This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log - Computer only starts in safe mod

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After starting up my computer in safe mode and running Adaware, Spybot, and Norton Corporate Antivirus, my computer now only boots up in Safe mode, despite my attempts to run in normal mode/last mode that worked/etc… I read somewhere to use Hijack This and post the log here to try and fix this problem. So thanks in advance for any help, as it is greatly appreciated! Anyways, here it is:

Logfile of HijackThis v1.99.1
Scan saved at 4:27:59 PM, on 5/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Symantec AntiVirus\DefWatch.exe
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\Program Files\Logitech\iTouch\iTouch.exe
F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\PROGRA~1\SYMANT~2\VPTray.exe
F:\Program Files\DriveCrypt\DriveCrypt.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Logitech\MouseWare\system\em_exec.exe
F:\Program Files\AIM\aim.exe
F:\Program Files\Spyware Doctor\swdoctor.exe
F:\Program Files\Spam Monitor\SpamMonitor.Exe
F:\Program Files\D-Link AirPlus G\AirPlus.exe
F:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = F:\WINDOWS\about.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.lib.ucdavis.edu/proxy/pacserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://channels.netscape.com/ns/men/default.jsp"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - F:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - F:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DCPPaid] F:\WINDOWS\system32\DCPPaid.exe /P
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [QD FastAndSafe] F:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] F:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "F:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "F:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [vptray] F:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [DriveCrypt Startup] F:\Program Files\DriveCrypt\DriveCrypt.exe /WS
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Spyware Doctor] "F:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [Spam Monitor] F:\Program Files\Spam Monitor\SpamMonitor.Exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - F:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - F:\WINDOWS\System32\shdocvw.dll (HKCU)
O12 - Plugin for .csm: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_KR.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} - http://www.wildtangent.com/webdrivers/webi…ave/Install.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {4CCD14FC-FE13-4CA7-B35E-2942BFE830D9} (Liveweb_SE Class) - http://206.67.236.76/updatefiles/liveweb_se.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partner…nds/install.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O20 - Winlogon Notify: NavLogon - F:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - F:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - F:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello ucdchrisco,
There is very little in the log to indicate what the problem is but I suspect there may be a problem on your other drives that is causing it. There is one entry that leads me to believe that there is a severe infection somewhere just waiting to show. This infection often hides and then suddenly takes over.

Would you please let me know what OS's you have on the other drives, if any? If there is another windows drive, please do an HJT scan of each drive with an OS on it and post them using Add Reply. Please indicate which log is for which drive and OS.

We will use a couple of programs to get rid of the line I see in your log that is bad and the next log may show the full infection because it is when you try to delete it that it shows up.

First We will use CWShredder :

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates

3. CLOSE ALL WINDOWS except CWShredder

4. Run the program by clicking 'fix' and letting it fix all CWS remnants.

5. REBOOT to finish the removal and clear memory.

6. Please SCAN with HijackThis and put a check mark beside the following entry :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = F:\WINDOWS\about.htm


7. Click fix checked

8. SCAN again with HijackThis

9. POST the logfile here in this thread using 'Add Reply' to determine what is in the log now.
I only have one hard drive currently attached. I followed your instructions, and here is the latest HJT log file. Thanks again for your help.

Logfile of HijackThis v1.99.1
Scan saved at 9:50:33 PM, on 6/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Symantec AntiVirus\DefWatch.exe
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\Program Files\Logitech\iTouch\iTouch.exe
F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\PROGRA~1\SYMANT~2\VPTray.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\AIM\aim.exe
F:\Program Files\Logitech\MouseWare\system\em_exec.exe
F:\Program Files\D-Link AirPlus G\AirPlus.exe
F:\Program Files\SpySubtract\SpySub.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.lib.ucdavis.edu/proxy/pacserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://channels.netscape.com/ns/men/default.jsp"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] F:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "F:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "F:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [vptray] F:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: SpySubtract.lnk = F:\Program Files\SpySubtract\SpySub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .csm: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_KR.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} - http://www.wildtangent.com/webdrivers/webi…ave/Install.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {4CCD14FC-FE13-4CA7-B35E-2942BFE830D9} (Liveweb_SE Class) - http://206.67.236.76/updatefiles/liveweb_se.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partner…nds/install.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O20 - Winlogon Notify: NavLogon - F:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - F:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - F:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi ucdchrisco,

The log looks pretty clean just a few active X controls that we will clean up. When I asked about the 'drives' I also meant 'partitions'. I look at your log and it shows me that Windows is installed to your F:\ drive. Could you please tell me what is on C:\, D:\ and E:\. Are the multiple users on this computer? If so, that is probably where the infection is.

Step#1

To remove the Active X controls, please scan again with HijackThis and put a check mark beside each entry listed below:

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} - http://www.wildtangent.com/webdrivers/webi…ave/Install.cab

O16 - DPF: {4CCD14FC-FE13-4CA7-B35E-2942BFE830D9} (Liveweb_SE Class) - http://206.67.236.76/updatefiles/liveweb_se.cab

O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partner…nds/install.cab


all of the above will reinstall the next time you visit the website if they are legitimate


Step#2

Scan each partition with HJT (you must be an administrator to do this)

Post each log file here using Add Reply with each log labeled so that you know which log is from which partition

Step#3

Scan F:\ again with HijackThis and post another new log file to make sure nothing is showing now.

Good Luck!
I don't have a C drive currently because at one point I bought a new hardrive, installed the new one as drive F, transferred the information from C to F and then ditched my C drive. D and E are CD/DVD burners. Here is the latest log of my only hard drive (which is not partitioned):

Logfile of HijackThis v1.99.1
Scan saved at 7:07:11 AM, on 6/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Symantec AntiVirus\DefWatch.exe
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\system32\userinit.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\Program Files\Logitech\iTouch\iTouch.exe
F:\Program Files\Ahead\InCD\InCD.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\PROGRA~1\SYMANT~2\VPTray.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Logitech\MouseWare\system\em_exec.exe
F:\Program Files\AIM\aim.exe
F:\Program Files\D-Link AirPlus G\AirPlus.exe
F:\Program Files\SpySubtract\SpySub.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.lib.ucdavis.edu/proxy/pacserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://channels.netscape.com/ns/men/default.jsp"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] F:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] F:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] F:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "F:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "F:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [vptray] F:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [THGuard] "F:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = ?
O4 - Global Startup: SpySubtract.lnk = F:\Program Files\SpySubtract\SpySub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe
O12 - Plugin for .csm: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O20 - Winlogon Notify: NavLogon - F:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - F:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - F:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks
Hello ucdchrisco,
Are you still having the problem of booting only in Safe Mode? The HijackThis log is clean. I would like you to boot into windows, safe mode it fine, and do the following:

Go To Start –>Run and Type Msconfig in the box and click Enter

When the system configuration utility opens do the following:

1) On the General Tab make sure that Normal Startup is selected. Click Apply if it is highlighted.

2) On the Boot.INI Tab make sure there are NO check marks in any of the boxes. Click Apply if it is highlighted

3) ClickOK

4) REBOOT to normal mode if possible

5) Scan again with HijackThis

6) Post a new log file in this thread using Add Reply



3. Click
It is still booting in only safe mode, even when normal startup is selected. However, in msconfig, I do not have a boot.ini tab (wierdly enough) there is only general, system.ini, win.ini, services, and startup tabs. Here is a HJT scan log after restarting with as little running as possible (all services/startup/system/win.ini checkboxes removed except for bare essentials):

Logfile of HijackThis v1.99.1
Scan saved at 11:26:12 AM, on 6/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\userinit.exe
F:\WINDOWS\Explorer.EXE
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.lib.ucdavis.edu/proxy/pacserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://channels.netscape.com/ns/men/default.jsp"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://F%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (F:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\r7f4li1w.slt\prefs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - F:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://F:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe
O12 - Plugin for .csm: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: F:\Program Files\Internet Explorer\Plugins\npchime.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/zuma/popcaploader_v5.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O20 - Winlogon Notify: NavLogon - F:\WINDOWS\system32\NavLogon.dll

Thanks again
Hello ucdchrisco,
There seems to be a problem that I am going to have to spend a little more time looking into for you. In the meantime could you answer a couple of questions to help narrow down the source.

1) What were your initial symptoms?

2) why did you originally run AdAware, Spybot and Norton Corporate AV?

3) what was found by each and did you fix anything? If so, do you have the backups that each program makes when it fixes items?

4)Was your computer upgraded to XP from Win 2K? If so, which version and was it updated before upgrading to XP?

5)You can only boot into safe mode. What I need to know is: when you boot to your desktop, what indicates to you that you are in safe mode and not in normal mode?

6) have you received any Windows errors when using your computer? Blue Screens or other indication that there are errors?

7) Is this URL your normal home page in IE : (has been made unuseable due to file download when clicked) hxxp://www.lib.ucdavis.edu/proxy/pacserve . Do you recognize it at all?

8) are all your programs working?

9) Do you have another computer available for use while cleaning this one?


Please answer each of the questions and also download and run this small tool to determine if you have any hidden bad files.


1. Please download DllCompare

2. Start the Program with its default settings and put a check mark in include subdirectories. Click the Run Locate.com and wait until the scan says complete.

3. Click the Compare button to start the next process.

4. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

5. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply to receive further instructions.

8 Scan again with HijackThis and post a new log file here using Add Reply with the log from DllCompare.

Good Luck!
I relisted your questions with answers following. Thanks for taking the time to help me out with this strange problem. 1) What were your initial symptoms? There were no initial symptoms, see #2 2) why did you originally run AdAware, Spybot and Norton Corporate AV? I used to run all three programs about twice a month just to make sure I didn't pick anything up, and to remove anything i had. 3) what was found by each and did you fix anything? If so, do you have the backups that each program makes when it fixes items? I will post another post as soon as i can get the info, but i believe all the programs above were set to create backups, so i will check (although I have a feeling the list of items caught by the programs will be too long to post here) 4)Was your computer upgraded to XP from Win 2K? If so, which version and was it updated before upgrading to XP? no, i built the computer myself last year and immediately installed xp. 5)You can only boot into safe mode. What I need to know is: when you boot to your desktop, what indicates to you that you are in safe mode and not in normal mode? besides it loading in classic mode (looks diff) than xp mode, i can also tell because the sound and printer drivers are not running. 6) have you received any Windows errors when using your computer? Blue Screens or other indication that there are errors? no other errors or blue screens at all before or after this problem 7) Is this URL your normal home page in IE : (has been made unuseable due to file download when clicked) hxxp://www.lib.ucdavis.edu/proxy/pacserve . Do you recognize it at all? this is not my normal home page, but it allows me to access my schools secure online library. 8) are all your programs working? yes, but currently without sound. 9) Do you have another computer available for use while cleaning this one? Yes, the one i am using to post replies currently
do you have the log from DllCompare? If you can find the AdAware log from that session it also would be helpful. thanks
If i do a scan with dllcompare and start the program with its default settings (searches windows/system32 for *.dll's), including subdirectories, i get no file names in the lower window.
Hello ucdchrisco,
Sorry for the delay. Would you please try changing the setting for the location to search to C:\Windows and see if any appear in the bottom window with that setting.


1. Please change the setting for the location to search to C:\Windows and see if any appear in the bottom window with that setting. Put a check mark in subdirectories. Click the Run Locate.com and wait until the scan says complete.

2. Click the Compare button to start the next process.

3. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

4. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan

5. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

6. Click the Make a Log of what was found button, and post the log even if it shows no files here in this thread using Add Reply with your new HijackThis log.

7 Scan again with HijackThis and post a new log file here using Add Reply with the log from DllCompare.

Good Luck!
as your HijackThis log is over 7 days old would you please scan again and post a new log file with the log from DLLCompare together in this thread so that I can assess your situation properly. I require all of the information I have asked for to be able to give you more instructions thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI