This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need some help

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm trying to clean up a friends computer. I've run spybot and adaware. I also ran cwshredder. He had tons of processes running - I took a guess on many of them and quarantined them with a shareware program I downloaded. I deleted his temporary internet files as well; all this to at least eliminate some junk before I ran the hijack this log. Here it is:

Logfile of HijackThis v1.99.1
Scan saved at 12:21:06 AM, on 5/23/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WTOOLSA.EXE
C:\WINDOWS\SYSTEM\APINL.EXE
C:\WINDOWS\IEEX.EXE
C:\WINDOWS\MFCHN.EXE
C:\WINDOWS\SYSTEM\D3CC.EXE
C:\WINDOWS\MSVS.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\SYSTEM\IPCE.EXE
C:\WINDOWS\SYSTEM\IEPF.EXE
C:\WINDOWS\JAVAGA.EXE
C:\WINDOWS\JAVAAO.EXE
C:\WINDOWS\MFCVT.EXE
C:\WINDOWS\APPXA.EXE
C:\WINDOWS\IEAX.EXE
C:\WINDOWS\SYSTEM\MFCIP.EXE
C:\WINDOWS\SYSTEM\NTXL.EXE
C:\WINDOWS\SYSTEM\ADDWW.EXE
C:\WINDOWS\IEET.EXE
C:\WINDOWS\SDKID.EXE
C:\WINDOWS\ADDTZ.EXE
C:\WINDOWS\SYSTEM\IPIF.EXE
C:\WINDOWS\SYSTEM\APPII.EXE
C:\WINDOWS\SYSTEM\IERV.EXE
C:\WINDOWS\SYSTEM\MSED.EXE
C:\WINDOWS\MSCE.EXE
C:\WINDOWS\MSDR32.EXE
C:\WINDOWS\SYSTEM\JAVAZR.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WSUP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\QUICKENW\QAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EBATESMOEMONEYMAKER0.EXE
C:\WINDOWS\SYSTEM\ADDRP32.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\QUICKENW\QWDLLS.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
C:\WINDOWS\SYSTEM\MRTMNGR.EXE
C:\WINDOWS\MFCHN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\IEEX.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EBATESMOEMONEYMAKER1.EXE
C:\WINDOWS\MFCHN.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\bfaqg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by DELL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {BA99F0F7-81BA-A3D0-11AE-7FAE337FF72F} - C:\WINDOWS\MSEL32.DLL
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [CRDD.EXE] C:\WINDOWS\SYSTEM\CRDD.EXE
O4 - HKLM\..\Run: [ADDRP32.EXE] C:\WINDOWS\SYSTEM\ADDRP32.EXE
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServices: [APINL.EXE] C:\WINDOWS\SYSTEM\APINL.EXE /s
O4 - HKLM\..\RunServices: [IEEX.EXE] C:\WINDOWS\IEEX.EXE /s
O4 - HKLM\..\RunServices: [MFCHN.EXE] C:\WINDOWS\MFCHN.EXE /s
O4 - HKLM\..\RunServices: [D3CC.EXE] C:\WINDOWS\SYSTEM\D3CC.EXE /s
O4 - HKLM\..\RunServices: [MSVS.EXE] C:\WINDOWS\MSVS.EXE /s
O4 - HKLM\..\RunServices: [SYSMV.EXE] C:\WINDOWS\SYSTEM\SYSMV.EXE /s
O4 - HKLM\..\RunServices: [IPCE.EXE] C:\WINDOWS\SYSTEM\IPCE.EXE /s
O4 - HKLM\..\RunServices: [IEPF.EXE] C:\WINDOWS\SYSTEM\IEPF.EXE /s
O4 - HKLM\..\RunServices: [JAVAGA.EXE] C:\WINDOWS\JAVAGA.EXE /s
O4 - HKLM\..\RunServices: [JAVAAO.EXE] C:\WINDOWS\JAVAAO.EXE /s
O4 - HKLM\..\RunServices: [MFCVT.EXE] C:\WINDOWS\MFCVT.EXE /s
O4 - HKLM\..\RunServices: [APPXA.EXE] C:\WINDOWS\APPXA.EXE /s
O4 - HKLM\..\RunServices: [IEAX.EXE] C:\WINDOWS\IEAX.EXE /s
O4 - HKLM\..\RunServices: [MFCIP.EXE] C:\WINDOWS\SYSTEM\MFCIP.EXE /s
O4 - HKLM\..\RunServices: [NTXL.EXE] C:\WINDOWS\SYSTEM\NTXL.EXE /s
O4 - HKLM\..\RunServices: [ADDWW.EXE] C:\WINDOWS\SYSTEM\ADDWW.EXE /s
O4 - HKLM\..\RunServices: [IEET.EXE] C:\WINDOWS\IEET.EXE /s
O4 - HKLM\..\RunServices: [SDKID.EXE] C:\WINDOWS\SDKID.EXE /s
O4 - HKLM\..\RunServices: [ADDTZ.EXE] C:\WINDOWS\ADDTZ.EXE /s
O4 - HKLM\..\RunServices: [IPIF.EXE] C:\WINDOWS\SYSTEM\IPIF.EXE /s
O4 - HKLM\..\RunServices: [APPII.EXE] C:\WINDOWS\SYSTEM\APPII.EXE /s
O4 - HKLM\..\RunServices: [IERV.EXE] C:\WINDOWS\SYSTEM\IERV.EXE /s
O4 - HKLM\..\RunServices: [MSED.EXE] C:\WINDOWS\SYSTEM\MSED.EXE /s
O4 - HKLM\..\RunServices: [MSCE.EXE] C:\WINDOWS\MSCE.EXE /s
O4 - HKLM\..\RunServices: [MSDR32.EXE] C:\WINDOWS\MSDR32.EXE /s
O4 - HKLM\..\RunServices: [JAVAZR.EXE] C:\WINDOWS\SYSTEM\JAVAZR.EXE /s
O4 - HKLM\..\RunServicesOnce: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: Ebates - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Dell Home - {5E0F7D80-483F-11D4-A837-60DB4AC12700} - http://www.dellnet.com/ (file missing) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {2FF18E20-DE11-11D1-8161-00A0C90DD90C} (MSNBC News Menu Control 3.01) - http://www.msnbc.com/download/nr1228.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//paxan/main.chm::/load.exe

I'm sure tons of this carp** can be eliminated. I appreciate your help - thanks.
You have a severe infection called About Blank. To remove this infection you need to download several small free programs and follow the directions very carefully.

During the fix you also can have no contact with the internet AND must also keep Internet Explorer closed or the infection will be reinstalled.

I am first going to ask you to download the programs to clean with and then have you disconnect from the internet and use the programs to clean your computer.


Please copy and paste this entire set of instructions into Wordpad (Start>Programs>Accessories>Wordpad) so that you have them available while disconnected from the internet You may also want to print them.


Step#1 - Show All Hidden Filesr

We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the View menu and click Folder Options.
* Select the View Tab.
* In the Hidden files section select Show all files.
* Click OK.



Step#2 - CWShredder For use Later

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates



Step#3 - Start Dreck For use Later

This program may expose the hidden file or we may need the following program to do it.
  • Download StartDreck.
  • b]Unzip to a folder of its own
  • Please Do Not Use It Yet
Step#4 - DLLCompare For use Later

This infection continues to reinstall itself through a hidden dll which we have to find and remove.
  • Please download DllCompare
  • Please Do Not Use It Yet
Step#5 - Ad-Aware SE For use Later

This is part of the fix and Ad-Aware SE must be setup the following way and be used at the specific step it is listed at

1. Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan

2.Close ALL windows except Ad-Aware SE

3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window

1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days

2) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

3) Click on the ‘Advanced’ button on the left and select in green:

Under Shell Integration:
*Move deleted files to recycle bin

Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information

Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT

4) Click the ‘Tweak’ button and select in green:

Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only

Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot

Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile

5. Click on ‘Proceed’ to save the settings.



Step#6 - About Buster For use Later

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip. link fixed

2. Once it is downloaded extract it to c:\aboutbuster. Please Do Not Use It Yet



Step#7 - Getting A StartDreck Log

open the program:

Click 'Config'
Click 'Unmark All'

2. Please put a check mark beside the following boxes only:
Under Registry -> Run Keys
Under System/drivers -> Running processes

3. Click 'Ok'.

4. Click 'Save' and select the location to save the log file (if you do not choose, the log will be saved in the folder that the application is in).

5. Open the log where you saved it and select all, then copy the paste the log into your next thread using 'Add Reply' after all the steps are completed



Step#8 - Getting A DLLCompare Log

1. Start DLLCompare with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

2. Click the Compare button to start the next process.

3. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

4. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply after completing all the steps.



Disconnect from the internet and disconnect your cable or phone line so there is no chance of contacting the internet until your computer is cleaner.



Step#9 - Fixing With CWShredder

1. Open CWShredder keeping ALL OTHER WINDOWS CLOSED

2. Run the program by clicking 'fix' and letting it fix all CWS remnants.

3. REBOOT to finish the removal and clear memory.




Step#10 - Uninstall Bad Programs

The following programs are malware You can find replacements for them once your computer is clean and read about the
Safe Programs
Please go to Start > Control Panel > Add Remove Programs and uninstall each of the following if they are there:
  • Weatherbug
  • Ebates MoneyMaker
  • Wintools

Step#11 - Fixing With HijackThis

1. Scan again with HijackThis (ALL WINDOWS CLOSED EXCEPT HJT)

2. Put a check mark beside each of the following entries in the HJT window

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\bfaqg.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {BA99F0F7-81BA-A3D0-11AE-7FAE337FF72F} - C:\WINDOWS\MSEL32.DLL

O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL

O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EbatesMoeMoneyMaker0.exe"

O4 - HKLM\..\Run: [CRDD.EXE] C:\WINDOWS\SYSTEM\CRDD.EXE

O4 - HKLM\..\Run: [ADDRP32.EXE] C:\WINDOWS\SYSTEM\ADDRP32.EXE

O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE

O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE

O4 - HKLM\..\RunServices: [APINL.EXE] C:\WINDOWS\SYSTEM\APINL.EXE /s

O4 - HKLM\..\RunServices: [IEEX.EXE] C:\WINDOWS\IEEX.EXE /s

O4 - HKLM\..\RunServices: [MFCHN.EXE] C:\WINDOWS\MFCHN.EXE /s

O4 - HKLM\..\RunServices: [D3CC.EXE] C:\WINDOWS\SYSTEM\D3CC.EXE /s

O4 - HKLM\..\RunServices: [MSVS.EXE] C:\WINDOWS\MSVS.EXE /s

O4 - HKLM\..\RunServices: [SYSMV.EXE] C:\WINDOWS\SYSTEM\SYSMV.EXE /s

O4 - HKLM\..\RunServices: [IPCE.EXE] C:\WINDOWS\SYSTEM\IPCE.EXE /s

O4 - HKLM\..\RunServices: [IEPF.EXE] C:\WINDOWS\SYSTEM\IEPF.EXE /s

O4 - HKLM\..\RunServices: [JAVAGA.EXE] C:\WINDOWS\JAVAGA.EXE /s

O4 - HKLM\..\RunServices: [JAVAAO.EXE] C:\WINDOWS\JAVAAO.EXE /s

O4 - HKLM\..\RunServices: [MFCVT.EXE] C:\WINDOWS\MFCVT.EXE /s

O4 - HKLM\..\RunServices: [APPXA.EXE] C:\WINDOWS\APPXA.EXE /s

O4 - HKLM\..\RunServices: [IEAX.EXE] C:\WINDOWS\IEAX.EXE /s

O4 - HKLM\..\RunServices: [MFCIP.EXE] C:\WINDOWS\SYSTEM\MFCIP.EXE /s

O4 - HKLM\..\RunServices: [NTXL.EXE] C:\WINDOWS\SYSTEM\NTXL.EXE /s

O4 - HKLM\..\RunServices: [ADDWW.EXE] C:\WINDOWS\SYSTEM\ADDWW.EXE /s

O4 - HKLM\..\RunServices: [IEET.EXE] C:\WINDOWS\IEET.EXE /s

O4 - HKLM\..\RunServices: [SDKID.EXE] C:\WINDOWS\SDKID.EXE /s

O4 - HKLM\..\RunServices: [ADDTZ.EXE] C:\WINDOWS\ADDTZ.EXE /s

O4 - HKLM\..\RunServices: [IPIF.EXE] C:\WINDOWS\SYSTEM\IPIF.EXE /s

O4 - HKLM\..\RunServices: [APPII.EXE] C:\WINDOWS\SYSTEM\APPII.EXE /s

O4 - HKLM\..\RunServices: [IERV.EXE] C:\WINDOWS\SYSTEM\IERV.EXE /s

O4 - HKLM\..\RunServices: [MSED.EXE] C:\WINDOWS\SYSTEM\MSED.EXE /s

O4 - HKLM\..\RunServices: [MSCE.EXE] C:\WINDOWS\MSCE.EXE /s

O4 - HKLM\..\RunServices: [MSDR32.EXE] C:\WINDOWS\MSDR32.EXE /s

O4 - HKLM\..\RunServices: [JAVAZR.EXE] C:\WINDOWS\SYSTEM\JAVAZR.EXE /s

O4 - HKLM\..\RunServicesOnce: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot

O8 - Extra context menu item: Ebates - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\Sy350\Tp350\scri350a.htm (HKCU)

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
<—Optional but believed to bring adware with it

O16 - DPF: {2FF18E20-DE11-11D1-8161-00A0C90DD90C} (MSNBC News Menu Control

O16 - DPF: {10000000-1000-0000-1000-000000000000} -
ms-its:mhtml:file://C:\MAIN.MHT!http://d.dialer2004.com//paxan/main.chm::/load.exe



3. Click 'fix checked

4. REBOOT into SAFE MODE by pressing F8 repeatedly while booting up to remove the files and folders.

5. In Safe Mode please FIND and DELETE the following files and Folders: Please also look in C:\Windows and C:\Windows\System\ for other files of the same name with the ending 'DAT' or 'DLL'.
and delete those as well. You also may find other similar files, you can check the properties of them and if the same as these files, delete those too.


C:\WINDOWS\SYSTEM\APINL.EXE
C:\WINDOWS\IEEX.EXE
C:\WINDOWS\MFCHN.EXE
C:\WINDOWS\SYSTEM\D3CC.EXE
C:\WINDOWS\MSVS.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\SYSTEM\IPCE.EXE
C:\WINDOWS\SYSTEM\IEPF.EXE
C:\WINDOWS\JAVAGA.EXE
C:\WINDOWS\JAVAAO.EXE
C:\WINDOWS\MFCVT.EXE
C:\WINDOWS\APPXA.EXE
C:\WINDOWS\IEAX.EXE
C:\WINDOWS\SYSTEM\MFCIP.EXE
C:\WINDOWS\SYSTEM\NTXL.EXE
C:\WINDOWS\SYSTEM\ADDWW.EXE
C:\WINDOWS\IEET.EXE
C:\WINDOWS\SDKID.EXE
C:\WINDOWS\ADDTZ.EXE
C:\WINDOWS\SYSTEM\MSVS.EXE
C:\WINDOWS\SYSTEM\APPII.EXE
C:\WINDOWS\SYSTEM\IERV.EXE
C:\WINDOWS\SYSTEM\MSED.EXE
C:\WINDOWS\MSCE.EXE
C:\WINDOWS\MSDR32.EXE
C:\WINDOWS\SYSTEM\JAVAZR.EXE
C:\WINDOWS\SYSTEM\ADDRP32.EXE
C:\WINDOWS\MFCHN.EXE
C:\WINDOWS\IEEX.EXE
C:\WINDOWS\SYSTEM\IPIF.EXE
C:\PROGRAM FILES\EBATES_MOEMONEYMAKER\EbatesMoeMoneyMaker0.exe
C:\WINDOWS\SYSTEM\CRDD.EXE
C:\WINDOWS\SYSTEM\ADDRP32.EXE
C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
C:\WINDOWS\SYSTEM\APINL.EXE
C:\WINDOWS\IEEX.EXE
C:\WINDOWS\MFCHN.EXE
C:\WINDOWS\SYSTEM\D3CC.EXE
C:\WINDOWS\MSVS.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\SYSTEM\IPCE.EXE
C:\WINDOWS\SYSTEM\IEPF.EXE
C:\WINDOWS\JAVAGA.EXE
C:\WINDOWS\JAVAAO.EXE
C:\WINDOWS\MFCVT.EXE
C:\WINDOWS\APPXA.EXE
C:\WINDOWS\IEAX.EXE
C:\WINDOWS\SYSTEM\MFCIP.EXE
C:\WINDOWS\SYSTEM\NTXL.EXE
C:\WINDOWS\SYSTEM\ADDWW.EXE
C:\WINDOWS\IEET.EXE
C:\WINDOWS\SDKID.EXE
C:\WINDOWS\ADDTZ.EXE
C:\WINDOWS\SYSTEM\IPIF.EXE /s
C:\WINDOWS\SYSTEM\APPII.EXE
C:\WINDOWS\SYSTEM\IERV.EXE
C:\WINDOWS\SYSTEM\MSED.EXE
C:\WINDOWS\MSCE.EXE
C:\WINDOWS\MSDR32.EXE
C:\WINDOWS\SYSTEM\JAVAZR.EXE
C:\Program Files\Common Files\WinTools <– folder
C:\Program Files\Toolbar <– folder
C:\WINDOWS\SYSTEM\SERVICES\MSXMIDI.EXE
C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot
C:\WINDOWS\bfaqg.dll



6. REBOOT into normal mode

7. If none of the files listed above are found please check for them now that you are in normal mode. If found please attempt to delete them in normal mode.


Step#12 - Fixing With Ad-Aware SE

1. Click ‘Start’

*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

2. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.

3. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window

4. Save the log file when it asks and then click ‘finish’

5. REBOOT to complete the removal of what Ad-Aware SE found




Step#13 - Fixing With About Buster

1. Navigate to the c:\aboutbuster directory and

2. double-click on aboutbuster.exe When the tool is open press the OK button

3. Press the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files.

If it asks if you would like to do a second scan, allow it to do so and keep running it until .

4. Post the log file in your next reply


Step#14:Registry Edit

Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

**Reconnect to the Internet Now and Finish With an Online AV Scan and a HijackThis log**


Step#15 - Complete an Online AntiVirus Scan

Run an online antivirus scan at:

Trend Micro Online AV

Reboot



Step#16 - Scan With HijackThis

1. please SCAN again with HJT and

2. POST a new HJT log file here in this thread using 'Add Reply' as well as the logs from StartDreck, DLLCompare and About Buster. This infection deletes some system files which still will need to be replaced.


Good Luck!
Thanks for your reply. However, I can't follow your instructions for configuring Ad-Aware - many of the settings you listed aren't there. I'm guessing your instructions were for an earlier version. Can you double check the Ad-Aware setup for me? I don't want to proceed until I know what I'm doing is correct.
The settings are for AdAware SE personal which is available from: AdAware SE If you have the previous version it is no longer supported and you will be unable to update the definitions for it. Please Download and install and then set it up according to the instructions above. Please continue the steps in order as this is one of the most important things with this infection. If you have trouble with this link please use the one above.

Good Luck!
This is driving me nuts. I've downloaded the programs you listed, but I can't start the cleanup process, because I can't get Ad-Aware to work properly. When I install it, it gives an error message at the end saying the definitions file was not installed properly. If I try to update the definitions file, it seems to be downloading, then when it gets to 100%, it say there was an error contacting the server, please try later. I have tried this several different ways, including safe mode, and emailing myself the updated definitions file from my computer and then placing it in the Ad-Aware directory, but I still get the same message. Any ideas? Thanks again.
Hello MrAtoZ It sounds like Ad-Aware has been attacked by the infection this happens occasionally and it makes it impossible to use until the infection is gone. Since it has been a couple of days since I gave you the instructions, there is probably a change in your log which if not corrected before you do the steps I gave you, will just have to be done again. So I suggest that you close all windows except HijackThis Please scan again and post your log here using AddReply. I will be available for the next 1 1/2 hours so if you post it I will be able to give you the steps to take to start removing the infection. Please try to keep the computer on until I get back to you and please also do not REBOOT. Use Internet Explorer as little as possible please. Good Luck!
Thanks again for all your help. Just so you know, I did clean up some of the things that needed to be deleted hoping that might allow Ad-Aware to install properly, and I am not using IE at all. I am using Firefox for what it's worth. That helps a lot on my own computer. Here's the new log. I will stay online a while and watch for a reply.

Logfile of HijackThis v1.99.1
Scan saved at 8:39:41 PM, on 6/4/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\MFCQC.EXE
C:\WINDOWS\MSYT32.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\SYSTEM\NTNO.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\MFCYI.EXE
C:\WINDOWS\MSWX32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\QUICKENW\QAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\WINDOWS\SYSTEM\CRDD.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\QUICKENW\QWDLLS.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\SYSTEM\MRTMNGR.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\elnxo.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by DELL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {6F5238D0-58CA-ADF4-63DE-FD4A5FF51173} - C:\WINDOWS\MFCKA32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [CRDD.EXE] C:\WINDOWS\SYSTEM\CRDD.EXE
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [MFCQC.EXE] C:\WINDOWS\MFCQC.EXE /s
O4 - HKLM\..\RunServices: [MSYT32.EXE] C:\WINDOWS\MSYT32.EXE /s
O4 - HKLM\..\RunServices: [MFCYP.EXE] C:\WINDOWS\MFCYP.EXE /s
O4 - HKLM\..\RunServices: [NTNO.EXE] C:\WINDOWS\SYSTEM\NTNO.EXE /s
O4 - HKLM\..\RunServices: [SYSMV.EXE] C:\WINDOWS\SYSTEM\SYSMV.EXE /s
O4 - HKLM\..\RunServices: [MFCYI.EXE] C:\WINDOWS\MFCYI.EXE /s
O4 - HKLM\..\RunServices: [MSWX32.EXE] C:\WINDOWS\MSWX32.EXE /s
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Dell Home - {5E0F7D80-483F-11D4-A837-60DB4AC12700} - http://www.dellnet.com/ (file missing) (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
That was very strange. This thread seemed to disappear and re-appear ..kept telling me there was no data in it. I am posting this while I work on the answer to make sure I can post to this thread.
Well it seems I was able to post now let's see how the fix goes. It will be the same steps as before but I am omitting Ad-Aware until you are clean. It seems you have picked up a few new files, but we'll get them all by the end and you did a good job cleaning out some of the other junk!

I think you have already made all files visible and downloaded the tools/programs I asked you to, but I am leaving the instructions here in case you didn't. If you have downloaded everything please start by disconnecting from the internet, making sure IE and Outlook Express are closed and start with Step #6 after copying and pasting the instructions to Wordpad.

During the fix you also can have no contact with the internet AND must also keep Internet Explorer closed or the infection will be reinstalled.

I am first going to ask you to download the programs to clean with and then have you disconnect from the internet and use the programs to clean your computer.


Please copy and paste this entire set of instructions into Wordpad (Start>Programs>Accessories>Wordpad) so that you have them available while disconnected from the internet You may also want to print them.


Step#1 - Show All Hidden Filesr

We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the View menu and click Folder Options.
* Select the View Tab.
* In the Hidden files section select Show all files.
* Click OK.



Step#2 - CWShredder For use Later

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates



Step#3 - Start Dreck For use Later

This program may expose the hidden file or we may need the following program to do it.
  • Download StartDreck.
  • b]Unzip to a folder of its own
  • Please Do Not Use It Yet
Step#4 - DLLCompare For use Later

This infection continues to reinstall itself through a hidden dll which we have to find and remove.
  • Please download DllCompare
  • Please Do Not Use It Yet
Step#5 - About Buster For use Later

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip. link fixed

2. Once it is downloaded extract it to c:\aboutbuster. Please Do Not Use It Yet



Disconnect from the internet and disconnect your cable or phone line so there is no chance of contacting the internet until your computer is cleaner.


Step#6 - Getting A StartDreck Log

open the program:

Click 'Config'
Click 'Unmark All'

2. Please put a check mark beside the following boxes only:
Under Registry -> Run Keys
Under System/drivers -> Running processes

3. Click 'Ok'.

4. Click 'Save' and select the location to save the log file (if you do not choose, the log will be saved in the folder that the application is in).

5. Open the log where you saved it and select all, then copy the paste the log into your next thread using 'Add Reply' after all the steps are completed



Step#7 - Getting A DLLCompare Log

1. Start DLLCompare with its default settings and put a check mark in the include subdirectories. Click the Run Locate.com and wait until the scan says complete.

2. Click the Compare button to start the next process.

3. Files in the upper portion have been verified to "exist", Files in the bottom section were not able to be accessed. Very few files should be listed in the bottom section when the Compare scan is complete.

4. Click on each of the listed entries in the lower section to select them. Right-click on the file and use the Option Rescan

6. This will cause Windows Find to see if the file does exist, and then it will be removed from the list (to reduce the number of identified files)

7. Click the Make a Log of what was found button, and post the log here in this thread using Add Reply after completing all the steps.




Step#8 - Fixing With CWShredder

1. Open CWShredder keeping ALL OTHER WINDOWS CLOSED

2. Run the program by clicking 'fix' and letting it fix all CWS remnants.

3. REBOOT to finish the removal and clear memory.



Step#9 - Use HijackThis to Delete the following:


1. Scan again with HijackThis (ALL WINDOWS CLOSED EXCEPT HJT)

2. Put a check mark beside each of the following entries in the HJT window


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\elnxo.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {6F5238D0-58CA-ADF4-63DE-FD4A5FF51173} - C:\WINDOWS\MFCKA32.DLL

O4 - HKLM\..\Run: [CRDD.EXE] C:\WINDOWS\SYSTEM\CRDD.EXE

O4 - HKLM\..\RunServices: [MFCQC.EXE] C:\WINDOWS\MFCQC.EXE /s

O4 - HKLM\..\RunServices: [MSYT32.EXE] C:\WINDOWS\MSYT32.EXE /s

O4 - HKLM\..\RunServices: [MFCYP.EXE] C:\WINDOWS\MFCYP.EXE /s

O4 - HKLM\..\RunServices: [NTNO.EXE] C:\WINDOWS\SYSTEM\NTNO.EXE /s

O4 - HKLM\..\RunServices: [SYSMV.EXE] C:\WINDOWS\SYSTEM\SYSMV.EXE /s

O4 - HKLM\..\RunServices: [MFCYI.EXE] C:\WINDOWS\MFCYI.EXE /s

O4 - HKLM\..\RunServices: [MSWX32.EXE] C:\WINDOWS\MSWX32.EXE /s

O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
<–if this one is legit it will be re-installed the next time you visit the website


3. Click 'fix checked

4. REBOOT into SAFE MODE by pressing F8 repeatedly while booting up to remove the files and folders.

5. In Safe Mode please FIND and DELETE the following files and Folders: Please also look in C:\Windows and C:\Windows\System\ for other files of the same name with the ending 'DAT' or 'DLL'.
and delete those as well. You also may find other similar files, you can check the properties of them and if the same as these files, delete those too.



C:\WINDOWS\MFCKA32.DLL
C:\WINDOWS\elnxo.dll
C:\WINDOWS\MFCQC.EXE
C:\WINDOWS\MSYT32.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\MFCYI.EXE
C:\WINDOWS\MSWX32.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\MFCYP.EXE
C:\WINDOWS\SYSTEM\NTNO.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE
C:\WINDOWS\SYSTEM\CRDD.EXE
C:\WINDOWS\SYSTEM\SYSMV.EXE



b]REBOOT into normal mode

7. If none of the files listed above are found please check for them now that you are in normal mode. If found please attempt to delete them in normal mode.



Step#10 - Fixing With About Buster

1. Navigate to the c:\aboutbuster directory and

2. double-click on aboutbuster.exe When the tool is open press the OK button

3. Press the Start button, then the OK button, and then finally the Yes button. It will start scanning your computer for files.

If it asks if you would like to do a second scan, allow it to do so and keep running it until .

4. Post the log file in your next reply



Step#11:Registry Edit

Copy the contents of the Quote Box below to Notepad.
Name the file as fix.reg
Change the Save as Type to All Files
and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

**Reconnect to the Internet Now and Finish With an Online AV Scan and a HijackThis log**


Step#12 - Complete an Online AntiVirus Scan

Run an online antivirus scan at:

Trend Micro Online AV

Bitdefender AV scan

eTrust AV web scanner(Computer Associates)


Reboot



Step#13 - Scan With HijackThis

1. please SCAN again with HJT and

2. POST a new HJT log file here in this thread using 'Add Reply' as well as the logs from StartDreck, DLLCompare and About Buster. This infection deletes some system files which still will need to be replaced.


Good Luck!
Here's the latest. I got through everything you requested. I ran the bitdefender scan, and it found 27 viruses, 270 infected files, and deleted 301 files. However, there were two that it couldn't fix or delete, I guess - it said the update failed. One is aim95.exe in the AIM directory, which is obviously AOL's Instant Messenger, and the other is wxbug.exe, in the AIM\sysfiles\ directory. Should I delete either or both of those? Otherwise, the HJT log looks pretty clean, although I'm not the expert. You also mentioned some system files that needed to be restored.


Logfile of HijackThis v1.99.1
Scan saved at 2:42:04 AM, on 6/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\QUICKENW\QAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\SYSTEM\MRTMNGR.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\QUICKENW\QWDLLS.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by DELL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Dell Home - {5E0F7D80-483F-11D4-A837-60DB4AC12700} - http://www.dellnet.com/ (file missing) (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
—————————————————–

Start Drek Log

StartDreck (build 2.1.7 public stable) - 2005-06-04 @ 23:23:50 (GMT -04:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2600.0000
Logged in as Default at H39Y10B

»Registry
»Run Keys
»Current User
»Run
*MoneyAgent="C:\Program Files\Microsoft Money\System\Money Express.exe"
*PPWebCap=C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
»RunOnce
»Default User
»Run
*MoneyAgent="C:\Program Files\Microsoft Money\System\Money Express.exe"
*PPWebCap=C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
»RunOnce
»Local Machine
»Run
*SystemTray=SysTray.Exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*AudioHQ=C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
*CTSysVol=C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
*Adaptec DirectCD=C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
*POINTER=C:\Program Files\Microsoft Hardware\Mouse\point32.exe
*QAGENT=C:\QUICKENW\QAGENT.EXE
*LoadQM=loadqm.exe
*WinampAgent="C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
*Share-to-Web Namespace Daemon=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
*StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE
*RealTray=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
*QuickTime Task="C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
*ViewMgr=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
*CRDD.EXE=C:\WINDOWS\SYSTEM\CRDD.EXE
*CreateCD=C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
»RunOnce
»RunServices
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SchedulingAgent=mstask.exe
*MFCQC.EXE=C:\WINDOWS\MFCQC.EXE /s
*MSYT32.EXE=C:\WINDOWS\MSYT32.EXE /s
*MFCYP.EXE=C:\WINDOWS\MFCYP.EXE /s
*NTNO.EXE=C:\WINDOWS\SYSTEM\NTNO.EXE /s
*SYSMV.EXE=C:\WINDOWS\SYSTEM\SYSMV.EXE /s
*MFCYI.EXE=C:\WINDOWS\MFCYI.EXE /s
*MSWX32.EXE=C:\WINDOWS\MSWX32.EXE /s
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Files
»System/Drivers
»Running Processes
+FF0F210B=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFF76A7=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFF61D7=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFF461B=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFFD1FF=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFFDDFF=C:\WINDOWS\MFCQC.EXE
+FFFFC5DF=C:\WINDOWS\MSYT32.EXE
+FFFFCCCF=C:\WINDOWS\MFCYP.EXE
+FFFE3E6B=C:\WINDOWS\SYSTEM\NTNO.EXE
+FFFE2A4B=C:\WINDOWS\SYSTEM\SYSMV.EXE
+FFFE125B=C:\WINDOWS\MFCYI.EXE
+FFFE05AF=C:\WINDOWS\MSWX32.EXE
+FFFE592F=C:\WINDOWS\EXPLORER.EXE
+FFFAD6AB=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFF92CCB=C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
+FFF91E1B=C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
+FFF9704B=C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
+FFF9550F=C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
+FFF9A457=C:\QUICKENW\QAGENT.EXE
+FFF987FB=C:\WINDOWS\LOADQM.EXE
+FFF9F31B=C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
+FFF9251B=C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
+FFF9FE77=C:\WINDOWS\SYSTEM\STIMON.EXE
+FFF9EC9F=C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
+FFF9DF3B=C:\WINDOWS\SYSTEM\QTTASK.EXE
+FFF8120B=C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
+FFF81EC3=C:\WINDOWS\SYSTEM\CRDD.EXE
+FFF81363=C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
+FFF725EF=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
+FFF70D23=C:\QUICKENW\QWDLLS.EXE
+FFF6627F=C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
+FFF66EF7=C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
+FFF5C7D7=C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
+FFF8EF0B=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFF23A77=C:\WINDOWS\MFCYP.EXE
+FFF26CE3=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF25E7B=C:\WINDOWS\SYSTEM\SYSMV.EXE
+FFF74A0F=C:\WINDOWS\SYSTEM\MRTMNGR.EXE
+FFF8AD4B=C:\WINDOWS\MFCYP.EXE
+F7D1C887=C:\WINDOWS\SYSTEM\TAPISRV.EXE
+FA4A8177=C:\WINDOWS\MFCYP.EXE
+FBA10E57=C:\STARTDREK\STARTDRECK.EXE
»Application specific
————————————————

DLL Compare Log

* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________

C:\WINDOWS\SYSTEM\oleaut32.dll Wed May 8 2002 6:34:52p ..SH. 929,792 908.00 K
C:\WINDOWS\SYSTEM\olepro32.dll Wed May 8 2002 6:34:52p ..SH. 229,376 224.00 K
________________________________________________

6,174 items found: 6,174 files (2 H/S), 0 directories.
Total of file sizes: 180,350,170 bytes 171.99 M

——————–End log———————

ABOUT BUSTER LOG

AboutBuster 5.0 reference file 28
Scan started on [6/5/05] at [1:10:52 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\gqjty.dat
Removed File! : C:\Windows\fnayo.dat
Removed File! : C:\Windows\rcvbcv.dat
Removed File! : C:\Windows\iwtgf.dat
Removed File! : C:\Windows\fqnst.dat
Removed File! : C:\Windows\estliz.dat
Removed File! : C:\Windows\zyysx.dat
Removed File! : C:\Windows\xlerdk.dat
Removed File! : C:\Windows\hmwwfm.dat
Removed File! : C:\Windows\tozqr.dat
Removed File! : C:\Windows\ozmlc.dat
Removed File! : C:\Windows\ntsiix.dat
Removed File! : C:\Windows\tdpns.dat
Removed File! : C:\Windows\wbdth.dat
Removed File! : C:\Windows\lwzqk.dat
Removed File! : C:\Windows\kykmf.dat
Removed File! : C:\Windows\mivkg.dat
Removed File! : C:\Windows\ebthx.dat
Removed File! : C:\Windows\fijcc.dat
Removed File! : C:\Windows\otyvw.dat
Removed File! : C:\Windows\lxlgp.dat
Removed File! : C:\Windows\gbchf.dat
Removed File! : C:\Windows\kfatw.dat
Removed File! : C:\Windows\ukpav.dll
Removed File! : C:\Windows\oadohb.dat
Removed File! : C:\Windows\hbvbbl.dat
Removed File! : C:\Windows\orwqoq.dat
Removed File! : C:\Windows\sxucxj.dat
Removed File! : C:\Windows\kqnirt.dat
Removed File! : C:\Windows\drfnte.dat
Removed File! : C:\Windows\ggwlc.dll
Removed File! : C:\Windows\qfwbw.dll
Removed File! : C:\Windows\vezmt.dll
Removed File! : C:\Windows\jpvfz.dll
Removed File! : C:\Windows\mbfzxf.dat
Removed File! : C:\Windows\xuxerh.dat
Removed File! : C:\Windows\uksxl.dll
Removed File! : C:\Windows\whnrg.dll
Removed File! : C:\Windows\pvqkls.dat
Removed File! : C:\Windows\ipqnm.dll
Removed File! : C:\Windows\jlygg.dll
Removed File! : C:\Windows\puzjs.dll
Removed File! : C:\Windows\ulipb.dll
Removed File! : C:\Windows\ozktw.dll
Removed File! : C:\Windows\vqqri.dat
Removed File! : C:\Windows\foddog.dat
Removed File! : C:\Windows\qpwiqq.dat
Removed File! : C:\Windows\zsmhh.dat
Removed File! : C:\Windows\olyuw.dll
Removed File! : C:\Windows\ptqac.dat
Removed File! : C:\Windows\zutty.dat
Removed File! : C:\Windows\higcx.dll
Removed File! : C:\Windows\vxxds.dll
Removed File! : C:\Windows\qzwgpl.dat
Removed File! : C:\Windows\jmddg.dll
Removed File! : C:\Windows\cfhcyk.dat
Removed File! : C:\Windows\bsyim.dat
Removed File! : C:\Windows\ttjog.dat
Removed File! : C:\Windows\uugcb.dll
Removed File! : C:\Windows\dwrpl.dat
Removed File! : C:\Windows\wkvxs.dat
Removed File! : C:\Windows\hxzba.dll
Removed File! : C:\Windows\hwiff.dll
Removed File! : C:\Windows\jgnwb.dll
Removed File! : C:\Windows\qqjibm.dat
Removed File! : C:\Windows\tjmbxz.dat
Removed File! : C:\Windows\mkfgaj.dat
Removed File! : C:\Windows\xaxda.dll
Removed File! : C:\Windows\cannl.dll
Removed File! : C:\Windows\bfzpo.dll
Removed File! : C:\Windows\zctpmm.dat
Removed File! : C:\Windows\puedr.dll
Removed File! : C:\Windows\kmefm.dat
Removed File! : C:\Windows\fyuvx.dll
Removed File! : C:\Windows\hnjtr.dat
Removed File! : C:\Windows\kbhga.dll
Removed File! : C:\Windows\wmvjy.dat
Removed File! : C:\Windows\shjmrk.dat
Removed File! : C:\Windows\xsvodh.dat
Removed File! : C:\Windows\surmte.dat
Removed File! : C:\Windows\hiztl.dll
Removed File! : C:\Windows\awikt.dll
Removed File! : C:\Windows\dqbtyn.dat
Removed File! : C:\Windows\csugl.dll
Removed File! : C:\Windows\zeail.dll
Removed File! : C:\Windows\enbbs.dll
Removed File! : C:\Windows\uvvvh.dll
Removed File! : C:\Windows\fyjjx.dll
Removed File! : C:\Windows\lvwocq.dat
Removed File! : C:\Windows\ufrux.dll
————————————————
Scan was COMPLETED SUCCESSFULLY at 1:16:56 AM
The two hidden files that were found by DLLCompare are legitimate files and belong to IE 6.0.

Step#1:Removing Infected Program

I suggest you start by uninstalling AIM through Start>Settings>Control Panel>Add Remove Programs and reinstall a clean version later. The Aim95.exe is a virus, not the real start file for AIM. We will delete it along with the wxbug.exe
You will probably need the following special program to delete them:



Step#2:Find infected Files

**please search for and FIND the location of each of the files. Make a Notepad file containing all of the files and their locations that need to be deleted with Killbox including the two below. If you find them in more than one location add each location to the list to be killboxed. You must have the exact location eg C:\ProgramFiles\XXX\XXX.exe or C:\Windows\System\….. You are making the notepad file temporarily to have somewhere to keep the list until you have all of them.


Step#3:Download and Use Killbox

Download: Killbox

Unzip the folder to your desktop.

Open Killbox.exe - Select "Delete on Reboot".

- Copy and Paste the following 2 files into your notepad file of infected files:

C:\PROGRAM FILES\AIM\AIM.EXE
C:\PROGRAM FILES\AIM\sysfiles\wxbug.exe


- Now highlight the contents of the Notepad file with ALL of the infected file names and locations in it and copy ALL using CTRL-C or 'select all'

- Return to Killbox, go to the File menu, and In the field "Full Path of File to Delete" choose "Paste from Clipboard".

- Press the "Delete File" button that looks like a red circle with a white X in it.

- Click "Yes" at the Delete on Reboot prompt.

- Killbox will tell you that all listed files will be deleted on next reboot.. Click YES

- When it asks if you would like to Reboot now, click YES.

- If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually.

- Your computer will reboot and check to see if the file is gone.

- Reboot your computer into Safe Mode

- Then Navigate to the location of each of the files and/or folders (Do not be concerned if they do not exist) that you identified in the notepad file, and Delete them
.
- Reboot your computer to go back to normal mode



Step#4:Removing added Files

Please go to C:\Windows and look for files that were created within the approximate time of the infection and are either 0 byte, 12 byte or 13 bytes. There also may be others but they should look like the ones deleted in the last post. Check Properties to verify that they are infected files because legitimate files will be copyrighted to Microsoft

Now go to C:\Windows\System and check this folder as you did for C:\Windows



Step#5:Replacing Deleted System Files


If any are missing or not working properly then you can download new copies from
Merijn's Files and following the instructions at that site to have them where they belong for your OS.

[*]If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32


[*]Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.


[*]This infection often deletes some system files that need to be replaced.

Now we need to see if we need to restore some deleted files:
  • Please check for the following files using the Windows Search Engine:
  • control.exe
  • rundll32.exe
  • wmplayer.exe
  • msconfig.exe
  • notepad.exe
  • shell.dll
  • SDHelper.dll
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button

Step#6:Reset System Restore
  • If you are using Windows ME you need to reset System Restore to clean the old backups out that are infected:

    1. Right-click My Computer and then click Properties.
    2. On the Performance tab, click File System
    3. On the Troubleshooting tab, click to select Disable System Restore
    4. Click OK twice
    5. Restart your computer.

    6. Right-click My Computer and again click Properties
    7. On the Performance tab, click File System
    8. Clear the check mark in Disable System Restore check box.
    9. System Restore is now be active again.


Step#7:Online AV scan

We'll try again with this
Run an online antivirus scan at:

Trend Micro Online AV

Reboot



Step#8:Update IE 6

Your copy of Internet Explorer eeds to be updated. You may also have some critical updates from Microsoft for this OS. Without the updates your computer will be defenseless against the infections that are everywhere on the internet. Critical updates for both Windows and Internet Explorer, are available at: Microsoft Windows and Internet Explorer Updates to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update





Step#9:General CleanUp
  • A cleanup that will help is to go to Start>Programs>Acccessories>System Tools> Disk Cleanup and put a check mark beside all the entries in the disk cleanup window that ask you what you want to clean. Clean all hard drives and all files. This will get rid of any malware that is hiding in the temporary folders.

  • Make sure that all Internet Temp files are gone, by checking the folders that the Temporary Internet Files and Temp files are stored in. To do so use Control Panel > Internet Options(or right click the IE icon on the desktop and choose Properties). Click Delete Files on the General Tab - place a check in the Delete all offline content box, then 'Clear History' and then press OK

  • Empty your Recycle Bin


  • Double Check the following folders to make sure they are empty:
  • C:\WINDOWS\Profiles\your account\Temporary Internet Files
    Delete all the files in (and any subfolders of) the C:\Windows\Temp\ folder

  • You may find that you have to repeat the steps a couple of times.




  • Step#10:Another Start Dreck Log Please

    open StartDreck

    Click 'Config'
    Click 'Unmark All'

    2. Please put a check mark beside the following boxes only:
    Under Registry -> Run Keys
    Under System/drivers -> Running processes

    3. Click 'Ok'.

    4. Click 'Save' and select the location to save the log file (if you do not choose, the log will be saved in the folder that the application is in).

    5. Open the log where you saved it and select all, then copy the paste the log into your next thread using 'Add Reply' after all the steps are completed



    Step#11:Post a New HijackThis Log

    1. Scan again with HijackThis

    2. POST your log file to see if there is anything left to fix


    ** In cases where many system files are missing you have no alternative but to have them insert their Windows OS disk and run sfc /scannow from the Run box if able or from Recovery Console if not able to get into windows

    Good Luck!
BIG NOTE: I posted this originally about 15 minutes ago, but realized I may not have done a reboot before the start drek and hijack this logs, so I rebooted, and am reposting with new logs.


I didn’t need Killbox to remove AIM, I did it with Add/Remove programs with no problem. I double checked, and the files are gone.

As far as Step#4:Removing added Files, I have no idea when he got this/these infection/s. I suspect many of the files were added over time. I looked through the 12 and 13k files, and see nothing to worry about. I noticed the first time it seemed like most of the exe files that needed to be deleted were 12k, and the ones that came back later were 16k, but in any case I see nothing there to worry about now. As far as the 0k files, he has almost 5600 of them. There is no way I can go through all of those, even if I weed out log and txt files.

I downloaded hoster a couple of times, but when I unzipped it, I got nothing. I don’t know how important that one is, but it didn’t work for me.

I think the only missing files were control.exe, shell.dll, and sdhelper.dll – I restored them.

He has 98 SE, so I skipped Step 6.

As far as the Trend Micro scan, I was not able to do that. I don’t think it’s a problem with his machine, I couldn’t do it on mine, and my brother tried his, too, no luck. Maybe a server problem on the other end? Should I run bitdefender again, or the other one you listed?

I tried to update his version of IE, but got a message at the MS website that they were having problems, to try again later. As far as Office, it says it will take a few hours, and I’m hoping you will tell me he can do that after I give his computer back to him.

I did the General Clean Up you suggested (I had already done that manually), and there was over 15 M of old Scan Disk files – I deleted them, too.

So, hoping that I am in pretty good shape, here’s the latest Drek log:

StartDreck (build 2.1.7 public stable) - 2005-06-05 @ 20:05:05 (GMT -04:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2600.0000
Logged in as Default at H39Y10B

»Registry
»Run Keys
»Current User
»Run
*MoneyAgent="C:\Program Files\Microsoft Money\System\Money Express.exe"
*PPWebCap=C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
»RunOnce
»Default User
»Run
*MoneyAgent="C:\Program Files\Microsoft Money\System\Money Express.exe"
*PPWebCap=C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
»RunOnce
»Local Machine
»Run
*SystemTray=SysTray.Exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*AudioHQ=C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
*CTSysVol=C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
*Adaptec DirectCD=C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
*POINTER=C:\Program Files\Microsoft Hardware\Mouse\point32.exe
*QAGENT=C:\QUICKENW\QAGENT.EXE
*LoadQM=loadqm.exe
*WinampAgent="C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
*Share-to-Web Namespace Daemon=C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
*StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE
*RealTray=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
*QuickTime Task="C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
*ViewMgr=C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
*CreateCD=C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
+OptionalComponents
+IMAIL
*Installed=1
+MAPI
*NoChange=1
*Installed=1
+MAPI
*NoChange=1
*Installed=1
»RunOnce
»RunServices
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SchedulingAgent=mstask.exe
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»Files
»System/Drivers
»Running Processes
+FF0F56DD=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFF0171=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFF1601=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFF31CD=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFFA241=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFFB759=C:\WINDOWS\EXPLORER.EXE
+FFFEE53D=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFE9AE9=C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
+FFFEA8E5=C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
+FFFD406D=C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
+FFFD6CD5=C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
+FFFD0B0D=C:\QUICKENW\QAGENT.EXE
+FFFD37ED=C:\WINDOWS\LOADQM.EXE
+FFFDC5AD=C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
+FFFDC9E9=C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
+FFFDD2E5=C:\WINDOWS\SYSTEM\STIMON.EXE
+FFFD8BF9=C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
+FFFE9FC9=C:\WINDOWS\SYSTEM\QTTASK.EXE
+FFFE9DB1=C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
+FFFC45D9=C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
+FFFC805D=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
+FFFC97D9=C:\QUICKENW\QWDLLS.EXE
+FFFBFDD9=C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
+FFFBAD8D=C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
+FFFA9CB1=C:\WINDOWS\SYSTEM\MRTMNGR.EXE
+FFF93189=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFF9ED11=C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
+FFFC7349=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF893DD=C:\WINDOWS\SYSTEM\RNAAPP.EXE
+FFF8BCC9=C:\WINDOWS\SYSTEM\TAPISRV.EXE
+FFF83A6D=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\WINWORD.EXE
+FFF7E375=C:\PROGRAM FILES\MICROSOFT WORKS\MSWORKS.EXE
+FFF6634D=C:\WINDOWS\SYSTEM\SPOOL32.EXE
+FFF6CC25=C:\STARTDREK\STARTDRECK.EXE
»Application specific

And here’s the latest HJT:

Logfile of HijackThis v1.99.1
Scan saved at 8:03:49 PM, on 6/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\QUICKENW\QAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\PROGRAM FILES\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\QUICKENW\QWDLLS.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\DLLCMD32.EXE
C:\PROGRAM FILES\COMMON FILES\EFAX\HOTTRAY.EXE
C:\WINDOWS\SYSTEM\MRTMNGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by DELL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\PROGRAM FILES\CREATIVE\SURROUNDMIXER\CTSYSVOL.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [QAGENT] C:\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [PPWebCap] C:\PROGRA~1\SCANSOFT\PAPERP~1\PPWebCap.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Dell Home - {5E0F7D80-483F-11D4-A837-60DB4AC12700} - http://www.dellnet.com/ (file missing) (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab


Whether I am done now or not, even if you give me something else to do, do you think when I return this he can update Office and IE on his own, or does that need to be done before something else is done?
Hi MrAtoz,
The logs are CLEAN! Congratulations.

There is no problem with having the owner of this computer do the updates, it is just important that someone updates because this is probably the reason he was infected in the first place. Although MS doesn't support 98SE any longer, they do occasionally issue a critical update for it and there have been a few since they stopped supporting 98. IE should be kept completely up-to-date with the latest version as MS does support it and leaving it without updates will leave the computer unprotected on the internet.

I also suggest that you have him read the following article and also install some of the small free programs available for protection that are mentioned in it. Windows 98 is very easy to infect because it is no longer supported and updated as other OS's
"How Did I Get Infected In The First Place"

Good Luck!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI