (i Beleive)

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi!
I seem to have a VX2 (as far as I can tell)
I have installed and used Spybot and Ad-aware. Both of them find malware and "fix" them but my problem remains. I also tried to use hijackthis myself a bit and "fixed" som files but those files just came back after I rebooted…I also tried the VX2 add-on but no luck there either…

Can anybody have a look at my log?

Best regards!
Pontus


Logfile of HijackThis v1.99.1
Scan saved at 21:07:58, on 2005-04-10
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\Smartscaps.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ICO.EXE
C:\Program\D-Tools\daemon.exe
C:\WINDOWS\system32\msdm32.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\Steam\Steam.exe
C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
C:\Program\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
C:\WINDOWS\iexr32.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\fmgjl.dll/sp.html#12345
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {DA991481-89B4-0B26-9C54-3A2FD8525D10} - C:\WINDOWS\system32\atlee.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [b13] "C:\y.exe "
O4 - HKLM\..\Run: [msdm32.exe] C:\WINDOWS\system32\msdm32.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKLM\..\RunOnce: [netdx32.exe] C:\WINDOWS\system32\netdx32.exe
O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\Program\Yahoo!\YPSR\ppclean.exe" "clean" "cws" "2"
O4 - HKLM\..\RunOnce: [d3ad.exe] C:\WINDOWS\d3ad.exe
O4 - HKLM\..\RunOnce: [crnw32.exe] C:\WINDOWS\crnw32.exe
O4 - HKLM\..\RunOnce: [iexr32.exe] C:\WINDOWS\iexr32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Program\Steam\Steam.exe -silent
O4 - Global Startup: Certificate Mover.lnk = C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
O4 - Global Startup: D-Link AirPlus G+ Wireless Adapter Utility.lnk = C:\Program\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program\Delade filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113129253077
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\msfn32.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartTrust Smart Card Server (Smartscaps) - SmartTrust - C:\WINDOWS\system32\Smartscaps.exe
I might add…The symptoms on my comp. is that IE allways starts on a special web page (about:blank) and that I get pop-ups (even when I have pop-up protection). I also get som weird links in my "favorites" of IE. Thanks!
Hello Stonefunker, welcome to the TC.

Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet)

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Run this process in safe mode and run it twice

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
Thanks for answering my call (for help!!)…
After following your instructions and after the last reboot I still seem to have the same problem remaining….maybe I did something wrong… :-(

/ Pontus

heres my logs:

Logfile of HijackThis v1.99.1
Scan saved at 23:29:09, on 2005-04-22
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\Smartscaps.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\d3oy32.exe
C:\WINDOWS\system32\syszs.exe
C:\WINDOWS\System32\ICO.EXE
C:\CFGSAFE\SCHWIZEX.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\Steam\Steam.exe
C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {FA72B7B8-21F5-118B-EFBB-A3F57457DA8D} - C:\WINDOWS\system32\syszs.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [b13] "C:\y.exe "
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [syszs.exe] C:\WINDOWS\system32\syszs.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Program\Steam\Steam.exe -silent
O4 - Global Startup: Certificate Mover.lnk = C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
O4 - Global Startup: D-Link AirPlus G+ Wireless Adapter Utility.lnk = C:\Program\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program\Delade filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113129253077
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\d3oy32.exe" /s (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartTrust Smart Card Server (Smartscaps) - SmartTrust - C:\WINDOWS\system32\Smartscaps.exe


and the other log:

(4-22-05 22:56:32) SPSeHjFix started v1.1.2
(4-22-05 22:56:32) OS: WinXP (5.1.2600)
(4-22-05 22:56:32) Language: svenska
(4-22-05 22:56:32) Win-Path: C:\WINDOWS
(4-22-05 22:56:32) System-Path: C:\WINDOWS\System32
(4-22-05 22:56:32) Temp-Path: C:\DOCUME~1\Pontus\LOKALA~1\Temp\
(4-22-05 22:56:34) Disinfection started
(4-22-05 22:56:34) Bad-Dll(IEP): c:\windows\jdiko.dll
(4-22-05 22:56:34) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:56:34) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:56:34) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\jdiko.dll/sp.html#12345
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\jdiko.dll/sp.html#12345
(4-22-05 22:56:34) Stealth-String not found
(4-22-05 22:56:34) No locked Files to delete. End without Reboot
(4-22-05 22:56:45) Disinfection started
(4-22-05 22:56:45) Bad-Dll(IEP): c:\windows\jdiko.dll
(4-22-05 22:56:45) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:56:45) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:56:45) Bad IE-pages: (none)
(4-22-05 22:56:45) Stealth-String not found
(4-22-05 22:56:45) No locked Files to delete. End without Reboot
(4-22-05 22:57:40) Disinfection started
(4-22-05 22:57:40) Bad-Dll(IEP): c:\windows\jdiko.dll
(4-22-05 22:57:40) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:57:40) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 22:57:40) Bad IE-pages: (none)
(4-22-05 22:57:40) Stealth-String not found
(4-22-05 22:57:40) No locked Files to delete. End without Reboot


(4-22-05 23:00:36) SPSeHjFix started v1.1.2
(4-22-05 23:00:36) OS: WinXP (5.1.2600)
(4-22-05 23:00:36) Language: svenska
(4-22-05 23:00:36) Win-Path: C:\WINDOWS
(4-22-05 23:00:36) System-Path: C:\WINDOWS\System32
(4-22-05 23:00:36) Temp-Path: C:\DOCUME~1\Pontus\LOKALA~1\Temp\
(4-22-05 23:00:38) Disinfection started
(4-22-05 23:00:38) Bad-Dll(IEP): (not found)
(4-22-05 23:00:38) Bad-Dll(IEP) in BHO: (not found)
(4-22-05 23:00:38) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 23:00:38) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 23:00:38) Bad IE-pages: (none)
(4-22-05 23:00:38) Stealth-String not found
(4-22-05 23:00:38) Not infected->END


(4-22-05 23:06:57) SPSeHjFix started v1.1.2
(4-22-05 23:06:57) OS: WinXP (5.1.2600)
(4-22-05 23:06:57) Language: svenska
(4-22-05 23:06:57) Win-Path: C:\WINDOWS
(4-22-05 23:06:57) System-Path: C:\WINDOWS\System32
(4-22-05 23:06:57) Temp-Path: C:\DOCUME~1\Pontus\LOKALA~1\Temp\
(4-22-05 23:07:01) Disinfection started
(4-22-05 23:07:01) Bad-Dll(IEP): (not found)
(4-22-05 23:07:01) Bad-Dll(IEP) in BHO: (not found)
(4-22-05 23:07:01) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 23:07:01) UBF: 4 - UBB: 1 - UBR: 15
(4-22-05 23:07:01) Bad IE-pages: (none)
(4-22-05 23:07:01) Stealth-String not found
(4-22-05 23:07:01) Not infected->END


(4-22-05 23:13:24) SPSeHjFix started v1.1.2
(4-22-05 23:13:24) OS: WinXP (5.1.2600)
(4-22-05 23:13:24) Language: svenska
(4-22-05 23:13:24) Win-Path: C:\WINDOWS
(4-22-05 23:13:24) System-Path: C:\WINDOWS\System32
(4-22-05 23:13:24) Temp-Path: C:\DOCUME~1\Pontus\LOKALA~1\Temp\
(4-22-05 23:13:27) Disinfection started
(4-22-05 23:13:27) Bad-Dll(IEP): (not found)
(4-22-05 23:13:27) Bad-Dll(IEP) in BHO: (not found)
(4-22-05 23:13:27) UBF: 4 - UBB: 0 - UBR: 13
(4-22-05 23:13:27) UBF: 4 - UBB: 0 - UBR: 13
(4-22-05 23:13:27) Bad IE-pages: (none)
(4-22-05 23:13:27) Stealth-String not found
(4-22-05 23:13:27) Not infected->END
You didn't do anything wrong. We still have some fixing to do.

I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {FA72B7B8-21F5-118B-EFBB-A3F57457DA8D} - C:\WINDOWS\system32\syszs.dll

O4 - HKLM\..\Run: [b13] "C:\y.exe "

O4 - HKLM\..\Run: [syszs.exe] C:\WINDOWS\system32\syszs.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office\OSA9.EXE

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\d3oy32.exe" /s (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.



Search for and delete these files if listed:
C:\y.exe
C:\WINDOWS\d3oy32.exe
C:\WINDOWS\system32\syszs.exe


Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi LDTate!!

Thanks for responding to my post, I really appretiate that you take the time!

…and sorry for not responding earlier, I been away for the weekend…

I printed out and followed your instructions thoroughly.

My computer seems faster (or is just my imagination?) and my IE start page is back to normal again!
It seems as if my comp. is fine again?!?!

Here my latest log:

Logfile of HijackThis v1.99.1
Scan saved at 21:39:49, on 2005-04-25
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\Smartscaps.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ICO.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program\Delade filer\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\tbctray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program\Steam\Steam.exe
C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program\hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\system32\tbctray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] C:\Program\Steam\Steam.exe -silent
O4 - Global Startup: Certificate Mover.lnk = C:\Documents and Settings\Pontus\Skrivbord\SmartTrust Personal\Csp\SmartCertmover.exe
O4 - Global Startup: D-Link AirPlus G+ Wireless Adapter Utility.lnk = C:\Program\D-Link\D-Link AirPlus G+ Wireless Adapter Utility\DWLGTI.EXE
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program\Delade filer\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1113129253077
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartTrust Smart Card Server (Smartscaps) - SmartTrust - C:\WINDOWS\system32\Smartscaps.exe
Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D


MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is around on the internet. Please go to
http://v5.windowsupdate.microsoft.com/v5co…t.aspx?ln=en-us]Microsoft Windows and Internet Explorer Updates to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI