This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help. whats running

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Having problems with an unknown program that still is running.
XP with spybot1.3 and NAV 2002 prior to problem.
Loaded Microsoft antispy beta which seemed to contain but not eliminate prob.
started reading and have since loaded cwshredder,adaware and still have problems.Mainly start up inspector shows upto about 60 programs in run once file. Microsoft anti spy continously showing startup programs tring to run or bho changes. Where and what is it?? I'm a novice at this.
Have run adaware/spybot in safe mode till all is clear then restarted. CWshredder showed nothing. Delete runonce contents from regedit every am

Log attached

Logfile of HijackThis v1.99.1
Scan saved at 2:32:19 PM, on 5/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\iptp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Documents and Settings\default\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gyoqn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gyoqn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\gyoqn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xphvg.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xphvg.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xphvg.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\ebhhv.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {FF234288-3F3D-AAD1-5406-2B255A30CA94} - C:\WINDOWS\ippv32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1424.0\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iptp.exe] C:\WINDOWS\iptp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [ntiz32.exe] C:\WINDOWS\system32\ntiz32.exe
O4 - HKLM\..\RunOnce: [atlji32.exe] C:\WINDOWS\atlji32.exe
O4 - HKLM\..\RunOnce: [wintj.exe] C:\WINDOWS\wintj.exe
O4 - HKLM\..\RunOnce: [ieie.exe] C:\WINDOWS\ieie.exe
O4 - HKLM\..\RunOnce: [appbd.exe] C:\WINDOWS\appbd.exe
O4 - HKLM\..\RunOnce: [netme.exe] C:\WINDOWS\system32\netme.exe
O4 - HKLM\..\RunOnce: [sysza32.exe] C:\WINDOWS\system32\sysza32.exe
O4 - HKLM\..\RunOnce: [msxv.exe] C:\WINDOWS\system32\msxv.exe
O4 - HKLM\..\RunOnce: [msrp32.exe] C:\WINDOWS\msrp32.exe
O4 - HKLM\..\RunOnce: [ipdi32.exe] C:\WINDOWS\ipdi32.exe
O4 - HKLM\..\RunOnce: [ntkq32.exe] C:\WINDOWS\system32\ntkq32.exe
O4 - HKLM\..\RunOnce: [ieoz32.exe] C:\WINDOWS\system32\ieoz32.exe
O4 - HKLM\..\RunOnce: [sysop.exe] C:\WINDOWS\system32\sysop.exe
O4 - HKLM\..\RunOnce: [iexq.exe] C:\WINDOWS\system32\iexq.exe
O4 - HKLM\..\RunOnce: [atlmf32.exe] C:\WINDOWS\atlmf32.exe
O4 - HKLM\..\RunOnce: [mssh32.exe] C:\WINDOWS\mssh32.exe
O4 - HKLM\..\RunOnce: [ievh.exe] C:\WINDOWS\system32\ievh.exe
O4 - HKLM\..\RunOnce: [d3dh.exe] C:\WINDOWS\d3dh.exe
O4 - HKLM\..\RunOnce: [apptw.exe] C:\WINDOWS\system32\apptw.exe
O4 - HKLM\..\RunOnce: [appnn.exe] C:\WINDOWS\appnn.exe
O4 - HKLM\..\RunOnce: [sysrz.exe] C:\WINDOWS\sysrz.exe
O4 - HKLM\..\RunOnce: [apihp32.exe] C:\WINDOWS\system32\apihp32.exe
O4 - HKLM\..\RunOnce: [addnk32.exe] C:\WINDOWS\addnk32.exe
O4 - HKLM\..\RunOnce: [ntcp32.exe] C:\WINDOWS\system32\ntcp32.exe
O4 - HKLM\..\RunOnce: [d3vo.exe] C:\WINDOWS\d3vo.exe
O4 - HKLM\..\RunOnce: [atlpz.exe] C:\WINDOWS\system32\atlpz.exe
O4 - HKLM\..\RunOnce: [d3pz32.exe] C:\WINDOWS\d3pz32.exe
O4 - HKLM\..\RunOnce: [sdkzg.exe] C:\WINDOWS\system32\sdkzg.exe
O4 - HKLM\..\RunOnce: [d3vy32.exe] C:\WINDOWS\system32\d3vy32.exe
O4 - HKLM\..\RunOnce: [mfcqp32.exe] C:\WINDOWS\mfcqp32.exe
O4 - HKLM\..\RunOnce: [ient.exe] C:\WINDOWS\system32\ient.exe
O4 - HKLM\..\RunOnce: [msbx32.exe] C:\WINDOWS\system32\msbx32.exe
O4 - HKLM\..\RunOnce: [ntrn.exe] C:\WINDOWS\ntrn.exe
O4 - HKLM\..\RunOnce: [ieew.exe] C:\WINDOWS\ieew.exe
O4 - HKLM\..\RunOnce: [ipjt.exe] C:\WINDOWS\system32\ipjt.exe
O4 - HKLM\..\RunOnce: [iede.exe] C:\WINDOWS\iede.exe
O4 - HKLM\..\RunOnce: [d3tu.exe] C:\WINDOWS\d3tu.exe
O4 - HKLM\..\RunOnce: [atlca32.exe] C:\WINDOWS\atlca32.exe
O4 - HKLM\..\RunOnce: [sdkrp.exe] C:\WINDOWS\system32\sdkrp.exe
O4 - HKLM\..\RunOnce: [d3kq32.exe] C:\WINDOWS\d3kq32.exe
O4 - HKLM\..\RunOnce: [d3zl.exe] C:\WINDOWS\d3zl.exe
O4 - HKLM\..\RunOnce: [msep.exe] C:\WINDOWS\msep.exe
O4 - HKLM\..\RunOnce: [apibs.exe] C:\WINDOWS\apibs.exe
O4 - HKLM\..\RunOnce: [crqh32.exe] C:\WINDOWS\system32\crqh32.exe
O4 - HKLM\..\RunOnce: [winut.exe] C:\WINDOWS\system32\winut.exe
O4 - HKLM\..\RunOnce: [mstw.exe] C:\WINDOWS\mstw.exe
O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\system32\netgt32.exe
O4 - HKLM\..\RunOnce: [atlkl.exe] C:\WINDOWS\atlkl.exe
O4 - HKLM\..\RunOnce: [javayu32.exe] C:\WINDOWS\javayu32.exe
O4 - HKLM\..\RunOnce: [javars.exe] C:\WINDOWS\system32\javars.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Ask Jeeves Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Dictionary Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection-word
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: eCrew Delta Technology V13100 - http://ecrew.delta-air.com/classes/cst/eCrew13100.cab
O16 - DPF: eCrew Delta Technology V13112 - http://ecrew.delta-air.com/classes/cst/eCrew13112.cab
O16 - DPF: eCrew Delta Technology V1381 - http://10.1.44.53/classes/cst/eCrew1381.cab
O16 - DPF: eCrew Delta Technology V1397 - http://10.1.44.53/classes/cst/eCrew1397.cab
O16 - DPF: eCrew Delta Technology V1410 - http://ecrew.delta-air.com/classes/cst/eCrew1410.cab
O16 - DPF: eCrew Delta Technology V14102 - http://ecrew.delta-air.com/eCrew14102.cab
O16 - DPF: eCrew Delta Technology V14120 - http://ecrew.delta-air.com/eCrew14120.cab
O16 - DPF: eCrew Delta Technology V14141 - http://ecrew.delta-air.com/eCrew14141.cab
O16 - DPF: eCrew Delta Technology V14169 - http://ecrew.delta-air.com/eCrew14169.cab
O16 - DPF: eCrew Delta Technology V14170 - http://ecrew.delta-air.com/eCrew14170.cab
O16 - DPF: eCrew Delta Technology V14180 - http://ecrew.delta-air.com/eCrew14180.cab
O16 - DPF: eCrew Delta Technology V14200 - http://ecrew.delta-air.com/eCrew14200.cab
O16 - DPF: eCrew Delta Technology V1451 - http://ecrew.delta-air.com/eCrew1451.cab
O16 - DPF: eCrew Delta Technology V1472 - http://ecrew.delta-air.com/eCrew1472.cab
O16 - DPF: eCrew Delta Technology V1486 - http://ecrew.delta-air.com/eCrew1486.cab
O16 - DPF: eCrew Delta Technology V1491 - http://ecrew.delta-air.com/eCrew1491.cab
O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) - http://diagnostics.support.hp.com/motivedo…w/ipgaxctrl.cab
O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} (AJ Installer Control) - http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093355041187
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {C3498BF0-2C07-43C8-99D0-434B038334A6} (VDLaunch Class) - http://www.catharon.com/download/plugins/ievdl2.ocx
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://carpoint.msn.com/components/ocx/aut…/autopricer.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?312
O17 - HKLM\System\CCS\Services\Tcpip\..\{14EA2617-642C-41BE-8C9D-F9ECEA618A6A}: NameServer = 198.6.100.6 198.6.1.6
O17 - HKLM\System\CS1\Services\Tcpip\..\{14EA2617-642C-41BE-8C9D-F9ECEA618A6A}: NameServer = 198.6.100.6 198.6.1.6
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netjo.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello av8tor You have a new variant of Cool Web Search, among other possible parasites. I'll have a closer look at your HJT log and will reply as soon as possible.
Hi av8tor

As I said, you have a variant of Cool Web Search. This variant requires special handling and programs in addition to CWShredder.

You also have that problem with those 04 Run Once entries. Refrence to those, it wouldn't do much good for me to tell you which ones to remove, since you are removing them each AM and they may not be the same ones as you had when you last posted. So, I'm going to ask that you do not delete them and do not reboot until advised by me to do so. At best, this is going to be difficult, so lets make it as easy as possible, by working closely together.

We'll tackle that CWS infection and one other first and when that is fixed, we will get to the other problems.

Go to Start > Run and type in Services.msc then click OK

Click the Extended tab.

Scroll down until you find the service. Remote Procedure Call (RPC) Helper

Click once on the service to highlight it.

Click Stop

Right-Click on the service. Remote Procedure Call (RPC) Helper

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The service should now be stopped and disabled.

Next:

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • (Be sure to update it now.)
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare AboutBuster for use:
    • Download AboutBuster.
    • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
    • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
    • Click "OK" at the prompt with instructions.
    • Click "Update" and then "Check For Update" to begin the update process.
    • If any updates exist please download them by clicking "Download Update".
    • You should not run the program yet so click "Exit".
Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.

[*]Run CWShredder:
  • Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".

[*]Run AboutBuster and save the logs:
  • Browse to where you saved AboutBuster and run AboutBuster.exe.
  • Click "OK" at the directions Read: Important! prompt.
  • Click "Start" and then "OK" to allow AboutBuster to scan for Alternate Data Streams.
  • Click "Yes" at the About:Buster prompt to allow it to shutdown explorer.exe.
  • Please wait while AboutBuster scans your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so. RUN ABOUTBUSTER TWO TIMES, WITH A REBOOT IN BETWEEN AND A REBOOT AFTER.
  • When it has finished, click "Save Log…". Make sure you save it as I will need a copy of it.
  • Click "Exit" and "Exit" again to exit AboutBuster.

[*]Clean out temporary files:
  • Start | Run | type cleanmgr | OK
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Click "OK" to remove them.
  • Click "Yes" to confirm the deletion.

[*]Restart your computer normally to return to normal mode.

[*]Free TrendMicro Housecall scan:
  • Vist the TrendMicro Housecall website.
  • Select your country from the drop-down list and click "Go".
  • Choose "Yes" at the ActiveX Security Warning prompt.
  • Please wait while the Housecall engine is updated.
  • Select the drives to be scanned by placing a check in their respective boxes.
  • Check the "Auto Clean" box.
  • Click "SCAN" in order to begin scanning your system.
  • Please be patient while Housecall scans your system for malicious files.
  • If not auto-cleaned, remove anything it finds.
  • Click "Close" to exit the Housecall scanner.
  • Choose "Yes" at the HouseCall message prompt.

Then, Please REBOOT, FOR THE LAST TIME, UNTIL YOU HEAR FROM ME AGAIN.

[*]Prepare your reply:

    [*]Please post a fresh HijackThis log

    [*]Please post the AboutBuster log.

    [*]Please note any complications you had.


    Please post in this string, using the Post Reply function, so I will be notified.

    Please do not reboot again, until after you have heard from me and have applied the upcoming fix on the Hijack This log you are about to post.
    Hi Piatan. First Thanks for your reply. Here's the situation so far with more to follow (if you still want it) -RPC Helper. Found it but was unable to "stop" after highlighting it. Stop was there but was not a function avail (does that make sense. it was dim and would not accept the input). I was able to go to properties and use the drop down menu to disable. IN safe mode -cwshredder (v2.14)run with no problems found -About buster run. Here is the Log: Scanned at: 10:34:14 AM on: 5/29/2005 – Scan 1 ————————— About:Buster Version 4.0 Reference List : 26 ADS not scanned System(FAT) Removed 4 Random Key Entries Removed! : C:\WINDOWS\cfnzb.dat Removed! : C:\WINDOWS\vvgdm.dat Removed! : C:\WINDOWS\pxoqw.dat Removed! : C:\WINDOWS\zudmpl.dat Removed! : C:\WINDOWS\aewdyy.dat Removed! : C:\WINDOWS\ohmvri.dat Removed! : C:\WINDOWS\system32\rjgeh.dat Attempted Clean Of Temp folder. Pages Reset… Done! – Scan 2 ————————— About:Buster Version 4.0 Reference List : 26 ADS not scanned System(FAT) Attempted Clean Of Temp folder. Pages Reset… Done! Scanned at: 10:44:49 AM on: 5/29/2005 – Scan 1 ————————— About:Buster Version 4.0 Reference List : 26 ADS not scanned System(FAT) Removed 3 Random Key Entries Attempted Clean Of Temp folder. Pages Reset… Done! – Scan 2 ————————— About:Buster Version 4.0 Reference List : 26 ADS not scanned System(FAT) Attempted Clean Of Temp folder. Pages Reset… Done! - cleanmgr run and deleted as instructed. (Note I have four users on this machine and I did the cleaning on all four as well as the administrator. I ran the about buster from my log in. than ran it again from another user later. log not attached but looked clean after the two done as requested) -TrendMicro Housecall run: I'm dealing with dialup here (out in the sticks but cable coming :D ) ) After about 2 hours it had found 632 viruses in the 9142 files it had checked. It had not completed and I had been disconnected.It was two virus types: TROJ DLOADER.HP (Non cleanable) (the majority) TROJ AGENT.UO (Non cleanable) (about every twenty or so) I triend to copy the report to post but was unsuccessful. All were Located in C:\WINDOWS\SYSTEM32\(fill in). I have not rebooted since the scan never completed. What do you think? I can post a new Hijack before or after a reboot if you would like. I hate not finishing with what you asked for but with the scan stopped I thought I would send what I had so far and await some futher guidence. Thanks again. I will stand by. av8tor
    A couple of things to add: I forgot that when I was loading housecall one thing popped up that I flipped a coin on. It asked about a file replace during the install. source : docume~1\default\locals~1\Temp\ICD.tmp\patchw32.dll target : c:windows\patchw32.dll file exists and is newer than source. flip was heads and I did not overwrite. I had no idea This morn the microsoft beta had run and it had 4 threats found: -Worm.Bagle (Worm) C:windows\system32\wingo.exe Then listed what appears to be everything in run once file - Netspy (Remote access trojan) c:windows\system 32\netdd.exe Again lists entire run once file - Net Advance (Remote access trojan) c:windows\mswk.exe Again lists entire run once file - Possible Browser Hijack (Browser Modifier) IE search page 1 I loaded this beta before I started reading up and don't know if I will keep it or if the info is any help. I did NOT allow the program to remove the threats and I still have not cleared the run once file but the Startup inspector program has it pretty long. I also disabled the NAV2002 during the Housecall. Didn't think 2 antivirus programs running was a good thing. The MS beta program continues to give alerts on unknown startup programs that I continue to block. Hope this is of some use and not a waste of your time. av8tor
    Hello av8tor
    Good work. Your hard work is absolutely NOT a waste of time. Keep it up.
    We have yet to finish dealing with that CWS infection, and must do so.

    Re: that Microsoft Anti-Virus Beta. Run it and let it fix, delete, contain, or whatever it will. Then see if there is an option to remove from your system what it finds.

    Please download the free MWAV antivirus tool from here:
    ftp://ftp.microworldsystems.com/download/tools/mwav.exe
    Save it to the desktop and run it.  Follow the prompts to scan your system for viruses.  Then please post for me the log of infected files from the BOTTOM panel of the scan window.

    194524


    AND HERE IS ANOTHER ONE, THAT WILL UNCOVER TROJANS ETC.

    Note: This is for Windows 2000 and Windows XP ONLY! Ewido does not work with any other versions of Windows.

    Please download, install, update and scan your system with the free version of Ewido trojan scanner:
    1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    3. From the main ewido screen, click on update in the left menu, then click the Start update button.
    4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack….
    5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
    6. When the scan finishes, click on "Save Report". This will create a text file.
    7. Please then paste the contents of the text file to this thread, along with a new HijackThis log and the log of infected files from the BOTTOM panel of the MWAV scan window.

      Please use the Post Reply function, so I will be notified.
    Hey Piatan.
    Well its not going so well on my end.
    Heres the status. Ran the microworldsystems program and I was stunned at the number of infections (25000+). Decided to run the microsoft Beta to remove what it could and then I installed and ran the ewido program. It shut down due to some error twice after about 70% scan completed. I than reran the microworld program again but the report was again brutal. I tried to post it but the machine locked up. Disconnected and did some investigating and found that the log from the microworld scan is 14.2 megs . I guess when I tried to cut and paste it while online it just froze in fear. remember i'm on dial up. I'm not sure I can upload it in a zipped form or not but know it would have been a record length post !!
    I will post the current hijack and hope it helps.
    I also looked at the services.msc again and the RPC Helper has shifted itself back to automatic from the setting of disable. I guess it shouldn't suprize me that it can turn it self back on. I did disable it again for what thats worth.
    OK here's the Hijack log and I may try a second post with the other log next.
    Frustrated. Av8tor
    Logfile of HijackThis v1.99.1
    Scan saved at 1:45:23 PM, on 6/3/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\NORTON~1\navapw32.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\WINDOWS\iptp.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
    C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\system32\sdkev32.exe
    C:\Documents and Settings\default\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\cebfi.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mjmnk.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\cebfi.dll/sp.html#37049
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\cebfi.dll/sp.html#37049
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: Class - {2D83144A-96F5-FD55-350C-BB36CBABB8B2} - C:\WINDOWS\system32\msyf.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Class - {FD53AF3D-B5A4-3DEC-C009-E2E6791F3EE9} - C:\WINDOWS\system32\ieya32.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1424.0\en-us\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [iptp.exe] C:\WINDOWS\iptp.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\RunOnce: [crmn.exe] C:\WINDOWS\crmn.exe
    O4 - HKLM\..\RunOnce: [sdkol.exe] C:\WINDOWS\sdkol.exe
    O4 - HKLM\..\RunOnce: [ieur32.exe] C:\WINDOWS\system32\ieur32.exe
    O4 - HKLM\..\RunOnce: [apiwj.exe] C:\WINDOWS\system32\apiwj.exe
    O4 - HKLM\..\RunOnce: [mscz.exe] C:\WINDOWS\mscz.exe
    O4 - HKLM\..\RunOnce: [ieya.exe] C:\WINDOWS\system32\ieya.exe
    O4 - HKLM\..\RunOnce: [netie32.exe] C:\WINDOWS\system32\netie32.exe
    O4 - HKLM\..\RunOnce: [ipcn32.exe] C:\WINDOWS\ipcn32.exe
    O4 - HKLM\..\RunOnce: [netcn32.exe] C:\WINDOWS\netcn32.exe
    O4 - HKLM\..\RunOnce: [sysqq32.exe] C:\WINDOWS\sysqq32.exe
    O4 - HKLM\..\RunOnce: [ntbd32.exe] C:\WINDOWS\system32\ntbd32.exe
    O4 - HKLM\..\RunOnce: [apigf.exe] C:\WINDOWS\system32\apigf.exe
    O4 - HKLM\..\RunOnce: [ipii32.exe] C:\WINDOWS\system32\ipii32.exe
    O4 - HKLM\..\RunOnce: [atldi.exe] C:\WINDOWS\system32\atldi.exe
    O4 - HKLM\..\RunOnce: [apiml.exe] C:\WINDOWS\apiml.exe
    O4 - HKLM\..\RunOnce: [javanm.exe] C:\WINDOWS\system32\javanm.exe
    O4 - HKLM\..\RunOnce: [appqv32.exe] C:\WINDOWS\system32\appqv32.exe
    O4 - HKLM\..\RunOnce: [d3bo32.exe] C:\WINDOWS\system32\d3bo32.exe
    O4 - HKLM\..\RunOnce: [netvh32.exe] C:\WINDOWS\netvh32.exe
    O4 - HKLM\..\RunOnce: [msjw.exe] C:\WINDOWS\msjw.exe
    O4 - HKLM\..\RunOnce: [iept32.exe] C:\WINDOWS\iept32.exe
    O4 - HKLM\..\RunOnce: [d3kx.exe] C:\WINDOWS\system32\d3kx.exe
    O4 - HKLM\..\RunOnce: [cryt.exe] C:\WINDOWS\cryt.exe
    O4 - HKLM\..\RunOnce: [sdkcd.exe] C:\WINDOWS\system32\sdkcd.exe
    O4 - HKLM\..\RunOnce: [ipra32.exe] C:\WINDOWS\system32\ipra32.exe
    O4 - HKLM\..\RunOnce: [iepl.exe] C:\WINDOWS\iepl.exe
    O4 - HKLM\..\RunOnce: [addot.exe] C:\WINDOWS\system32\addot.exe
    O4 - HKLM\..\RunOnce: [netdq32.exe] C:\WINDOWS\netdq32.exe
    O4 - HKLM\..\RunOnce: [wincq.exe] C:\WINDOWS\wincq.exe
    O4 - HKLM\..\RunOnce: [javaby.exe] C:\WINDOWS\javaby.exe
    O4 - HKLM\..\RunOnce: [addim32.exe] C:\WINDOWS\addim32.exe
    O4 - HKLM\..\RunOnce: [iexc32.exe] C:\WINDOWS\iexc32.exe
    O4 - HKLM\..\RunOnce: [winwj32.exe] C:\WINDOWS\system32\winwj32.exe
    O4 - HKLM\..\RunOnce: [crhc.exe] C:\WINDOWS\crhc.exe
    O4 - HKLM\..\RunOnce: [d3ku.exe] C:\WINDOWS\system32\d3ku.exe
    O4 - HKLM\..\RunOnce: [atlex.exe] C:\WINDOWS\atlex.exe
    O4 - HKLM\..\RunOnce: [apidv32.exe] C:\WINDOWS\apidv32.exe
    O4 - HKLM\..\RunOnce: [addck32.exe] C:\WINDOWS\system32\addck32.exe
    O4 - HKLM\..\RunOnce: [crve32.exe] C:\WINDOWS\crve32.exe
    O4 - HKLM\..\RunOnce: [appbs.exe] C:\WINDOWS\appbs.exe
    O4 - HKLM\..\RunOnce: [mfcbg32.exe] C:\WINDOWS\system32\mfcbg32.exe
    O4 - HKLM\..\RunOnce: [winkt.exe] C:\WINDOWS\system32\winkt.exe
    O4 - HKLM\..\RunOnce: [javayv.exe] C:\WINDOWS\javayv.exe
    O4 - HKLM\..\RunOnce: [nttz32.exe] C:\WINDOWS\system32\nttz32.exe
    O4 - HKLM\..\RunOnce: [atlko.exe] C:\WINDOWS\atlko.exe
    O4 - HKLM\..\RunOnce: [msjw32.exe] C:\WINDOWS\msjw32.exe
    O4 - HKLM\..\RunOnce: [ieje32.exe] C:\WINDOWS\ieje32.exe
    O4 - HKLM\..\RunOnce: [sdkna32.exe] C:\WINDOWS\sdkna32.exe
    O4 - HKLM\..\RunOnce: [javaht32.exe] C:\WINDOWS\system32\javaht32.exe
    O4 - HKLM\..\RunOnce: [crhb.exe] C:\WINDOWS\system32\crhb.exe
    O4 - HKLM\..\RunOnce: [sdkpc.exe] C:\WINDOWS\system32\sdkpc.exe
    O4 - HKLM\..\RunOnce: [sysfz32.exe] C:\WINDOWS\system32\sysfz32.exe
    O4 - HKLM\..\RunOnce: [mfcpp32.exe] C:\WINDOWS\system32\mfcpp32.exe
    O4 - HKLM\..\RunOnce: [ipon32.exe] C:\WINDOWS\ipon32.exe
    O4 - HKLM\..\RunOnce: [atlmd32.exe] C:\WINDOWS\system32\atlmd32.exe
    O4 - HKLM\..\RunOnce: [syslq32.exe] C:\WINDOWS\syslq32.exe
    O4 - HKLM\..\RunOnce: [mfcml.exe] C:\WINDOWS\system32\mfcml.exe
    O4 - HKLM\..\RunOnce: [atlvl.exe] C:\WINDOWS\atlvl.exe
    O4 - HKLM\..\RunOnce: [systy.exe] C:\WINDOWS\system32\systy.exe
    O4 - HKLM\..\RunOnce: [mfcjn32.exe] C:\WINDOWS\mfcjn32.exe
    O4 - HKLM\..\RunOnce: [ntzd32.exe] C:\WINDOWS\ntzd32.exe
    O4 - HKLM\..\RunOnce: [apijd.exe] C:\WINDOWS\apijd.exe
    O4 - HKLM\..\RunOnce: [crys32.exe] C:\WINDOWS\system32\crys32.exe
    O4 - HKLM\..\RunOnce: [apifg32.exe] C:\WINDOWS\system32\apifg32.exe
    O4 - HKLM\..\RunOnce: [netfw32.exe] C:\WINDOWS\netfw32.exe
    O4 - HKLM\..\RunOnce: [ntzh.exe] C:\WINDOWS\system32\ntzh.exe
    O4 - HKLM\..\RunOnce: [msow32.exe] C:\WINDOWS\msow32.exe
    O4 - HKLM\..\RunOnce: [addee.exe] C:\WINDOWS\addee.exe
    O4 - HKLM\..\RunOnce: [apiii32.exe] C:\WINDOWS\system32\apiii32.exe
    O4 - HKLM\..\RunOnce: [sdknk32.exe] C:\WINDOWS\system32\sdknk32.exe
    O4 - HKLM\..\RunOnce: [addhv32.exe] C:\WINDOWS\addhv32.exe
    O4 - HKLM\..\RunOnce: [appsq.exe] C:\WINDOWS\appsq.exe
    O4 - HKLM\..\RunOnce: [sysws32.exe] C:\WINDOWS\sysws32.exe
    O4 - HKLM\..\RunOnce: [mfcgt32.exe] C:\WINDOWS\mfcgt32.exe
    O4 - HKLM\..\RunOnce: [netfy.exe] C:\WINDOWS\system32\netfy.exe
    O4 - HKLM\..\RunOnce: [iplx.exe] C:\WINDOWS\iplx.exe
    O4 - HKLM\..\RunOnce: [sysld32.exe] C:\WINDOWS\system32\sysld32.exe
    O4 - HKLM\..\RunOnce: [netlx32.exe] C:\WINDOWS\system32\netlx32.exe
    O4 - HKLM\..\RunOnce: [apiau.exe] C:\WINDOWS\apiau.exe
    O4 - HKLM\..\RunOnce: [netnr.exe] C:\WINDOWS\netnr.exe
    O4 - HKLM\..\RunOnce: [systn.exe] C:\WINDOWS\system32\systn.exe
    O4 - HKLM\..\RunOnce: [mfcdm32.exe] C:\WINDOWS\mfcdm32.exe
    O4 - HKLM\..\RunOnce: [d3xx32.exe] C:\WINDOWS\system32\d3xx32.exe
    O4 - HKLM\..\RunOnce: [appaj.exe] C:\WINDOWS\appaj.exe
    O4 - HKLM\..\RunOnce: [netli32.exe] C:\WINDOWS\netli32.exe
    O4 - HKLM\..\RunOnce: [syswn.exe] C:\WINDOWS\system32\syswn.exe
    O4 - HKLM\..\RunOnce: [netry32.exe] C:\WINDOWS\netry32.exe
    O4 - HKLM\..\RunOnce: [javapg32.exe] C:\WINDOWS\javapg32.exe
    O4 - HKLM\..\RunOnce: [winfb32.exe] C:\WINDOWS\system32\winfb32.exe
    O4 - HKLM\..\RunOnce: [iptq.exe] C:\WINDOWS\system32\iptq.exe
    O4 - HKLM\..\RunOnce: [apiuq.exe] C:\WINDOWS\apiuq.exe
    O4 - HKLM\..\RunOnce: [sdkmr32.exe] C:\WINDOWS\sdkmr32.exe
    O4 - HKLM\..\RunOnce: [sysib32.exe] C:\WINDOWS\system32\sysib32.exe
    O4 - HKLM\..\RunOnce: [ieqd.exe] C:\WINDOWS\ieqd.exe
    O4 - HKLM\..\RunOnce: [sdkqr.exe] C:\WINDOWS\sdkqr.exe
    O4 - HKLM\..\RunOnce: [netfg.exe] C:\WINDOWS\netfg.exe
    O4 - HKLM\..\RunOnce: [winkc.exe] C:\WINDOWS\system32\winkc.exe
    O4 - HKLM\..\RunOnce: [ipnw32.exe] C:\WINDOWS\ipnw32.exe
    O4 - HKLM\..\RunOnce: [atlyv32.exe] C:\WINDOWS\atlyv32.exe
    O4 - HKLM\..\RunOnce: [atldl32.exe] C:\WINDOWS\system32\atldl32.exe
    O4 - HKLM\..\RunOnce: [mfclt.exe] C:\WINDOWS\system32\mfclt.exe
    O4 - HKLM\..\RunOnce: [sysqv32.exe] C:\WINDOWS\system32\sysqv32.exe
    O4 - HKLM\..\RunOnce: [msrw32.exe] C:\WINDOWS\msrw32.exe
    O4 - HKLM\..\RunOnce: [crgl32.exe] C:\WINDOWS\crgl32.exe
    O4 - HKLM\..\RunOnce: [winea32.exe] C:\WINDOWS\system32\winea32.exe
    O4 - HKLM\..\RunOnce: [sdkei.exe] C:\WINDOWS\sdkei.exe
    O4 - HKLM\..\RunOnce: [appsc.exe] C:\WINDOWS\system32\appsc.exe
    O4 - HKLM\..\RunOnce: [apiim32.exe] C:\WINDOWS\system32\apiim32.exe
    O4 - HKLM\..\RunOnce: [addyb.exe] C:\WINDOWS\addyb.exe
    O4 - HKLM\..\RunOnce: [nthi32.exe] C:\WINDOWS\nthi32.exe
    O4 - HKLM\..\RunOnce: [ntvh32.exe] C:\WINDOWS\system32\ntvh32.exe
    O4 - HKLM\..\RunOnce: [sdkhq32.exe] C:\WINDOWS\sdkhq32.exe
    O4 - HKLM\..\RunOnce: [ipwp.exe] C:\WINDOWS\ipwp.exe
    O4 - HKLM\..\RunOnce: [atluc.exe] C:\WINDOWS\system32\atluc.exe
    O4 - HKLM\..\RunOnce: [ienv32.exe] C:\WINDOWS\ienv32.exe
    O4 - HKLM\..\RunOnce: [javadk.exe] C:\WINDOWS\system32\javadk.exe
    O4 - HKLM\..\RunOnce: [sdkmj.exe] C:\WINDOWS\system32\sdkmj.exe
    O4 - HKLM\..\RunOnce: [netqv.exe] C:\WINDOWS\system32\netqv.exe
    O4 - HKLM\..\RunOnce: [addaq32.exe] C:\WINDOWS\system32\addaq32.exe
    O4 - HKLM\..\RunOnce: [crfk32.exe] C:\WINDOWS\crfk32.exe
    O4 - HKLM\..\RunOnce: [syswr.exe] C:\WINDOWS\syswr.exe
    O4 - HKLM\..\RunOnce: [appay.exe] C:\WINDOWS\system32\appay.exe
    O4 - HKLM\..\RunOnce: [addjw.exe] C:\WINDOWS\addjw.exe
    O4 - HKLM\..\RunOnce: [addps32.exe] C:\WINDOWS\addps32.exe
    O4 - HKLM\..\RunOnce: [netyn32.exe] C:\WINDOWS\system32\netyn32.exe
    O4 - HKLM\..\RunOnce: [netni32.exe] C:\WINDOWS\netni32.exe
    O4 - HKLM\..\RunOnce: [ieno32.exe] C:\WINDOWS\system32\ieno32.exe
    O4 - HKLM\..\RunOnce: [javafr32.exe] C:\WINDOWS\javafr32.exe
    O4 - HKLM\..\RunOnce: [apifk32.exe] C:\WINDOWS\apifk32.exe
    O4 - HKLM\..\RunOnce: [javaoh.exe] C:\WINDOWS\javaoh.exe
    O4 - HKLM\..\RunOnce: [nettp32.exe] C:\WINDOWS\nettp32.exe
    O4 - HKLM\..\RunOnce: [ipyf32.exe] C:\WINDOWS\ipyf32.exe
    O4 - HKLM\..\RunOnce: [nethm.exe] C:\WINDOWS\system32\nethm.exe
    O4 - HKLM\..\RunOnce: [sysyn.exe] C:\WINDOWS\system32\sysyn.exe
    O4 - HKLM\..\RunOnce: [winbf.exe] C:\WINDOWS\winbf.exe
    O4 - HKLM\..\RunOnce: [apprp32.exe] C:\WINDOWS\system32\apprp32.exe
    O4 - HKLM\..\RunOnce: [atlnh32.exe] C:\WINDOWS\system32\atlnh32.exe
    O4 - HKLM\..\RunOnce: [atlaa.exe] C:\WINDOWS\system32\atlaa.exe
    O4 - HKLM\..\RunOnce: [addax.exe] C:\WINDOWS\addax.exe
    O4 - HKLM\..\RunOnce: [apitu32.exe] C:\WINDOWS\apitu32.exe
    O4 - HKLM\..\RunOnce: [ieej32.exe] C:\WINDOWS\system32\ieej32.exe
    O4 - HKLM\..\RunOnce: [javauy.exe] C:\WINDOWS\javauy.exe
    O4 - HKLM\..\RunOnce: [javaxo.exe] C:\WINDOWS\javaxo.exe
    O4 - HKLM\..\RunOnce: [crdc32.exe] C:\WINDOWS\crdc32.exe
    O4 - HKLM\..\RunOnce: [appmi.exe] C:\WINDOWS\appmi.exe
    O4 - HKLM\..\RunOnce: [winrw32.exe] C:\WINDOWS\system32\winrw32.exe
    O4 - HKLM\..\RunOnce: [sysvr32.exe] C:\WINDOWS\sysvr32.exe
    O4 - HKLM\..\RunOnce: [addrm.exe] C:\WINDOWS\system32\addrm.exe
    O4 - HKLM\..\RunOnce: [winam.exe] C:\WINDOWS\winam.exe
    O4 - HKLM\..\RunOnce: [msfr.exe] C:\WINDOWS\system32\msfr.exe
    O4 - HKLM\..\RunOnce: [apipb32.exe] C:\WINDOWS\system32\apipb32.exe
    O4 - HKLM\..\RunOnce: [atlll.exe] C:\WINDOWS\system32\atlll.exe
    O4 - HKLM\..\RunOnce: [sysdd32.exe] C:\WINDOWS\sysdd32.exe
    O4 - HKLM\..\RunOnce: [ietu32.exe] C:\WINDOWS\system32\ietu32.exe
    O4 - HKLM\..\RunOnce: [mfcst.exe] C:\WINDOWS\system32\mfcst.exe
    O4 - HKLM\..\RunOnce: [ntdt32.exe] C:\WINDOWS\system32\ntdt32.exe
    O4 - HKLM\..\RunOnce: [sysvv.exe] C:\WINDOWS\system32\sysvv.exe
    O4 - HKLM\..\RunOnce: [sdkop.exe] C:\WINDOWS\sdkop.exe
    O4 - HKLM\..\RunOnce: [mshf.exe] C:\WINDOWS\system32\mshf.exe
    O4 - HKLM\..\RunOnce: [ipaw32.exe] C:\WINDOWS\system32\ipaw32.exe
    O4 - HKLM\..\RunOnce: [mfctb.exe] C:\WINDOWS\mfctb.exe
    O4 - HKLM\..\RunOnce: [netpt32.exe] C:\WINDOWS\netpt32.exe
    O4 - HKLM\..\RunOnce: [ippb32.exe] C:\WINDOWS\ippb32.exe
    O4 - HKLM\..\RunOnce: [javalh.exe] C:\WINDOWS\system32\javalh.exe
    O4 - HKLM\..\RunOnce: [javafb32.exe] C:\WINDOWS\javafb32.exe
    O4 - HKLM\..\RunOnce: [apikx32.exe] C:\WINDOWS\system32\apikx32.exe
    O4 - HKLM\..\RunOnce: [sdkco32.exe] C:\WINDOWS\sdkco32.exe
    O4 - HKLM\..\RunOnce: [ntrd.exe] C:\WINDOWS\system32\ntrd.exe
    O4 - HKLM\..\RunOnce: [sdkxz.exe] C:\WINDOWS\system32\sdkxz.exe
    O4 - HKLM\..\RunOnce: [sdkph.exe] C:\WINDOWS\sdkph.exe
    O4 - HKLM\..\RunOnce: [javafn32.exe] C:\WINDOWS\system32\javafn32.exe
    O4 - HKLM\..\RunOnce: [msks.exe] C:\WINDOWS\msks.exe
    O4 - HKLM\..\RunOnce: [crss32.exe] C:\WINDOWS\system32\crss32.exe
    O4 - HKLM\..\RunOnce: [atlqq.exe] C:\WINDOWS\system32\atlqq.exe
    O4 - HKLM\..\RunOnce: [crzp32.exe] C:\WINDOWS\crzp32.exe
    O4 - HKLM\..\RunOnce: [mfckc32.exe] C:\WINDOWS\system32\mfckc32.exe
    O4 - HKLM\..\RunOnce: [mfcks32.exe] C:\WINDOWS\mfcks32.exe
    O4 - HKLM\..\RunOnce: [ielb.exe] C:\WINDOWS\system32\ielb.exe
    O4 - HKLM\..\RunOnce: [msmb32.exe] C:\WINDOWS\msmb32.exe
    O4 - HKLM\..\RunOnce: [ippw32.exe] C:\WINDOWS\ippw32.exe
    O4 - HKLM\..\RunOnce: [mfcdh.exe] C:\WINDOWS\mfcdh.exe
    O4 - HKLM\..\RunOnce: [ipsf32.exe] C:\WINDOWS\system32\ipsf32.exe
    O4 - HKLM\..\RunOnce: [javatx32.exe] C:\WINDOWS\system32\javatx32.exe
    O4 - HKLM\..\RunOnce: [msvz.exe] C:\WINDOWS\system32\msvz.exe
    O4 - HKLM\..\RunOnce: [msbo32.exe] C:\WINDOWS\msbo32.exe
    O4 - HKLM\..\RunOnce: [msql32.exe] C:\WINDOWS\system32\msql32.exe
    O4 - HKLM\..\RunOnce: [sysrc32.exe] C:\WINDOWS\system32\sysrc32.exe
    O4 - HKLM\..\RunOnce: [mspb32.exe] C:\WINDOWS\system32\mspb32.exe
    O4 - HKLM\..\RunOnce: [addxp32.exe] C:\WINDOWS\system32\addxp32.exe
    O4 - HKLM\..\RunOnce: [mspn.exe] C:\WINDOWS\system32\mspn.exe
    O4 - HKLM\..\RunOnce: [netbj.exe] C:\WINDOWS\netbj.exe
    O4 - HKLM\..\RunOnce: [msjz32.exe] C:\WINDOWS\system32\msjz32.exe
    O4 - HKLM\..\RunOnce: [winaq32.exe] C:\WINDOWS\winaq32.exe
    O4 - HKLM\..\RunOnce: [ntrc32.exe] C:\WINDOWS\ntrc32.exe
    O4 - HKLM\..\RunOnce: [appkw32.exe] C:\WINDOWS\appkw32.exe
    O4 - HKLM\..\RunOnce: [javacy32.exe] C:\WINDOWS\javacy32.exe
    O4 - HKLM\..\RunOnce: [atlke32.exe] C:\WINDOWS\atlke32.exe
    O4 - HKLM\..\RunOnce: [sysgk.exe] C:\WINDOWS\sysgk.exe
    O4 - HKLM\..\RunOnce: [sdkff.exe] C:\WINDOWS\sdkff.exe
    O4 - HKLM\..\RunOnce: [addaj.exe] C:\WINDOWS\addaj.exe
    O4 - HKLM\..\RunOnce: [iepy.exe] C:\WINDOWS\system32\iepy.exe
    O4 - HKLM\..\RunOnce: [javazr32.exe] C:\WINDOWS\system32\javazr32.exe
    O4 - HKLM\..\RunOnce: [javabc.exe] C:\WINDOWS\javabc.exe
    O4 - HKLM\..\RunOnce: [crtk.exe] C:\WINDOWS\crtk.exe
    O4 - HKLM\..\RunOnce: [ntqz.exe] C:\WINDOWS\ntqz.exe
    O4 - HKLM\..\RunOnce: [atlhh32.exe] C:\WINDOWS\atlhh32.exe
    O4 - HKLM\..\RunOnce: [javaqf.exe] C:\WINDOWS\system32\javaqf.exe
    O4 - HKLM\..\RunOnce: [ipfu.exe] C:\WINDOWS\system32\ipfu.exe
    O4 - HKLM\..\RunOnce: [crbs32.exe] C:\WINDOWS\system32\crbs32.exe
    O4 - HKLM\..\RunOnce: [mfcjy32.exe] C:\WINDOWS\system32\mfcjy32.exe
    O4 - HKLM\..\RunOnce: [wingc32.exe] C:\WINDOWS\system32\wingc32.exe
    O4 - HKLM\..\RunOnce: [d3wr32.exe] C:\WINDOWS\d3wr32.exe
    O4 - HKLM\..\RunOnce: [apiro.exe] C:\WINDOWS\apiro.exe
    O4 - HKLM\..\RunOnce: [d3eh.exe] C:\WINDOWS\d3eh.exe
    O4 - HKLM\..\RunOnce: [msli.exe] C:\WINDOWS\system32\msli.exe
    O4 - HKLM\..\RunOnce: [crfi.exe] C:\WINDOWS\crfi.exe
    O4 - HKLM\..\RunOnce: [apppr.exe] C:\WINDOWS\system32\apppr.exe
    O4 - HKLM\..\RunOnce: [d3dw32.exe] C:\WINDOWS\d3dw32.exe
    O4 - HKLM\..\RunOnce: [msmy32.exe] C:\WINDOWS\msmy32.exe
    O4 - HKLM\..\RunOnce: [ipte32.exe] C:\WINDOWS\system32\ipte32.exe
    O4 - HKLM\..\RunOnce: [sdkln.exe] C:\WINDOWS\system32\sdkln.exe
    O4 - HKLM\..\RunOnce: [ipgx.exe] C:\WINDOWS\ipgx.exe
    O4 - HKLM\..\RunOnce: [iewp.exe] C:\WINDOWS\system32\iewp.exe
    O4 - HKLM\..\RunOnce: [javasb32.exe] C:\WINDOWS\javasb32.exe
    O4 - HKLM\..\RunOnce: [netqr.exe] C:\WINDOWS\system32\netqr.exe
    O4 - HKLM\..\RunOnce: [ntdi.exe] C:\WINDOWS\ntdi.exe
    O4 - HKLM\..\RunOnce: [addpg32.exe] C:\WINDOWS\system32\addpg32.exe
    O4 - HKLM\..\RunOnce: [msfo32.exe] C:\WINDOWS\msfo32.exe
    O4 - HKLM\..\RunOnce: [iene.exe] C:\WINDOWS\iene.exe
    O4 - HKLM\..\RunOnce: [d3vy32.exe] C:\WINDOWS\d3vy32.exe
    O4 - HKLM\..\RunOnce: [mfcpc32.exe] C:\WINDOWS\mfcpc32.exe
    O4 - HKLM\..\RunOnce: [mfcxk32.exe] C:\WINDOWS\mfcxk32.exe
    O4 - HKLM\..\RunOnce: [winwa.exe] C:\WINDOWS\system32\winwa.exe
    O4 - HKLM\..\RunOnce: [netsr.exe] C:\WINDOWS\system32\netsr.exe
    O4 - HKLM\..\RunOnce: [crez32.exe] C:\WINDOWS\crez32.exe
    O4 - HKLM\..\RunOnce: [sdkoi.exe] C:\WINDOWS\system32\sdkoi.exe
    O4 - HKLM\..\RunOnce: [apikm.exe] C:\WINDOWS\system32\apikm.exe
    O4 - HKLM\..\RunOnce: [ipyw32.exe] C:\WINDOWS\system32\ipyw32.exe
    O4 - HKLM\..\RunOnce: [javawd.exe] C:\WINDOWS\system32\javawd.exe
    O4 - HKLM\..\RunOnce: [syssz32.exe] C:\WINDOWS\system32\syssz32.exe
    O4 - HKLM\..\RunOnce: [d3ci.exe] C:\WINDOWS\system32\d3ci.exe
    O4 - HKLM\..\RunOnce: [apprv.exe] C:\WINDOWS\system32\apprv.exe
    O4 - HKLM\..\RunOnce: [d3uu.exe] C:\WINDOWS\system32\d3uu.exe
    O4 - HKLM\..\RunOnce: [winss32.exe] C:\WINDOWS\system32\winss32.exe
    O4 - HKLM\..\RunOnce: [d3ct32.exe] C:\WINDOWS\system32\d3ct32.exe
    O4 - HKLM\..\RunOnce: [ntbi.exe] C:\WINDOWS\ntbi.exe
    O4 - HKLM\..\RunOnce: [atlay32.exe] C:\WINDOWS\atlay32.exe
    O4 - HKLM\..\RunOnce: [javadp32.exe] C:\WINDOWS\system32\javadp32.exe
    O4 - HKLM\..\RunOnce: [ipbv.exe] C:\WINDOWS\ipbv.exe
    O4 - HKLM\..\RunOnce: [apikv.exe] C:\WINDOWS\system32\apikv.exe
    O4 - HKLM\..\RunOnce: [sysps32.exe] C:\WINDOWS\sysps32.exe
    O4 - HKLM\..\RunOnce: [d3kv.exe] C:\WINDOWS\system32\d3kv.exe
    O4 - HKLM\..\RunOnce: [ipjl32.exe] C:\WINDOWS\system32\ipjl32.exe
    O4 - HKLM\..\RunOnce: [ienl32.exe] C:\WINDOWS\ienl32.exe
    O4 - HKLM\..\RunOnce: [crli.exe] C:\WINDOWS\system32\crli.exe
    O4 - HKLM\..\RunOnce: [javauj.exe] C:\WINDOWS\system32\javauj.exe
    O4 - HKLM\..\RunOnce: [iprw32.exe] C:\WINDOWS\iprw32.exe
    O4 - HKLM\..\RunOnce: [ipbc.exe] C:\WINDOWS\system32\ipbc.exe
    O4 - HKLM\..\RunOnce: [ntoz32.exe] C:\WINDOWS\system32\ntoz32.exe
    O4 - HKLM\..\RunOnce: [ipvw32.exe] C:\WINDOWS\ipvw32.exe
    O4 - HKLM\..\RunOnce: [netvs.exe] C:\WINDOWS\system32\netvs.exe
    O4 - HKLM\..\RunOnce: [sysap.exe] C:\WINDOWS\system32\sysap.exe
    O4 - HKLM\..\RunOnce: [d3eb.exe] C:\WINDOWS\d3eb.exe
    O4 - HKLM\..\RunOnce: [apptq32.exe] C:\WINDOWS\system32\apptq32.exe
    O4 - HKLM\..\RunOnce: [addil.exe] C:\WINDOWS\addil.exe
    O4 - HKLM\..\RunOnce: [atlwp.exe] C:\WINDOWS\atlwp.exe
    O4 - HKLM\..\RunOnce: [atlqj32.exe] C:\WINDOWS\atlqj32.exe
    O4 - HKLM\..\RunOnce: [crta32.exe] C:\WINDOWS\crta32.exe
    O4 - HKLM\..\RunOnce: [javaix32.exe] C:\WINDOWS\javaix32.exe
    O4 - HKLM\..\RunOnce: [apiyn.exe] C:\WINDOWS\system32\apiyn.exe
    O4 - HKLM\..\RunOnce: [winxc32.exe] C:\WINDOWS\system32\winxc32.exe
    O4 - HKLM\..\RunOnce: [ipbm.exe] C:\WINDOWS\ipbm.exe
    O4 - HKLM\..\RunOnce: [javafq32.exe] C:\WINDOWS\javafq32.exe
    O4 - HKLM\..\RunOnce: [msku.exe] C:\WINDOWS\system32\msku.exe
    O4 - HKLM\..\RunOnce: [atlne.exe] C:\WINDOWS\system32\atlne.exe
    O4 - HKLM\..\RunOnce: [iemu32.exe] C:\WINDOWS\system32\iemu32.exe
    O4 - HKLM\..\RunOnce: [appxs.exe] C:\WINDOWS\appxs.exe
    O4 - HKLM\..\RunOnce: [apifg.exe] C:\WINDOWS\system32\apifg.exe
    O4 - HKLM\..\RunOnce: [crmv.exe] C:\WINDOWS\system32\crmv.exe
    O4 - HKLM\..\RunOnce: [netuj32.exe] C:\WINDOWS\system32\netuj32.exe
    O4 - HKLM\..\RunOnce: [winyf32.exe] C:\WINDOWS\system32\winyf32.exe
    O4 - HKLM\..\RunOnce: [d3gh32.exe] C:\WINDOWS\system32\d3gh32.exe
    O4 - HKLM\..\RunOnce: [msgp32.exe] C:\WINDOWS\msgp32.exe
    O4 - HKLM\..\RunOnce: [javaqx.exe] C:\WINDOWS\javaqx.exe
    O4 - HKLM\..\RunOnce: [d3jq32.exe] C:\WINDOWS\d3jq32.exe
    O4 - HKLM\..\RunOnce: [sdkhu32.exe] C:\WINDOWS\system32\sdkhu32.exe
    O4 - HKLM\..\RunOnce: [winfr32.exe] C:\WINDOWS\winfr32.exe
    O4 - HKLM\..\RunOnce: [d3vg32.exe] C:\WINDOWS\system32\d3vg32.exe
    O4 - HKLM\..\RunOnce: [msdw32.exe] C:\WINDOWS\system32\msdw32.exe
    O4 - HKLM\..\RunOnce: [addmp32.exe] C:\WINDOWS\addmp32.exe
    O4 - HKLM\..\RunOnce: [sysxt32.exe] C:\WINDOWS\system32\sysxt32.exe
    O4 - HKLM\..\RunOnce: [javakv32.exe] C:\WINDOWS\javakv32.exe
    O4 - HKLM\..\RunOnce: [appnv32.exe] C:\WINDOWS\system32\appnv32.exe
    O4 - HKLM\..\RunOnce: [netmo32.exe] C:\WINDOWS\system32\netmo32.exe
    O4 - HKLM\..\RunOnce: [crnv32.exe] C:\WINDOWS\crnv32.exe
    O4 - HKLM\..\RunOnce: [crba32.exe] C:\WINDOWS\system32\crba32.exe
    O4 - HKLM\..\RunOnce: [sdkmg.exe] C:\WINDOWS\system32\sdkmg.exe
    O4 - HKLM\..\RunOnce: [windx32.exe] C:\WINDOWS\windx32.exe
    O4 - HKLM\..\RunOnce: [sdkev32.exe] C:\WINDOWS\system32\sdkev32.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
    O4 - Global Startup: officejet 6100.lnk = ?
    O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Ask Jeeves Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Dictionary Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection-word
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O16 - DPF: eCrew Delta Technology V13100 - http://ecrew.delta-air.com/classes/cst/eCrew13100.cab
    O16 - DPF: eCrew Delta Technology V13112 - http://ecrew.delta-air.com/classes/cst/eCrew13112.cab
    O16 - DPF: eCrew Delta Technology V1381 - http://10.1.44.53/classes/cst/eCrew1381.cab
    O16 - DPF: eCrew Delta Technology V1397 - http://10.1.44.53/classes/cst/eCrew1397.cab
    O16 - DPF: eCrew Delta Technology V1410 - http://ecrew.delta-air.com/classes/cst/eCrew1410.cab
    O16 - DPF: eCrew Delta Technology V14102 - http://ecrew.delta-air.com/eCrew14102.cab
    O16 - DPF: eCrew Delta Technology V14120 - http://ecrew.delta-air.com/eCrew14120.cab
    O16 - DPF: eCrew Delta Technology V14141 - http://ecrew.delta-air.com/eCrew14141.cab
    O16 - DPF: eCrew Delta Technology V14169 - http://ecrew.delta-air.com/eCrew14169.cab
    O16 - DPF: eCrew Delta Technology V14170 - http://ecrew.delta-air.com/eCrew14170.cab
    O16 - DPF: eCrew Delta Technology V14180 - http://ecrew.delta-air.com/eCrew14180.cab
    O16 - DPF: eCrew Delta Technology V14200 - http://ecrew.delta-air.com/eCrew14200.cab
    O16 - DPF: eCrew Delta Technology V1451 - http://ecrew.delta-air.com/eCrew1451.cab
    O16 - DPF: eCrew Delta Technology V1472 - http://ecrew.delta-air.com/eCrew1472.cab
    O16 - DPF: eCrew Delta Technology V1486 - http://ecrew.delta-air.com/eCrew1486.cab
    O16 - DPF: eCrew Delta Technology V1491 - http://ecrew.delta-air.com/eCrew1491.cab
    O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) - http://diagnostics.support.hp.com/motivedo…w/ipgaxctrl.cab
    O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} (AJ Installer Control) - http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093355041187
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {C3498BF0-2C07-43C8-99D0-434B038334A6} (VDLaunch Class) - http://www.catharon.com/download/plugins/ievdl2.ocx
    O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://carpoint.msn.com/components/ocx/aut…/autopricer.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?312
    O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\netjo.exe (file missing)
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    Hi av8tor

    Sorry about your problems and are having to deal with a dialup connection.
    Our first efforts have to be to get rid of the AboutBlank infestation and it has not seemed to work so far. Lets do the following and see if we can get rid of it. Looks like it's going to be something of a repeat of my initial instructions. If that doesn't get it then another solution is needed.
    Please download the following programs and update them before beginning the fix. Under no circumstances attempt to use any that you may already have.

    Go to Start > Run and type in Services.msc then click OK

    Click the Extended tab.

    Scroll down until you find the service. Remote Procedure Call (RPC) Helper

    Click once on the service to highlight it.

    Click Stop

    Right-Click on the service. Remote Procedure Call (RPC) Helper

    Click on 'Properties'

    Select the 'General' tab

    Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

    From the drop-down menu, click on 'Disabled'

    Click the 'Apply' tab, then click 'OK'

    Next:
    You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
    • Prepare CWShredder for use:
      • Do update it now, please.
      • Download CWShredder.
      • Save CWShredder.exe to a convenient location.
      • Please do not do anything with it yet.
    • Prepare AboutBuster for use:
      • Download AboutBuster.
      • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
      • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
      • Click "OK" at the prompt with instructions.
      • Click "Update" and then "Check For Update" to begin the update process.
      • If any updates exist please download them by clicking "Download Update".
      • You should not run the program yet so click "Exit".
    Boot into Safe Mode:
    Restart your computer and immediately begin tapping the F8 key on your keyboard.
    If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.

    [*]Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".

    [*]Run AboutBuster and save the logs:
    • Browse to where you saved AboutBuster and run AboutBuster.exe.
    • Click "OK" at the directions Read: Important! prompt.
    • Click "Start" and then "OK" to allow AboutBuster to scan for Alternate Data Streams.
    • Click "Yes" at the About:Buster prompt to allow it to shutdown explorer.exe.
    • Please wait while AboutBuster scans your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so. Please run it two times.
    • When it has finished, click "Save Log…". Make sure you save it as I will need a copy of it.
    • Click "Exit" and "Exit" again to exit AboutBuster.

    [*]Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.

    [*]Restart your computer normally to return to normal mode.

    [*]Free TrendMicro Housecall scan:
    • Vist the TrendMicro Housecall website.
    • Select your country from the drop-down list and click "Go".
    • Choose "Yes" at the ActiveX Security Warning prompt.
    • Please wait while the Housecall engine is updated.
    • Select the drives to be scanned by placing a check in their respective boxes.
    • Check the "Auto Clean" box.
    • Click "SCAN" in order to begin scanning your system.
    • Please be patient while Housecall scans your system for malicious files.
    • If not auto-cleaned, remove anything it finds.
    • Click "Close" to exit the Housecall scanner.
    • Choose "Yes" at the HouseCall message prompt.

    [*]Prepare your reply:

      [*]Please post a fresh HijackThis log

      [*]Please post the AboutBuster log.

      [*]Please note any complications you had.


      Please post in this string, using the Post Reply function, so I will be notified.

      Hi av8tor

      Sorry about your problems and are having to deal with a dialup connection.
      Our first efforts have to be to get rid of the AboutBlank infestation and it has not seemed to work so far. Lets do the following and see if we can get rid of it. Looks like it's going to be something of a repeat of my initial instructions. If that doesn't get it then another solution is needed.
      Please download the following programs and update them before beginning the fix. Under no circumstances attempt to use any that you may already have.

      ——Ok Just trying to make sure I follow instructions to a tee. I think I have before but I will clarify and questions now. Should I delete the programs (shredder/aboutbuster) before downloading the new copies. I assume yes but will ask.
      Go to Start > Run and type in Services.msc then click OK

      Click the Extended tab.

      Scroll down until you find the service. Remote Procedure Call (RPC) Helper

      Click once on the service to highlight it.

      Click Stop

      ——–Tried this the last time and stop was not an option. I believe the service was stopped so it will not let me stop it again. When I just went back to check prior to starting these instructions I could not find RPC Helper at all. Thought that was strange and ran Hijack with no log. RPC Helper no longer listed: Replaced by Workstation Netlogon Service with the same unknown owner. ran services and workstation highlighted again stop is not an option due to service is stopped. Start up type is still in automatic with drop down ability to disable

      [*]Start | Run | type cleanmgr | OK

      [*]Let it scan your system for files to remove.

      [*]Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.

      [*]Click "OK" to remove them.

      [*]Click "Yes" to confirm the deletion.


      ——–Does it matter which of the 4 users on my computer I use to run the shredder/About buster programs from. I ran them from mine last time and then ran cleanmgr in all 4 users as well as the administrator.

      [*]Restart your computer normally to return to normal mode.

      [*]Free TrendMicro Housecall scan:

        [*]Vist the TrendMicro Housecall website.


        ———Tried to run last time and as posted was disconnected. Will ensure that it will be run this time when no one else can disrupt connection.


        [*]Please post a fresh HijackThis log

        [*]Please post the AboutBuster log.

        [*]Please note any complications you had.


        ———Will be able to do in a couple of days. (work) will check on your reply before proceeding.

        Thanks Av8tor
        Hi av8tor
        How do I put this ? The instructions I gave should be done all at one sitting and not interrupted by others using the computer as the fix is being done, or doing other things on the system in the interim.
        This is a very serious infestation and if not handled correctly, will not be stopped. It is often nearly impossible to fix under the best of conditions.

        You say Remote Procedure Call (RPC) Helper was replaced by Workstation Netlogon Service. Yes, this happens after a reboot and the previous entry cannot be fixed because it is no longer present. That is expected with this parasite, to prevent its removal. Do disable and stop whichever is present, if possible.

        Some individuals will attempt to use old programs which have not been updated. If the CWShredder and others are fresh downloads by you and are updated each time before being used, then another download of the programs is not necessary.

        Please do this fix using the Administrators sign on and lets get it cleared from there before going on to others.
        By the way, Trend Micro is often quirky and will disconnect frequently on its own.

        When you return, please post a fresh Hijack This log and we will see what is still applicable to the fix needed. Though I'm sure the Cool Web Search parasite is still present. Please do not reboot until asked to do so.
        Hey Piatan.
        Here are my latest logs:



        Scanned at: 9:21:00 AM on: 6/8/2005


        – Scan 1 —————————
        About:Buster Version 4.0
        Reference List : 28


        ADS not scanned System(FAT)
        Removed 2 Random Key Entries
        Removed! : C:\WINDOWS\bblaxs.dat
        Removed! : C:\WINDOWS\oqpkn.dat
        Removed! : C:\WINDOWS\nmdhy.dat
        Removed! : C:\WINDOWS\gtlhnj.dat
        Removed! : C:\WINDOWS\hzmtho.dat
        Removed! : C:\WINDOWS\zafyjy.dat
        Removed! : C:\WINDOWS\ksxedj.dat
        Removed! : C:\WINDOWS\ctirfl.dat
        Removed! : C:\WINDOWS\evyye.dat
        Removed! : C:\WINDOWS\hldxen.dat
        Removed! : C:\WINDOWS\ervfc.dat
        Removed! : C:\WINDOWS\ghxalt.dat
        Removed! : C:\WINDOWS\xewcy.dat
        Removed! : C:\WINDOWS\rptwk.dll
        Removed! : C:\WINDOWS\eyvqam.dat
        Removed! : C:\WINDOWS\addni.exe
        Removed! : C:\WINDOWS\ptcftr.dat
        Removed! : C:\WINDOWS\ureft.dat
        Removed! : C:\WINDOWS\iukbkh.dat
        Removed! : C:\WINDOWS\bvdgek.dat
        Removed! : C:\WINDOWS\tvvlgu.dat
        Removed! : C:\WINDOWS\eepym.dll
        Removed! : C:\WINDOWS\system32\lpaum.dll
        Removed! : C:\WINDOWS\system32\bnynb.dll
        Removed! : C:\WINDOWS\system32\zvxfh.dat
        Removed! : C:\WINDOWS\system32\gbvvs.dll
        Removed! : C:\WINDOWS\system32\atljm32.exe
        Removed! : C:\WINDOWS\system32\mjmnk.dll
        Removed! : C:\WINDOWS\system32\dfrvt.dat
        Attempted Clean Of Temp folder.
        Pages Reset… Done!

        – Scan 2 —————————
        About:Buster Version 4.0
        Reference List : 28


        ADS not scanned System(FAT)
        Attempted Clean Of Temp folder.
        Pages Reset… Done!


        gfile of HijackThis v1.99.1
        Scan saved at 2:14:15 PM, on 6/8/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ewido\security suite\ewidoctrl.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\ntta.exe
        C:\WINDOWS\system32\cryp.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\PROGRA~1\NORTON~1\navapw32.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
        C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
        C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
        C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
        C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
        C:\WINDOWS\System32\HPZipm12.exe
        C:\Documents and Settings\default\Desktop\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aktmi.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aktmi.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R3 - Default URLSearchHook is missing
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
        O2 - BHO: Class - {565744A1-C652-BC19-4230-289DA72A989C} - C:\WINDOWS\netwb32.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1424.0\en-us\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
        O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
        O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
        O4 - HKLM\..\Run: [cryp.exe] C:\WINDOWS\system32\cryp.exe
        O4 - HKLM\..\RunOnce: [crmn.exe] C:\WINDOWS\crmn.exe
        O4 - HKLM\..\RunOnce: [mscz.exe] C:\WINDOWS\mscz.exe
        O4 - HKLM\..\RunOnce: [cryt.exe] C:\WINDOWS\cryt.exe
        O4 - HKLM\..\RunOnce: [appbs.exe] C:\WINDOWS\appbs.exe
        O4 - HKLM\..\RunOnce: [sdkpc.exe] C:\WINDOWS\system32\sdkpc.exe
        O4 - HKLM\..\RunOnce: [apijd.exe] C:\WINDOWS\apijd.exe
        O4 - HKLM\..\RunOnce: [netli32.exe] C:\WINDOWS\netli32.exe
        O4 - HKLM\..\RunOnce: [ntvh32.exe] C:\WINDOWS\system32\ntvh32.exe
        O4 - HKLM\..\RunOnce: [apifk32.exe] C:\WINDOWS\apifk32.exe
        O4 - HKLM\..\RunOnce: [ieej32.exe] C:\WINDOWS\system32\ieej32.exe
        O4 - HKLM\..\RunOnce: [sysdd32.exe] C:\WINDOWS\sysdd32.exe
        O4 - HKLM\..\RunOnce: [javalh.exe] C:\WINDOWS\system32\javalh.exe
        O4 - HKLM\..\RunOnce: [msks.exe] C:\WINDOWS\msks.exe
        O4 - HKLM\..\RunOnce: [ntrc32.exe] C:\WINDOWS\ntrc32.exe
        O4 - HKLM\..\RunOnce: [javabc.exe] C:\WINDOWS\javabc.exe
        O4 - HKLM\..\RunOnce: [msli.exe] C:\WINDOWS\system32\msli.exe
        O4 - HKLM\..\RunOnce: [javawd.exe] C:\WINDOWS\system32\javawd.exe
        O4 - HKLM\..\RunOnce: [sysps32.exe] C:\WINDOWS\sysps32.exe
        O4 - HKLM\..\RunOnce: [iprw32.exe] C:\WINDOWS\iprw32.exe
        O4 - HKLM\..\RunOnce: [javaix32.exe] C:\WINDOWS\javaix32.exe
        O4 - HKLM\..\RunOnce: [winyf32.exe] C:\WINDOWS\system32\winyf32.exe
        O4 - HKLM\..\RunOnce: [appnv32.exe] C:\WINDOWS\system32\appnv32.exe
        O4 - HKLM\..\RunOnce: [ntta.exe] C:\WINDOWS\ntta.exe
        O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
        O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        O4 - Global Startup: officejet 6100.lnk = ?
        O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Ask Jeeves Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection
        O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O8 - Extra context menu item: Dictionary Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection-word
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
        O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
        O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
        O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
        O16 - DPF: eCrew Delta Technology V13100 - http://ecrew.delta-air.com/classes/cst/eCrew13100.cab
        O16 - DPF: eCrew Delta Technology V13112 - http://ecrew.delta-air.com/classes/cst/eCrew13112.cab
        O16 - DPF: eCrew Delta Technology V1381 - http://10.1.44.53/classes/cst/eCrew1381.cab
        O16 - DPF: eCrew Delta Technology V1397 - http://10.1.44.53/classes/cst/eCrew1397.cab
        O16 - DPF: eCrew Delta Technology V1410 - http://ecrew.delta-air.com/classes/cst/eCrew1410.cab
        O16 - DPF: eCrew Delta Technology V14102 - http://ecrew.delta-air.com/eCrew14102.cab
        O16 - DPF: eCrew Delta Technology V14120 - http://ecrew.delta-air.com/eCrew14120.cab
        O16 - DPF: eCrew Delta Technology V14141 - http://ecrew.delta-air.com/eCrew14141.cab
        O16 - DPF: eCrew Delta Technology V14169 - http://ecrew.delta-air.com/eCrew14169.cab
        O16 - DPF: eCrew Delta Technology V14170 - http://ecrew.delta-air.com/eCrew14170.cab
        O16 - DPF: eCrew Delta Technology V14180 - http://ecrew.delta-air.com/eCrew14180.cab
        O16 - DPF: eCrew Delta Technology V14200 - http://ecrew.delta-air.com/eCrew14200.cab
        O16 - DPF: eCrew Delta Technology V1451 - http://ecrew.delta-air.com/eCrew1451.cab
        O16 - DPF: eCrew Delta Technology V1472 - http://ecrew.delta-air.com/eCrew1472.cab
        O16 - DPF: eCrew Delta Technology V1486 - http://ecrew.delta-air.com/eCrew1486.cab
        O16 - DPF: eCrew Delta Technology V1491 - http://ecrew.delta-air.com/eCrew1491.cab
        O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) - http://diagnostics.support.hp.com/motivedo…w/ipgaxctrl.cab
        O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} (AJ Installer Control) - http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093355041187
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {C3498BF0-2C07-43C8-99D0-434B038334A6} (VDLaunch Class) - http://www.catharon.com/download/plugins/ievdl2.ocx
        O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://carpoint.msn.com/components/ocx/aut…/autopricer.cab
        O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?312
        O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\crmn.exe" /s (file missing)
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
        O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


        Again no luck with a complete Housecall scan. Disconnected
        Non cleanable or CanNotAccess files:
        TROJ AGENT .UO
        TROJ AGENT .LZ
        TROJ DOWNLOADER .HP
        TROJ WINSHOW.T
        TROJ AGENT .PG
        TROJ AGENT .GE


        Standing by.
        Av8tor
        Hello av8tor
        I apologize for taking so long to post a reply, but as you will see this is one big post.
        Also, if you have rebooted since you posted, I will need to see a fresh Hijack This log before we begin.

        The Fix:



        Step#1:Getting Ready

        ( If Notepad is not effected, then continue to use it.If Notepad is not working, use Word pad, as instructed just below.)


        Please save these instructions to WordPad so that you have them accessible while
        following the steps. You also may want to print out these directions as the Internet will not be available.
        You must disconnect from the internet totally, as staying connected while fixing will prevent the fix from working. This means completely removing the cable,or DSL connection. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection. Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet. It would be best to use Firefox,if you have access to it, or any browser other than Internet Explorer, when providing us with Hijack This logs etc.for the duration of this fix.

        Please start by downloading the tools you will need to clean this infection. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you do reply.

        Since you already have CWShredder and AboutBuster, an update on both is sufficient. However, there is one additional program you will need to download (Registrar Lite).


        Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
        http://www.davehigham.zen.co.uk/downloads/xphidden.zip



        Step#3: CWShredder


        Check for Updates but please Do NOT use it yet


        Step#4: About Buster

        Check to make sure it is up-to-date. Please Do NOT use it yet


        Step#5:Download Registrar Lite

        Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use.

        Please disconnect from the Internet

        Then, please disable MS Anti-Spyware, or it will attempt to prevent us from making the necessary changes. Directions to do so follow.
        Open Microsoft AntiSpyware.
        Click on Tools, Settings.
        In the left pane, click on Real-time Protection.
        Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
        Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
        After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
        Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
        After all of the fixes are complete it is very important that you enable Real-time Protection again.


        Next:
        Step#6:Disable The Bad Service
        • Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE
        • Click on start > control panel > administrative programs > services. Look for a service called (Network Security Service). Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.


        Step#7:Stop The Running Processes




        Press control-alt-delete to get into the task manager and end the following processes if they exist:

        C:\WINDOWS\system32\cryp.exe
        C:\WINDOWS\system32\sdkpc.exe
        C:\WINDOWS\system32\ntvh32.exe
        C:\WINDOWS\system32\ieej32.exe
        C:\WINDOWS\system32\javalh.exe
        C:\WINDOWS\system32\msli.exe
        C:\WINDOWS\system32\javawd.exe
        C:\WINDOWS\system32\winyf32.exe
        C:\WINDOWS\system32\appnv32.exe
        C:\WINDOWS\ntta.exe>


        Step#8:Use HijackThis to Delete About Blank

        I now need you to delete the following files:

        C:\WINDOWS\aktmi.dll
        C:\WINDOWS\agpoo.dll
        C:\WINDOWS\netwb32.dll

        C:\WINDOWS\crmn.exe
        C:\WINDOWS\mscz.exe
        C:\WINDOWS\cryt.exe
        C:\WINDOWS\appbs.exe

        C:\WINDOWS\apijd.exe
        C:\WINDOWS\netli32.exe
        C:\WINDOWS\apifk32.exe
        C:\WINDOWS\sysdd32.exe

        C:\WINDOWS\msks.exe
        C:\WINDOWS\ntrc32.exe
        C:\WINDOWS\javabc.exe

        C:\WINDOWS\sysps32.exe
        C:\WINDOWS\iprw32.exe
        C:\WINDOWS\javaix32.exe
        C:\WINDOWS\ntta.exe

        C:\WINDOWS\system32\cryp.exe
        C:\WINDOWS\system32\sdkpc.exe
        C:\WINDOWS\system32\ntvh32.exe
        C:\WINDOWS\system32\ieej32.exe
        C:\WINDOWS\system32\msli.exe
        C:\WINDOWS\system32\javawd.exe
        C:\WINDOWS\system32\javalh.exe
        C:\WINDOWS\system32\winyf32.exe
        C:\WINDOWS\system32\appnv32.exe

        If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



        Step#9:Cleaning With HijackThis

        Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aktmi.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\aktmi.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\agpoo.dll/sp.html#37049
        R3 - Default URLSearchHook is missing
        O2 - BHO: Class - {565744A1-C652-BC19-4230-289DA72A989C} - C:\WINDOWS\netwb32.dll
        O4 - HKLM\..\Run: [cryp.exe] C:\WINDOWS\system32\cryp.exe
        O4 - HKLM\..\RunOnce: [crmn.exe] C:\WINDOWS\crmn.exe
        O4 - HKLM\..\RunOnce: [mscz.exe] C:\WINDOWS\mscz.exe
        O4 - HKLM\..\RunOnce: [cryt.exe] C:\WINDOWS\cryt.exe
        O4 - HKLM\..\RunOnce: [appbs.exe] C:\WINDOWS\appbs.exe
        O4 - HKLM\..\RunOnce: [sdkpc.exe] C:\WINDOWS\system32\sdkpc.exe
        O4 - HKLM\..\RunOnce: [apijd.exe] C:\WINDOWS\apijd.exe
        O4 - HKLM\..\RunOnce: [netli32.exe] C:\WINDOWS\netli32.exe
        O4 - HKLM\..\RunOnce: [ntvh32.exe] C:\WINDOWS\system32\ntvh32.exe
        O4 - HKLM\..\RunOnce: [apifk32.exe] C:\WINDOWS\apifk32.exe
        O4 - HKLM\..\RunOnce: [ieej32.exe] C:\WINDOWS\system32\ieej32.exe
        O4 - HKLM\..\RunOnce: [sysdd32.exe] C:\WINDOWS\sysdd32.exe
        O4 - HKLM\..\RunOnce: [javalh.exe] C:\WINDOWS\system32\javalh.exe
        O4 - HKLM\..\RunOnce: [msks.exe] C:\WINDOWS\msks.exe
        O4 - HKLM\..\RunOnce: [ntrc32.exe] C:\WINDOWS\ntrc32.exe
        O4 - HKLM\..\RunOnce: [javabc.exe] C:\WINDOWS\javabc.exe
        O4 - HKLM\..\RunOnce: [msli.exe] C:\WINDOWS\system32\msli.exe
        O4 - HKLM\..\RunOnce: [javawd.exe] C:\WINDOWS\system32\javawd.exe
        O4 - HKLM\..\RunOnce: [sysps32.exe] C:\WINDOWS\sysps32.exe
        O4 - HKLM\..\RunOnce: [iprw32.exe] C:\WINDOWS\iprw32.exe
        O4 - HKLM\..\RunOnce: [javaix32.exe] C:\WINDOWS\javaix32.exe
        O4 - HKLM\..\RunOnce: [winyf32.exe] C:\WINDOWS\system32\winyf32.exe
        O4 - HKLM\..\RunOnce: [appnv32.exe] C:\WINDOWS\system32\appnv32.exe
        O4 - HKLM\..\RunOnce: [ntta.exe] C:\WINDOWS\ntta.exe
        O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\crmn.exe" /s (file missing)


        The following are recommended fixes:If you did not set the following 06 policies, or ask a program such as Spybot S&D to do so, then these two 06 entries can be fixed with Hijack This.

        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present



        click "fix checked"




        Step#10: Backup The Registry

        In the next step we are going to remove a service that gets installed by this malware.

        1. Open Registrar Lite and run it.

        2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

        Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

        1.) Winkey.reg (Save as type: regedit4 .reg type)
        2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)



        Step#11: Delete the Registry Entries

        3. Copy and paste each line of bold text below into the address bar of Reglite one at a time:
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\11Fßä#·ºÄÖ`I
        • Click Go
        • If 11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet00\Services\11Fßä#·ºÄÖ`I
        • Click Go
        • If 11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\11Fßä#·ºÄÖ`I
        • Click Go
        • If 11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

        4. Copy and Paste each line of bold text below into the address bar of Registrar Lite one at a time:
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_11Fßä#·ºÄÖ`I
        • Click Go
        • If LEGACY_11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY__11Fßä#·ºÄÖ`I
        • Click Go
        • If LEGACY_11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

          HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY__11Fßä#·ºÄÖ`I
        • Click Go
        • If LEGACY_ 11Fßä#·ºÄÖ`I exist it will be highlighted in the left pane , right click on it and choose delete from the menu.

        If you get errors when copying and pasting the above bold entries into RegLite please try replacing the bold text with the following abbreviated line, changed as necessary for each entry eg currentcontrolset001, currentcontrolset002
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\
          AND
        • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_
        If this search finds the bad entries please look in the left hand column for the funny looking letter/number combination and if found, right click and choose delete for each entry

        Please be cautious in identifying the correct entries in the registry because deleting other entries may cause serious problems with your PC




        Step#12:Fixing With CWShredder
        • CLOSE ALL WINDOWS except CWShredder
        • Run the program by clicking 'fix' and letting it fix all CWS remnants.


        Step#13:Fixing With About Buster

        This is the step where we will use About:Buster that you had downloaded previously.
        • Navigate to the c:\aboutbuster directory
        • double-click on aboutbuster.exe
        • When the tool opens press the OK button, then Start button, then the OK button
        • then finally the Yes button. It will start scanning your computer for files.
        • If it asks if you would like to do a second pass, allow it to do so.
        • Post the log file in your next reply


        Step#14:Saving and Using a Reg File

        Copy the contents of the Quote Box below to Notepad.
        Name the file as fix.reg
        Change the Save as Type to All Files
        and Save it on the desktop


        REGEDIT4

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HSA]

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE]

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW]


        Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

        Reboot your computer back to normal mode


        Step#15:Scan and Post a New HJT log with other logs
        • Scan again with HijackThis. We still have a few steps to complete but a log file at this time would be helpful.

        • Reconnect To The Internet


        • Post both your log from About Buster and your HijackThis log here in this thread with any questions or problems that you have run into. There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.

        • Good Luck!
        Hi Piatan. Wow. looks like I've got some work to do. I would like to ask for one clarification please. Step 8: Use HijackThis to Delete About Blank Delete the following files……. Am I using the Config Menu of Hijack to accomplish this? Open the Misc Tools Config menu –System tools —-Open process Manger and "kill the process" ?? I'm just not sure of how you want me to use Hijack to delete these files. I am familiar with hijacks function as used in step 9. and steps 10 and beyond are new territory so I will just follow the list. Computer has not been rebooted since my last post. Thanks for all the hard work. when I'm sure of how to proceed with step 8 I will give it a go. Av8tor
        Hi av8tor; I plead guilty to using a canned speech for this fix, though the entries are difficult enough. The canned speech is new, so may have a few oddities, as you know. Regarding Step 8. That header is definately misleading. Just delete those files as you normally would, nothing at all different is necessary. You are also right about the following steps, certainly new territory. If you have any additional questions, please do not hesitate to ask.
        Hello Piatan.
        Sorry it took so long to get back but I've been out of town for a few days.
        Worked on the instructions sheet and am not sure we made any progress. I will give you a fell how it went as I went thru the instructions.
        NOTE: No one had to rebbot the computer while I was away but it was used online. I tried to install firefox to keep this going but I think I'm a litle fried and am missing something obvious to get it running.
        Step #3- CWShredder updated to V2.15

        #4 Aboutbuster update 30

        #5 no prob

        #6 Disabled Network Security Service.
        Service name is the "junkName"
        path is "c:\WINDOWS\crmn.exe" /s

        #7in safe mode the followimg processes are running
        taskmgr.exe
        explorer.exe
        svchost.exe (file size added because there is 3 identical 7.9k)
        svchost.exe (3.6k)
        svchost.exe (3.0k)
        lsass.exe
        services.exe
        winlogon.exe
        csrss.exe
        smss.exe
        system
        System Idle PROCESS SYSTEM

        #8 Found and deleted many of the files listed
        exceptions \WINDOWS\cryt.exe
        \WINDOWS\ntta.exe
        entire last list(WINDOWS\system32\
        I looked on the drive, then to windows folder, found the said file, then deleted file. If I could not find the file I ran a search for it and then deleted It. Did I do it correctly ?? I would not be suprised if I was incorrect in the procedure but I thought I could find them. also there looked to be files similar to the dll files I deleted.

        #9 Worked fine. deleted all assigned
        Note the last 2 (06 HKCU\Software……) were not avail in the safe mode.

        #10/11 Think I did this all correctly.. I believe it was only the first one that the junk appeared in the left pane and I deleted it.

        #12 Saved as instructed and when prompted to merge recieved error msg.
        Cannot import
        The specified file is not a registry script. You can only import binary registry files from within the registry editor.
        went back and confirmed that Save as type was all
        Drop down box below was set to ANSI. Other choices available were
        Unicode
        Unicode big endian
        UTF-8

        Rebooted and ran Hijack. Looks to me like it is still here because some of the items deleted are back.

        here are my logs







        Scanned at: 2:42:28 PM on: 6/15/2005


        – Scan 1 —————————
        About:Buster Version 4.0
        Reference List : 30


        ADS not scanned System(FAT)
        Removed 2 Random Key Entries
        Removed! : C:\WINDOWS\ehxig.dll
        Removed! : C:\WINDOWS\yyrxd.dll
        Removed! : C:\WINDOWS\xcbcl.dll
        Removed! : C:\WINDOWS\system32\mggug.dll
        Removed! : C:\WINDOWS\system32\iclto.dll
        Attempted Clean Of Temp folder.
        Pages Reset… Done!

        – Scan 2 —————————
        About:Buster Version 4.0
        Reference List : 30


        ADS not scanned System(FAT)
        Attempted Clean Of Temp folder.
        Pages Reset… Done!




        Logfile of HijackThis v1.99.1
        Scan saved at 3:00:57 PM, on 6/15/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ewido\security suite\ewidoctrl.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\PROGRA~1\NORTON~1\navapw32.exe
        C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
        C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
        C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
        C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
        C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\System32\HPZipm12.exe
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Documents and Settings\default\Desktop\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\lqadh.dll/sp.html#37049
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
        R3 - Default URLSearchHook is missing
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O2 - BHO: Class - {FD657148-CFF7-B0FA-3DF2-27DD4B37658F} - C:\WINDOWS\system32\d3qg.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1424.0\en-us\msntb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
        O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
        O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
        O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
        O4 - HKLM\..\RunOnce: [msff.exe] C:\WINDOWS\system32\msff.exe
        O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
        O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
        O4 - Global Startup: officejet 6100.lnk = ?
        O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
        O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Ask Jeeves Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection
        O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O8 - Extra context menu item: Dictionary Search - res://C:\WINDOWS\System32\askbarAB.dll/cmd-search-selection-word
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
        O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
        O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
        O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
        O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
        O16 - DPF: eCrew Delta Technology V13100 - http://ecrew.delta-air.com/classes/cst/eCrew13100.cab
        O16 - DPF: eCrew Delta Technology V13112 - http://ecrew.delta-air.com/classes/cst/eCrew13112.cab
        O16 - DPF: eCrew Delta Technology V1381 - http://10.1.44.53/classes/cst/eCrew1381.cab
        O16 - DPF: eCrew Delta Technology V1397 - http://10.1.44.53/classes/cst/eCrew1397.cab
        O16 - DPF: eCrew Delta Technology V1410 - http://ecrew.delta-air.com/classes/cst/eCrew1410.cab
        O16 - DPF: eCrew Delta Technology V14102 - http://ecrew.delta-air.com/eCrew14102.cab
        O16 - DPF: eCrew Delta Technology V14120 - http://ecrew.delta-air.com/eCrew14120.cab
        O16 - DPF: eCrew Delta Technology V14141 - http://ecrew.delta-air.com/eCrew14141.cab
        O16 - DPF: eCrew Delta Technology V14169 - http://ecrew.delta-air.com/eCrew14169.cab
        O16 - DPF: eCrew Delta Technology V14170 - http://ecrew.delta-air.com/eCrew14170.cab
        O16 - DPF: eCrew Delta Technology V14180 - http://ecrew.delta-air.com/eCrew14180.cab
        O16 - DPF: eCrew Delta Technology V14200 - http://ecrew.delta-air.com/eCrew14200.cab
        O16 - DPF: eCrew Delta Technology V1451 - http://ecrew.delta-air.com/eCrew1451.cab
        O16 - DPF: eCrew Delta Technology V1472 - http://ecrew.delta-air.com/eCrew1472.cab
        O16 - DPF: eCrew Delta Technology V1486 - http://ecrew.delta-air.com/eCrew1486.cab
        O16 - DPF: eCrew Delta Technology V1491 - http://ecrew.delta-air.com/eCrew1491.cab
        O16 - DPF: {058025FC-4416-436B-ACFD-03E6224C901C} (FileInfo Class) - http://diagnostics.support.hp.com/motivedo…w/ipgaxctrl.cab
        O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} (AJ Installer Control) - http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1093355041187
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {C3498BF0-2C07-43C8-99D0-434B038334A6} (VDLaunch Class) - http://www.catharon.com/download/plugins/ievdl2.ocx
        O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://carpoint.msn.com/components/ocx/aut…/autopricer.cab
        O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?312
        O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\msff.exe
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
        O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


        Thanks for your efforts and once again in the delay.
        I should be around for a couple of days and will try to watch for a reply and respond quickly over the next couple of days.

        Think I followed the instructions pretty well but I am a little nervous about your reply about my attempts to delete the files requested.. Well I'm learning.

        Standing by
        av8tor

        Ask AI

        AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

        Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI