This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Stubborn Infection

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All,

This is my first posting here and would greatly appreciate any help. I have an infection that keeps throwing up pop-ups and adds hyperlinks to key words on web pages. I tracked down many .dll files that were suspect, but they keep replicating under new names after they are deleted. netaf.dll was one of them and javadf.exe was an .exe file that seemed suspect as well.

I have tried Spybot, Ad-Aware 1.06, Microsoft Anti-Spyware, and Spy Sweeper to no avail. CWS shredder now gives me a blue screen of death and Spybot is now saying that there was an error during scanning at the end of the scan. This is a copy of my HJT log. Thanks again!


MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\WDBtnMgr.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\mfcgy32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\sysat.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Documents and Settings\TJ Scheidel\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\TJ Scheidel\Application Data\Mozilla\Profiles\default\i1rhdl2p.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Class - {15B62A91-B604-E8BE-823F-826E91DF8EB7} - C:\WINDOWS\apilk.dll
O2 - BHO: Class - {36D6C7FD-FCAC-86D3-0A01-29E6A5D9B94F} - C:\WINDOWS\apilk.dll
O2 - BHO: Class - {9E394F5F-BB60-E2B1-4D4B-08C63F49D782} - C:\WINDOWS\apilk.dll
O2 - BHO: Class - {E4D4E13B-CB89-A761-6A5C-64D83E95B9FC} - C:\WINDOWS\apilk.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FullAudio] "C:\PROGRA~1\MUSICN~1\WMPImporter.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [mfcgy32.exe] C:\WINDOWS\mfcgy32.exe
O4 - HKLM\..\Run: [javalp.exe] C:\WINDOWS\javalp.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.truedoc.com/activex/tdserver.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.bulletinboards.com/CFIDE/classes/CFJava.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid;=0x409
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} (eAssist NetAgent Customer ActiveX Control version 3) - https://quicken.ehosts.net/netagent/objects/custappx3.CAB
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://64.124.45.181/downloads/ccpm_0237.cab
O16 - DPF: {2B4F4FA8-814A-11D7-B31B-0002A500B281} (FASetupStart Control) - http://a2.ff.fullaudio.com.edgesuite.net/f….0.55/setup.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://petmail.cti-pet.com/iNotes6.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1106190497125
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - http://www.shop.intuit.com/commerce/accoun…bles/ie/IDA.cab
O16 - DPF: {B69F2A9C-E470-11D3-AFA3-525400DB7692} (Actimage Room Control) - http://dar.armstrong.com/ib/databases/actimage30717.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysat.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello Angryboss, welcome to the TC.


Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click and select….. Save Target As….Save

To use: Right-click and select……. Install (no need to restart)
**Note** This will remove all entries in the "Trusted Zone"



We need To disable SpySweeper:

Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck 'automaticly restore default without notifiction".




I suggest you do this:


Next, open HijackThis
Click on: Config
Click on: Misc Tools
Click on: Delete an NT Service
In the prompt: Delete an NT Service copy/paste: 11Fßä#·ºÄÖ`I
Press: Enter
Press: OK



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;

R3 - Default URLSearchHook is missing

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)

O2 - BHO: Class - {15B62A91-B604-E8BE-823F-826E91DF8EB7} - C:\WINDOWS\apilk.dll

O2 - BHO: Class - {36D6C7FD-FCAC-86D3-0A01-29E6A5D9B94F} - C:\WINDOWS\apilk.dll

O2 - BHO: Class - {9E394F5F-BB60-E2B1-4D4B-08C63F49D782} - C:\WINDOWS\apilk.dll

O2 - BHO: Class - {E4D4E13B-CB89-A761-6A5C-64D83E95B9FC} - C:\WINDOWS\apilk.dll

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - HKLM\..\Run: [mfcgy32.exe] C:\WINDOWS\mfcgy32.exe

O4 - HKLM\..\Run: [javalp.exe] C:\WINDOWS\javalp.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O15 - Trusted IP range: 206.161.125.149

ALL 016's. They'll come back if needed,

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysat.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"




Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.



Search for and delete these files if listed:
C:\WINDOWS\mfcgy32.exe
C:\WINDOWS\javalp.exe
C:\WINDOWS\sysat.exe



Open C:\Windows\Prefetch\ Delete ALL files in this folder.


Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi LDTate, I did what you said, although some of the files had changed names I think. When I was deleting the java file, I noticed a lot of files with similar names that were the same size. Now, after a restart, I get the about:blank home page. Thank you for your assistance. Logfile of HijackThis v1.99.1 Scan saved at 10:08:06 PM, on 6/19/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\DSentry.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\System32\CTsvcCDA.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\Program Files\America Online 8.0\aoltray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe C:\WINDOWS\System32\nvsvc32.exe C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\appfp.exe C:\WINDOWS\system32\appbw.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\TJ Scheidel\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\egsjj.dll/sp.html#37049 R3 - Default URLSearchHook is missing N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\TJ Scheidel\Application Data\Mozilla\Profiles\default\i1rhdl2p.slt\prefs.js) O2 - BHO: Class - {CF55FDE9-BA43-BE10-5455-CE366744EC0C} - C:\WINDOWS\mfcmv.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [appbw.exe] C:\WINDOWS\system32\appbw.exe O4 - HKLM\..\RunOnce: [appfp.exe] C:\WINDOWS\system32\appfp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysat.exe (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet)

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above Starting with: Reboot into safe mode..

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.




run it in safe mode and run it twice
Hi LDTate, I ran the SpSeHjfix112.exe in Safe Mode then tried to run CWS Shredder v2.15. CWS shredder crashed the system again as soon as it looks like it is getting ready to look for/fix the Homesearch problem, I go right to a blue error screen that says that a critical process was terminated. I tried it twice. Here are the logs for the SpSeHjfix112.exe program and a new HJT log. I really appreciate all the help so far. (6/20/05 7:25:44 PM) SPSeHjFix started v1.1.2 (6/20/05 7:25:44 PM) OS: WinXP Service Pack 2 (5.1.2600) (6/20/05 7:25:44 PM) Language: english (6/20/05 7:25:44 PM) Win-Path: C:\WINDOWS (6/20/05 7:25:44 PM) System-Path: C:\WINDOWS\system32 (6/20/05 7:25:44 PM) Temp-Path: C:\DOCUME~1\TJSCHE~1\LOCALS~1\Temp\ (6/20/05 7:25:47 PM) Disinfection started (6/20/05 7:25:47 PM) Bad-Dll(IEP): c:\windows\lawli.dll (6/20/05 7:25:47 PM) UBF: 7 - UBB: 0 - UBR: 18 (6/20/05 7:25:47 PM) UBF: 7 - UBB: 0 - UBR: 18 (6/20/05 7:25:47 PM) Bad IE-pages: deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\lawli.dll/sp.html#37049 Logfile of HijackThis v1.99.1 Scan saved at 7:34:53 PM, on 6/20/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\System32\CTsvcCDA.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\system32\appfp.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Winamp3\winampa.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\WINDOWS\system32\WDBtnMgr.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\WINDOWS\system32\appbw.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\America Online 8.0\aoltray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\TJ Scheidel\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\kbucj.dll/sp.html#37049 R3 - Default URLSearchHook is missing N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\TJ Scheidel\Application Data\Mozilla\Profiles\default\i1rhdl2p.slt\prefs.js) O2 - BHO: Class - {049A8A3E-05E8-D2B5-4653-619CE6A7149E} - C:\WINDOWS\system32\netwn.dll O2 - BHO: Class - {72D88229-59F8-D733-B034-6BF44B4FA569} - C:\WINDOWS\system32\netwn.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [appbw.exe] C:\WINDOWS\system32\appbw.exe O4 - HKLM\..\RunOnce: [appfp.exe] C:\WINDOWS\system32\appfp.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\sysat.exe (file missing) O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Delete the CWShredder you have now and download the latest:

Please save these instructions to a text file in Wordpad or print them out because we will be restarting in Safe Mode and you will have no Internet Connection
  • Download CWShredder.
  • Save CWShredder.exe to a convenient location.
  • Please Do Not Use It Yet.
  • Download AboutBuster.
  • Unzip AboutBuster.zip and it will install in it's own folder.
  • Double-click on AboutBuster.exe and then click 'OK' then 'Update'
  • Click "Check For Update" and then "Download Update".
  • Click "Exit"
  • Please Do Not Use It Yet.
Disconnect From The Internet

Boot into Safe Mode:
Restart your computer and tap F8 repeatedly while booting up and choose Safe Mode at the menu.

In Safe Mode Please Clean with CWShredder
  • Please Double-click on CWShredder.exe.
  • Click "Fix ->" and click "OK" at the prompt.
  • CWShredder will scan and clean your system of CWS files.
  • Click "Next->" and then "Exit".
In Safe Mode Please Use AboutBuster
  • Please Double-click on AboutBuster.exe.
  • Click "OK" then "Start" and then "OK" to allow AboutBuster to scan for all bad files.
  • Click "Yes" when About Buster asks if you will allow it to shutdown explorer.exe.
  • Allow AboutBuster to scan for all malicious files.
  • Repeat the scan if it asks to do another.
  • After the scan, click "Save Log". Post the log in your next post as it is necessary to make sure all has been cleaned
  • Then Click "Exit"
This infection often deletes necessary system files.
Reboot your computer back into normal mode so that we can see if any files need to be restored.
  • This infection deletes the windows file, shell.dll.

    If you are using XP,2000, or NT please download shell.dll from here: shell-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations:
    C:\Windows\system32
    C:\Windows\system


    If you are using Windows 98/ME please download shell.dll from here: shell98-dll.zip. Once the file is downloaded uncompress the zip file and copy shell.dll to the following locations
    C:\Windows\system
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
  • If you are using Windows 95, 98, or ME it is possible that the malware deleted your control.exe. Please check for the existence of this file by going to to Merijn Files control.exe and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to this information.
  • There are several other files that are not targeted as often as the above, but new copies of them can be downloaded from
    Merijn Files
Online Antivirus Scan
  • Please go to The TrendMicro Housecall website.
  • Allow it to scan and fix anything that it finds.
  • Please Clean out temporary files:
  • Start> Run> then type cleanmgr and click enter
  • Please put a check mark beside Temporary Files, Temporary Internet Files, and Recycle Bin
  • Let cleanmgr scan your system and remove the files indicated
Reboot and Post a New HijackThis Log and your About Buster Log in this thread, using Add Reply to see what is left to clean.
Hi LDTate,

Here are the About Buster and HJT logs. My home page is no longer being hijacked to the about:blank screen. I have also not had any pop-ups.

AboutBuster 5.0 reference file 30
Scan started on [6/20/2005] at [9:37:31 PM]
————————————————
Removed Stream! C:\WINDOWS\$_hpcst$.hpc:bogijg
Removed Stream! C:\WINDOWS\3dr.ini:kmzhzz
Removed Stream! C:\WINDOWS\3dr.ini:upznlq
Removed Stream! C:\WINDOWS\AC3API.INI:rqoate
Removed Stream! C:\WINDOWS\aftah.log:mhragt
Removed Stream! C:\WINDOWS\aubzm.log:ficgid
Removed Stream! C:\WINDOWS\awmrs.log:nvbmqm
Removed Stream! C:\WINDOWS\bfano.log:fwurkx
Removed Stream! C:\WINDOWS\bgmnp.log:aqjzls
Removed Stream! C:\WINDOWS\bgmnp.log:icskso
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:hbhzdv
Removed Stream! C:\WINDOWS\BOOTSTAT.DAT:acdpnz
Removed Stream! C:\WINDOWS\buytk.log:acsexf
Removed Stream! C:\WINDOWS\bwoiq.txt:kjpvpd
Removed Stream! C:\WINDOWS\bwoiq.txt:mheylh
Removed Stream! C:\WINDOWS\bwoiq.txt:sgcezw
Removed Stream! C:\WINDOWS\CLIFFS.LOG:sprkif
Removed Stream! C:\WINDOWS\CLOCK.AVI:cjcxwk
Removed Stream! C:\WINDOWS\CLOCK.AVI:tdvdpj
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:cjhirn
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:cyzawn
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:eiwdnr
Removed Stream! C:\WINDOWS\COMSETUP.LOG:ukvcrm
Removed Stream! C:\WINDOWS\COMSETUP.LOG:vewcod
Removed Stream! C:\WINDOWS\CONTROL.INI:bbmwv
Removed Stream! C:\WINDOWS\CONTROL.INI:uzsfqp
Removed Stream! C:\WINDOWS\CONTROL.INI:ykcuwh
Removed Stream! C:\WINDOWS\corelpf.lrs:rlmbhi
Removed Stream! C:\WINDOWS\cwwbf.txt:ofghqf
Removed Stream! C:\WINDOWS\DESKTOP.INI:wrnhhc
Removed Stream! C:\WINDOWS\DirectX.log:jiaopg
Removed Stream! C:\WINDOWS\dqzks.dat:osfnbf
Removed Stream! C:\WINDOWS\DtcInstall.log:cibzea
Removed Stream! C:\WINDOWS\DtcInstall.log:tglhh
Removed Stream! C:\WINDOWS\DtcInstall.log:tusrym
Removed Stream! C:\WINDOWS\DUMPa50a.tmp:favymk
Removed Stream! C:\WINDOWS\DUMPa50a.tmp:fgmisp
Removed Stream! C:\WINDOWS\DUMPa50a.tmp:flynnh
Removed Stream! C:\WINDOWS\DUMPa50a.tmp:qdlqtm
Removed Stream! C:\WINDOWS\eailg.txt:wgttqs
Removed Stream! C:\WINDOWS\ebcnq.log:gtqadp
Removed Stream! C:\WINDOWS\efdlg.txt:okdwug
Removed Stream! C:\WINDOWS\EXPLORER.SCF:rozwsc
Removed Stream! C:\WINDOWS\EXPLORER.SCF:ztjfxa
Removed Stream! C:\WINDOWS\FaxSetup.log:qcgijx
Removed Stream! C:\WINDOWS\FaxSetup.log:sgcezw
Removed Stream! C:\WINDOWS\fdcij.txt:nkwmfe
Removed Stream! C:\WINDOWS\FeatherTexture.bmp:bedtev
Removed Stream! C:\WINDOWS\FeatherTexture.bmp:dzksmy
Removed Stream! C:\WINDOWS\FeatherTexture.bmp:voizff
Removed Stream! C:\WINDOWS\fthwk.dat:lhnsth
Removed Stream! C:\WINDOWS\fthwk.dat:mdyuzw
Removed Stream! C:\WINDOWS\fthwk.dat:ohhlld
Removed Stream! C:\WINDOWS\ftnyc.log:hhwmmn
Removed Stream! C:\WINDOWS\ftnyc.log:iiqxjm
Removed Stream! C:\WINDOWS\ftnyc.log:qnjgju
Removed Stream! C:\WINDOWS\fzrzw.dat:hasrgo
Removed Stream! C:\WINDOWS\fzrzw.dat:pdhebq
Removed Stream! C:\WINDOWS\ggqdo.log:rqoepy
Removed Stream! C:\WINDOWS\Gone Fishing.bmp:iesjeb
Removed Stream! C:\WINDOWS\Gone Fishing.bmp:notezp
Removed Stream! C:\WINDOWS\grcts.txt:vzdxgj
Removed Stream! C:\WINDOWS\Greenstone.bmp:tktqfh
Removed Stream! C:\WINDOWS\hoefh.log:aymvjq
Removed Stream! C:\WINDOWS\hplj1010.bu1:bqchox
Removed Stream! C:\WINDOWS\hplj1010.bu1:ylxxvx
Removed Stream! C:\WINDOWS\hplj1010.bu2:bxahyq
Removed Stream! C:\WINDOWS\hplj1010.bu2:fplkbs
Removed Stream! C:\WINDOWS\hplj1010.hi1:gctlaj
Removed Stream! C:\WINDOWS\hplj1010.hi1:trfbda
Removed Stream! C:\WINDOWS\hplj1010.hi2:fgzrus
Removed Stream! C:\WINDOWS\hplj1010.ini:xfnraw
Removed Stream! C:\WINDOWS\huzzn.dat:ukjcnd
Removed Stream! C:\WINDOWS\ICOADB32.DAT:hggwcy
Removed Stream! C:\WINDOWS\ICOADB32.DAT:imairs
Removed Stream! C:\WINDOWS\IIS6.LOG:mivveh
Removed Stream! C:\WINDOWS\IIS6.LOG:vynfpr
Removed Stream! C:\WINDOWS\INTUPREM.DAT:flnncq
Removed Stream! C:\WINDOWS\INTUPREM.DAT:ozxlrb
Removed Stream! C:\WINDOWS\INTUPREM.DAT:rygnxl
Removed Stream! C:\WINDOWS\intuprof.ini:ablode
Removed Stream! C:\WINDOWS\iunlb.log:mhemuh
Removed Stream! C:\WINDOWS\jautoexp.dat:dcdeet
Removed Stream! C:\WINDOWS\jautoexp.dat:oisuwt
Removed Stream! C:\WINDOWS\jautoexp.dat:uujnhr
Removed Stream! C:\WINDOWS\jpydj.dat:carfug
Removed Stream! C:\WINDOWS\jskqh.txt:kemesz
Removed Stream! C:\WINDOWS\jumsy.log:fvbajb
Removed Stream! C:\WINDOWS\jumsy.log:vodqzb
Removed Stream! C:\WINDOWS\jvdui.log:xjpfru
Removed Stream! C:\WINDOWS\KB823980.log:gdoxao
Removed Stream! C:\WINDOWS\KB828741.log:npovbm
Removed Stream! C:\WINDOWS\KB828741.log:wbscbn
Removed Stream! C:\WINDOWS\KB833987.log:gjlzqd
Removed Stream! C:\WINDOWS\KB833987.log:pkakle
Removed Stream! C:\WINDOWS\KB833987.log:xviqvt
Removed Stream! C:\WINDOWS\KB840987.log:ufxxou
Removed Stream! C:\WINDOWS\KB841356.log:cierpx
Removed Stream! C:\WINDOWS\KB841356.log:njtxlz
Removed Stream! C:\WINDOWS\KB841356.log:qxelfo
Removed Stream! C:\WINDOWS\KB842773.log:ggksdl
Removed Stream! C:\WINDOWS\KB842773.log:qildgc
Removed Stream! C:\WINDOWS\KB871250.log:gjecfc
Removed Stream! C:\WINDOWS\KB871250.log:ngicqw
Removed Stream! C:\WINDOWS\KB871250.log:rjfwrp
Removed Stream! C:\WINDOWS\KB873333.log:qqvxrc
Removed Stream! C:\WINDOWS\KB873339.log:spxsjy
Removed Stream! C:\WINDOWS\KB873376.log:hgednj
Removed Stream! C:\WINDOWS\KB873376.log:qhdffn
Removed Stream! C:\WINDOWS\KB873376.log:txenlr
Removed Stream! C:\WINDOWS\KB885492.log:brfdln
Removed Stream! C:\WINDOWS\KB885835.log:lywtnb
Removed Stream! C:\WINDOWS\KB885836.log:bypdbb
Removed Stream! C:\WINDOWS\KB887472.log:chvech
Removed Stream! C:\WINDOWS\KB887742.log:drhyid
Removed Stream! C:\WINDOWS\KB889293-IE6SP1-20041111.235619.log:mcxica
Removed Stream! C:\WINDOWS\KB889293-IE6SP1-20041111.235619.log:ofooju
Removed Stream! C:\WINDOWS\KB889293-IE6SP1-20041111.235619.log:wsadko
Removed Stream! C:\WINDOWS\KB890046.log:txenlr
Removed Stream! C:\WINDOWS\KB890175.log:bujiym
Removed Stream! C:\WINDOWS\KB890175.log:lkrvha
Removed Stream! C:\WINDOWS\KB890175.log:qaywpb
Removed Stream! C:\WINDOWS\KB891781.log:gihbgh
Removed Stream! C:\WINDOWS\KB891781.log:umcosw
Removed Stream! C:\WINDOWS\KB893066.log:fzomqc
Removed Stream! C:\WINDOWS\KB893066.log:kjfugi
Removed Stream! C:\WINDOWS\KB893066.log:xkqcse
Removed Stream! C:\WINDOWS\KB893803v2.log:tppbma
Removed Stream! C:\WINDOWS\kfgzv.log:jcczff
Removed Stream! C:\WINDOWS\kfgzv.log:yayakf
Removed Stream! C:\WINDOWS\kqzcq.txt:iidahu
Removed Stream! C:\WINDOWS\lfahw.dat:ilbnoz
Removed Stream! C:\WINDOWS\Live.bmp:gghuew
Removed Stream! C:\WINDOWS\Live.bmp:megktr
Removed Stream! C:\WINDOWS\Live.bmp:tchtfz
Removed Stream! C:\WINDOWS\Live.ico:jbqkjm
Removed Stream! C:\WINDOWS\lkfwl.dat:bemajj
Removed Stream! C:\WINDOWS\MedCtrOC.log:feyxvc
Removed Stream! C:\WINDOWS\MedCtrOC.log:ulampn
Removed Stream! C:\WINDOWS\Microsoft.MIF:ejimzl
Removed Stream! C:\WINDOWS\Microsoft.MIF:yhzhgh
Removed Stream! C:\WINDOWS\mozver.dat:wjbsbw
Removed Stream! C:\WINDOWS\mozver.dat:ynsnal
Removed Stream! C:\WINDOWS\MSDFMAP.INI:wdklbm
Removed Stream! C:\WINDOWS\MSDFMAP.INI:yccsou
Removed Stream! C:\WINDOWS\MSGSOCM.LOG:cucwhw
Removed Stream! C:\WINDOWS\MSGSOCM.LOG:jhemyy
Removed Stream! C:\WINDOWS\MSMQINST.LOG:femflz
Removed Stream! C:\WINDOWS\MSMQINST.LOG:gjxovt
Removed Stream! C:\WINDOWS\MSMQINST.LOG:rofxgv
Removed Stream! C:\WINDOWS\mugpo.txt:vnjnzx
Removed Stream! C:\WINDOWS\mugpo.txt:vvebid
Removed Stream! C:\WINDOWS\NETFXOCM.LOG:chwzsi
Removed Stream! C:\WINDOWS\nlvap.dat:jpydjf
Removed Stream! C:\WINDOWS\nlvap.dat:zdekxj
Removed Stream! C:\WINDOWS\notepad.exe.bak:uumbjz
Removed Stream! C:\WINDOWS\nsreg.dat:jdnkkh
Removed Stream! C:\WINDOWS\nsreg.dat:unmffd
Removed Stream! C:\WINDOWS\nsw.log:affveu
Removed Stream! C:\WINDOWS\nsw.log:gohtfq
Removed Stream! C:\WINDOWS\nsw.log:gpuywk
Removed Stream! C:\WINDOWS\ntdtcsetup.log:qonsut
Removed Stream! C:\WINDOWS\nxock.log:kehdue
Removed Stream! C:\WINDOWS\n_dhhxuv.dat:joxgwd
Removed Stream! C:\WINDOWS\n_htdnzi.txt:cfaiog
Removed Stream! C:\WINDOWS\n_jnrsbt.log:ecepyd
Removed Stream! C:\WINDOWS\n_jnrsbt.log:mofkzg
Removed Stream! C:\WINDOWS\n_ucwphj.dat:gihbgh
Removed Stream! C:\WINDOWS\n_vrfpiy.txt:kldmvz
Removed Stream! C:\WINDOWS\n_vrfpiy.txt:meobeb
Removed Stream! C:\WINDOWS\OCGEN.LOG:zjzhik
Removed Stream! C:\WINDOWS\OCMSN.LOG:myyadf
Removed Stream! C:\WINDOWS\ODBC.INI:dmwrxk
Removed Stream! C:\WINDOWS\OEWABLog.txt:crrhtg
Removed Stream! C:\WINDOWS\OEWABLog.txt:ezrfxi
Removed Stream! C:\WINDOWS\OEWABLog.txt:jzgxef
Removed Stream! C:\WINDOWS\OEWABLog.txt:zljztw
Removed Stream! C:\WINDOWS\okyow.txt:dhbtvr
Removed Stream! C:\WINDOWS\okyow.txt:pfslbo
Removed Stream! C:\WINDOWS\okyow.txt:tgltrw
Removed Stream! C:\WINDOWS\OOBEACT.LOG:fubmom
Removed Stream! C:\WINDOWS\OOBEACT.LOG:tzrdgq
Removed Stream! C:\WINDOWS\orun32.isu:mheylh
Removed Stream! C:\WINDOWS\orun32.isu:vskmnr
Removed Stream! C:\WINDOWS\pbyob.dat:yylyfa
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:ojmdre
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:ypqkxk
Removed Stream! C:\WINDOWS\pyewj.txt:qyvehk
Removed Stream! C:\WINDOWS\Q327979.log:auvugw
Removed Stream! C:\WINDOWS\Q327979.log:urkogb
Removed Stream! C:\WINDOWS\Q329048.log:dhdsrq
Removed Stream! C:\WINDOWS\Q329909.log:fggyaf
Removed Stream! C:\WINDOWS\Q329909.log:rhjpru
Removed Stream! C:\WINDOWS\Q329909.log:yresdh
Removed Stream! C:\WINDOWS\Q331060.log:dnexjt
Removed Stream! C:\WINDOWS\Q331953.log:ntqjoa
Removed Stream! C:\WINDOWS\Q331953.log:suohig
Removed Stream! C:\WINDOWS\Q331953.log:txqphu
Removed Stream! C:\WINDOWS\q812415.log:jitute
Removed Stream! C:\WINDOWS\q812415.log:qroxxj
Removed Stream! C:\WINDOWS\Q813862.log:fuboic
Removed Stream! C:\WINDOWS\Q816486.log:eqtadh
Removed Stream! C:\WINDOWS\Q816982.log:qvmzfx
Removed Stream! C:\WINDOWS\Q816982.log:vwjxzd
Removed Stream! C:\WINDOWS\qjwnj.txt:vbiddo
Removed Stream! C:\WINDOWS\qjwnj.txt:xrlfxr
Removed Stream! C:\WINDOWS\Readme.txt:ncbixz
Removed Stream! C:\WINDOWS\River Sumida.bmp:bpprbk
Removed Stream! C:\WINDOWS\River Sumida.bmp:gqvqvq
Removed Stream! C:\WINDOWS\rooxv.dat:awdueo
Removed Stream! C:\WINDOWS\SBMIXDEF.INI:uiucfm
Removed Stream! C:\WINDOWS\SchedLgU.Txt:jtanoi
Removed Stream! C:\WINDOWS\scunin.dat:eifizw
Removed Stream! C:\WINDOWS\scunin.dat:ssmmtf
Removed Stream! C:\WINDOWS\sessmgr.setup.log:cuktqk
Removed Stream! C:\WINDOWS\SETUPACT.LOG:mxtdlj
Removed Stream! C:\WINDOWS\SETUPACT.LOG:rtcmex
Removed Stream! C:\WINDOWS\setupapi.log.0.old:mcexiq
Removed Stream! C:\WINDOWS\setupapi.log.0.old:mvdgku
Removed Stream! C:\WINDOWS\SETUPERR.LOG:dtpfqs
Removed Stream! C:\WINDOWS\SETUPLOG.TXT:jumsyh
Removed Stream! C:\WINDOWS\smscfg.ini:mygbra
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:knbphz
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:rqbbvj
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:usaeim
Removed Stream! C:\WINDOWS\Sti_Trace.log:nnapmf
Removed Stream! C:\WINDOWS\Sti_Trace.log:wyfviw
Removed Stream! C:\WINDOWS\swonh.log:zwsedg
Removed Stream! C:\WINDOWS\SYSTEM.INI:jrhyds
Removed Stream! C:\WINDOWS\SYSTEM.INI:lzmhiw
Removed Stream! C:\WINDOWS\TABLETOC.LOG:hzxblu
Removed Stream! C:\WINDOWS\thxro.log:yodiia
Removed Stream! C:\WINDOWS\tioxc.log:mhkdvf
Removed Stream! C:\WINDOWS\tpvzv.dat:jpwnlc
Removed Stream! C:\WINDOWS\twjyj.log:urmmrw
Removed Stream! C:\WINDOWS\uhdqk.txt:saauhg
Removed Stream! C:\WINDOWS\uieks.txt:pbgbmc
Removed Stream! C:\WINDOWS\uieks.txt:pfanzn
Removed Stream! C:\WINDOWS\VB.INI:cmaidd
Removed Stream! C:\WINDOWS\VB.INI:fmqnsd
Removed Stream! C:\WINDOWS\VB.INI:hxrmoa
Removed Stream! C:\WINDOWS\VB.INI:ntdwup
Removed Stream! C:\WINDOWS\VBADDIN.INI:adrmip
Removed Stream! C:\WINDOWS\VER.DL:xwgjrj
Removed Stream! C:\WINDOWS\vminst.log:aglgva
Removed Stream! C:\WINDOWS\vminst.log:wapswr
Removed Stream! C:\WINDOWS\vzldx.txt:tdczkz
Removed Stream! C:\WINDOWS\wgttq.log:ovrzyx
Removed Stream! C:\WINDOWS\WIADEBUG.LOG:beuzey
Removed Stream! C:\WINDOWS\WIADEBUG.LOG:nodaap
Removed Stream! C:\WINDOWS\WIADEBUG.LOG:qnohqc
Removed Stream! C:\WINDOWS\WIASERVC.LOG:fomeid
Removed Stream! C:\WINDOWS\WIN.INI:ixjcnw
Removed Stream! C:\WINDOWS\WIN.INI:lrnkey
Removed Stream! C:\WINDOWS\Winamp.ini:ufmeyb
Removed Stream! C:\WINDOWS\winampa.ini:ubwwkh
Removed Stream! C:\WINDOWS\Windows Update.log:bychph
Removed Stream! C:\WINDOWS\WindowsUpdate.log:jaukdk
Removed Stream! C:\WINDOWS\wininit.ini:hevhzn
Removed Stream! C:\WINDOWS\WINNT256.BMP:cbmyfm
Removed Stream! C:\WINDOWS\WINNT256.BMP:mdbxff
Removed Stream! C:\WINDOWS\WINNT256.BMP:qqyyqn
Removed Stream! C:\WINDOWS\wmsetup.log:zeombp
Removed Stream! C:\WINDOWS\wmsetup10.log:ndnvtj
Removed Stream! C:\WINDOWS\wmsetup10.log:owqacb
Removed Stream! C:\WINDOWS\WMSysPrx.prx:kfgzva
Removed Stream! C:\WINDOWS\wtxfx.txt:gxbfem
Removed Stream! C:\WINDOWS\X8409.INI:xxuqjh
Removed Stream! C:\WINDOWS\xdmqi.txt:elcnus
Removed Stream! C:\WINDOWS\xorub.log:pmfyrf
Removed Stream! C:\WINDOWS\xpsp1hfm.log:fegavt
Removed Stream! C:\WINDOWS\xpsp1hfm.log:ptshaq
Removed Stream! C:\WINDOWS\yhfiz.txt:fcpich
Removed Stream! C:\WINDOWS\yhfiz.txt:uqkprn
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:adkzxo
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:ahehxj
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:ahokwe
————————————————
Removed File! : C:\Windows\addfb.exe
Removed File! : C:\Windows\addhy.exe
Removed File! : C:\Windows\addlg.exe
Removed File! : C:\Windows\addlu32.exe
Removed File! : C:\Windows\addpo.exe
Removed File! : C:\Windows\addpz32.exe
Removed File! : C:\Windows\addth32.exe
Removed File! : C:\Windows\addzz32.exe
Removed File! : C:\Windows\apidk.exe
Removed File! : C:\Windows\apign32.exe
Removed File! : C:\Windows\apiit32.exe
Removed File! : C:\Windows\apijo32.exe
Removed File! : C:\Windows\apimg32.exe
Removed File! : C:\Windows\apimj32.exe
Removed File! : C:\Windows\apinq32.exe
Removed File! : C:\Windows\apiok32.exe
Removed File! : C:\Windows\apipj.exe
Removed File! : C:\Windows\apiqs32.exe
Removed File! : C:\Windows\apiqx.exe
Removed File! : C:\Windows\apirr.exe
Removed File! : C:\Windows\apitk.exe
Removed File! : C:\Windows\apiun32.exe
Removed File! : C:\Windows\apiuv32.exe
Removed File! : C:\Windows\apiyr32.exe
Removed File! : C:\Windows\appbu.exe
Removed File! : C:\Windows\appct.exe
Removed File! : C:\Windows\appei32.exe
Removed File! : C:\Windows\appgo32.exe
Removed File! : C:\Windows\appix32.exe
Removed File! : C:\Windows\appni32.exe
Removed File! : C:\Windows\appsk32.exe
Removed File! : C:\Windows\apptj.exe
Removed File! : C:\Windows\appwj.exe
Removed File! : C:\Windows\appzv.exe
Removed File! : C:\Windows\appzv32.exe
Removed File! : C:\Windows\atlby.exe
Removed File! : C:\Windows\atlgn.exe
Removed File! : C:\Windows\atlij.exe
Removed File! : C:\Windows\atlkp.exe
Removed File! : C:\Windows\atlly32.exe
Removed File! : C:\Windows\atlmz32.exe
Removed File! : C:\Windows\atloc32.exe
Removed File! : C:\Windows\atlwe32.exe
Removed File! : C:\Windows\atlwl.exe
Removed File! : C:\Windows\axmwm.dat
Removed File! : C:\Windows\bmedx.dll
Removed File! : C:\Windows\cjtjq.dll
Removed File! : C:\Windows\cmuwg.dll
Removed File! : C:\Windows\crdi32.exe
Removed File! : C:\Windows\crlil.dll
Removed File! : C:\Windows\crmj32.exe
Removed File! : C:\Windows\crmx32.exe
Removed File! : C:\Windows\crpf32.exe
Removed File! : C:\Windows\crse.exe
Removed File! : C:\Windows\crss.exe
Removed File! : C:\Windows\crtu32.exe
Removed File! : C:\Windows\crwm32.exe
Removed File! : C:\Windows\crxc32.exe
Removed File! : C:\Windows\cvawn.dll
Removed File! : C:\Windows\d3cv.exe
Removed File! : C:\Windows\d3fo.exe
Removed File! : C:\Windows\d3rk32.exe
Removed File! : C:\Windows\d3sb32.exe
Removed File! : C:\Windows\d3sr32.exe
Removed File! : C:\Windows\d3sz.exe
Removed File! : C:\Windows\d3tv32.exe
Removed File! : C:\Windows\d3vq32.exe
Removed File! : C:\Windows\dfwbp.dat
Removed File! : C:\Windows\dvezh.dll
Removed File! : C:\Windows\egsjj.dll
Removed File! : C:\Windows\fioyr.dll
Removed File! : C:\Windows\fkbyo.dll
Removed File! : C:\Windows\fthwk.dat
Removed File! : C:\Windows\fzrzw.dat
Removed File! : C:\Windows\gbfez.dll
Removed File! : C:\Windows\gpxvw.dll
Removed File! : C:\Windows\gszds.dll
Removed File! : C:\Windows\henfp.dat
Removed File! : C:\Windows\hvech.dll
Removed File! : C:\Windows\hxdxc.dat
Removed File! : C:\Windows\iebq32.exe
Removed File! : C:\Windows\iebz32.exe
Removed File! : C:\Windows\iedm.exe
Removed File! : C:\Windows\ieef32.exe
Removed File! : C:\Windows\ieeq.exe
Removed File! : C:\Windows\ieir32.exe
Removed File! : C:\Windows\ienj.exe
Removed File! : C:\Windows\iepa32.exe
Removed File! : C:\Windows\ieuy.exe
Removed File! : C:\Windows\iewf32.exe
Removed File! : C:\Windows\iewn32.exe
Removed File! : C:\Windows\ifqbe.dat
Removed File! : C:\Windows\igmuv.dat
Removed File! : C:\Windows\ipdl.exe
Removed File! : C:\Windows\ipee32.exe
Removed File! : C:\Windows\ipgp.exe
Removed File! : C:\Windows\ipii.exe
Removed File! : C:\Windows\ipli.exe
Removed File! : C:\Windows\ipqc32.exe
Removed File! : C:\Windows\ipud32.exe
Removed File! : C:\Windows\jtzde.dat
Removed File! : C:\Windows\kbucj.dll
Removed File! : C:\Windows\kriyj.dll
Removed File! : C:\Windows\lawli.dll
Removed File! : C:\Windows\lkfwl.dat
Removed File! : C:\Windows\lzite.dll
Removed File! : C:\Windows\mfcas.exe
Removed File! : C:\Windows\mfcec.exe
Removed File! : C:\Windows\mfcjf32.exe
Removed File! : C:\Windows\mfcry32.exe
Removed File! : C:\Windows\mfcuk.exe
Removed File! : C:\Windows\mfcwy32.exe
Removed File! : C:\Windows\mfcxr32.exe
Removed File! : C:\Windows\mfcxu.exe
Removed File! : C:\Windows\msbg.exe
Removed File! : C:\Windows\mseg.exe
Removed File! : C:\Windows\mseh.exe
Removed File! : C:\Windows\msjk32.exe
Removed File! : C:\Windows\mskc32.exe
Removed File! : C:\Windows\mslk.exe
Removed File! : C:\Windows\msql.exe
Removed File! : C:\Windows\mswg.exe
Removed File! : C:\Windows\netbd.exe
Removed File! : C:\Windows\netda.exe
Removed File! : C:\Windows\netdz.exe
Removed File! : C:\Windows\netep.exe
Removed File! : C:\Windows\netfl32.exe
Removed File! : C:\Windows\netha32.exe
Removed File! : C:\Windows\netlf.exe
Removed File! : C:\Windows\netmp32.exe
Removed File! : C:\Windows\netut32.exe
Removed File! : C:\Windows\nllts.dat
Removed File! : C:\Windows\nspju.dll
Removed File! : C:\Windows\ntbp.exe
Removed File! : C:\Windows\nteu.exe
Removed File! : C:\Windows\ntgj32.exe
Removed File! : C:\Windows\nthx32.exe
Removed File! : C:\Windows\ntir.exe
Removed File! : C:\Windows\ntoz32.exe
Removed File! : C:\Windows\ntuk32.exe
Removed File! : C:\Windows\ntwj.exe
Removed File! : C:\Windows\ohowm.dat
Removed File! : C:\Windows\pbyob.dat
Removed File! : C:\Windows\pymqu.dll
Removed File! : C:\Windows\qaosm.dat
Removed File! : C:\Windows\qgodn.dll
Removed File! : C:\Windows\qnsrx.dll
Removed File! : C:\Windows\qpjga.dll
Removed File! : C:\Windows\rgrlf.dat
Removed File! : C:\Windows\rooxv.dat
Removed File! : C:\Windows\rzjtg.dat
Removed File! : C:\Windows\sdkae32.exe
Removed File! : C:\Windows\sdkai32.exe
Removed File! : C:\Windows\sdkcn.exe
Removed File! : C:\Windows\sdkfc32.exe
Removed File! : C:\Windows\sdkiy32.exe
Removed File! : C:\Windows\sdklh32.exe
Removed File! : C:\Windows\sdkwl.exe
Removed File! : C:\Windows\sysag.exe
Removed File! : C:\Windows\sysfz.exe
Removed File! : C:\Windows\syslo32.exe
Removed File! : C:\Windows\sysmj32.exe
Removed File! : C:\Windows\sysmy32.exe
Removed File! : C:\Windows\syspx.exe
Removed File! : C:\Windows\sysrt32.exe
Removed File! : C:\Windows\syszv.exe
Removed File! : C:\Windows\takyq.dll
Removed File! : C:\Windows\tazvu.dat
Removed File! : C:\Windows\ttkuc.dat
Removed File! : C:\Windows\upslk.dat
Removed File! : C:\Windows\winby.exe
Removed File! : C:\Windows\wingi.exe
Removed File! : C:\Windows\winnn.exe
Removed File! : C:\Windows\winos.exe
Removed File! : C:\Windows\winuh.exe
Removed File! : C:\Windows\winyd.exe
Removed File! : C:\Windows\winyv.exe
Removed File! : C:\Windows\winzp.exe
Removed File! : C:\Windows\wqbgo.dll
Removed File! : C:\Windows\xihqh.dat
Removed File! : C:\Windows\ycnat.dat
Removed File! : C:\Windows\yrydu.dll
Removed File! : C:\Windows\zlywt.dll
Removed File! : C:\Windows\System32\addbm32.exe
Removed File! : C:\Windows\System32\addid32.exe
Removed File! : C:\Windows\System32\addil.exe
Removed File! : C:\Windows\System32\addjw.exe
Removed File! : C:\Windows\System32\addqp32.exe
Removed File! : C:\Windows\System32\addqx.exe
Removed File! : C:\Windows\System32\addum32.exe
Removed File! : C:\Windows\System32\aeptb.dat
Removed File! : C:\Windows\System32\apibu32.exe
Removed File! : C:\Windows\System32\apifg32.exe
Removed File! : C:\Windows\System32\apiik32.exe
Removed File! : C:\Windows\System32\apimu32.exe
Removed File! : C:\Windows\System32\apioy.exe
Removed File! : C:\Windows\System32\apipe.exe
Removed File! : C:\Windows\System32\apiwj.exe
Removed File! : C:\Windows\System32\apiwj32.exe
Removed File! : C:\Windows\System32\apize32.exe
Removed File! : C:\Windows\System32\appaw.exe
Removed File! : C:\Windows\System32\appbw.exe
Removed File! : C:\Windows\System32\appcc32.exe
Removed File! : C:\Windows\System32\appfp.exe
Removed File! : C:\Windows\System32\appiy.exe
Removed File! : C:\Windows\System32\appjx32.exe
Removed File! : C:\Windows\System32\appol32.exe
Removed File! : C:\Windows\System32\appvg.exe
Removed File! : C:\Windows\System32\appzb.exe
Removed File! : C:\Windows\System32\atldz.exe
Removed File! : C:\Windows\System32\atlhr32.exe
Removed File! : C:\Windows\System32\atlhx.exe
Removed File! : C:\Windows\System32\crfg32.exe
Removed File! : C:\Windows\System32\crlh.exe
Removed File! : C:\Windows\System32\crlp.exe
Removed File! : C:\Windows\System32\crrg32.exe
Removed File! : C:\Windows\System32\crvo32.exe
Removed File! : C:\Windows\System32\crwc.exe
Removed File! : C:\Windows\System32\d3cv.exe
Removed File! : C:\Windows\System32\d3gk32.exe
Removed File! : C:\Windows\System32\d3hg.exe
Removed File! : C:\Windows\System32\d3ow.exe
Removed File! : C:\Windows\System32\d3pj32.exe
Removed File! : C:\Windows\System32\d3ta32.exe
Removed File! : C:\Windows\System32\d3uf32.exe
Removed File! : C:\Windows\System32\d3un.exe
Removed File! : C:\Windows\System32\d3zm32.exe
Removed File! : C:\Windows\System32\dazdo.dat
Removed File! : C:\Windows\System32\dvgsd.dat
Removed File! : C:\Windows\System32\eiijk.dat
Removed File! : C:\Windows\System32\ekspr.dat
Removed File! : C:\Windows\System32\glnfj.dat
Removed File! : C:\Windows\System32\hdwid.dat
Removed File! : C:\Windows\System32\hemuh.dll
Removed File! : C:\Windows\System32\ibrrm.dll
Removed File! : C:\Windows\System32\ieas32.exe
Removed File! : C:\Windows\System32\ieja32.exe
Removed File! : C:\Windows\System32\iepy.exe
Removed File! : C:\Windows\System32\ierc.exe
Removed File! : C:\Windows\System32\iete32.exe
Removed File! : C:\Windows\System32\ipeg32.exe
Removed File! : C:\Windows\System32\ipiz32.exe
Removed File! : C:\Windows\System32\ipms.exe
Removed File! : C:\Windows\System32\ipoh32.exe
Removed File! : C:\Windows\System32\ipzi.exe
Removed File! : C:\Windows\System32\ishdz.dat
Removed File! : C:\Windows\System32\jafbv.dat
Removed File! : C:\Windows\System32\javadl32.exe
Removed File! : C:\Windows\System32\javahe.exe
Removed File! : C:\Windows\System32\javaih32.exe
Removed File! : C:\Windows\System32\jqire.dll
Removed File! : C:\Windows\System32\lnacp.dat
Removed File! : C:\Windows\System32\mfcau32.exe
Removed File! : C:\Windows\System32\mfcex.exe
Removed File! : C:\Windows\System32\mfckd32.exe
Removed File! : C:\Windows\System32\mfclo.exe
Removed File! : C:\Windows\System32\mfcnh.exe
Removed File! : C:\Windows\System32\mfcpj.exe
Removed File! : C:\Windows\System32\mfcse32.exe
Removed File! : C:\Windows\System32\mfcwh.exe
Removed File! : C:\Windows\System32\mfcxn.exe
Removed File! : C:\Windows\System32\mfczw.exe
Removed File! : C:\Windows\System32\mfxka.dat
Removed File! : C:\Windows\System32\mmngx.dat
Removed File! : C:\Windows\System32\mpmpq.dll
Removed File! : C:\Windows\System32\msjj.exe
Removed File! : C:\Windows\System32\msnd32.exe
Removed File! : C:\Windows\System32\mspx32.exe
Removed File! : C:\Windows\System32\msqp.exe
Removed File! : C:\Windows\System32\mssj.exe
Removed File! : C:\Windows\System32\msuj32.exe
Removed File! : C:\Windows\System32\msxc.exe
Removed File! : C:\Windows\System32\msxn.exe
Removed File! : C:\Windows\System32\mszm32.exe
Removed File! : C:\Windows\System32\netcf.exe
Removed File! : C:\Windows\System32\netlc32.exe
Removed File! : C:\Windows\System32\netrd.exe
Removed File! : C:\Windows\System32\netsb32.exe
Removed File! : C:\Windows\System32\netsd32.exe
Removed File! : C:\Windows\System32\netui.exe
Removed File! : C:\Windows\System32\ntdl32.exe
Removed File! : C:\Windows\System32\nthh32.exe
Removed File! : C:\Windows\System32\nthst32.dll
Removed File! : C:\Windows\System32\ntkm.exe
Removed File! : C:\Windows\System32\ntql32.exe
Removed File! : C:\Windows\System32\nuarm.dat
Removed File! : C:\Windows\System32\ouubo.dll
Removed File! : C:\Windows\System32\pvigv.dat
Removed File! : C:\Windows\System32\pxxcx.dat
Removed File! : C:\Windows\System32\qiydi.dll
Removed File! : C:\Windows\System32\qlqmq.dll
Removed File! : C:\Windows\System32\qpjzv.dat
Removed File! : C:\Windows\System32\rapfw.dll
Removed File! : C:\Windows\System32\riutn.dll
Removed File! : C:\Windows\System32\rjcaz.dll
Removed File! : C:\Windows\System32\sdkar.exe
Removed File! : C:\Windows\System32\sdkei32.exe
Removed File! : C:\Windows\System32\sdkic32.exe
Removed File! : C:\Windows\System32\sdktq.exe
Removed File! : C:\Windows\System32\sdkyi32.exe
Removed File! : C:\Windows\System32\sravd.dll
Removed File! : C:\Windows\System32\svrni.dat
Removed File! : C:\Windows\System32\sysjr32.exe
Removed File! : C:\Windows\System32\sysoc32.exe
Removed File! : C:\Windows\System32\sysrc.exe
Removed File! : C:\Windows\System32\syssf32.exe
Removed File! : C:\Windows\System32\sysuy32.exe
Removed File! : C:\Windows\System32\sysxa.exe
Removed File! : C:\Windows\System32\tnaks.dat
Removed File! : C:\Windows\System32\tzqgz.dat
Removed File! : C:\Windows\System32\ukuyo.dat
Removed File! : C:\Windows\System32\wgjrj.dll
Removed File! : C:\Windows\System32\wingx32.exe
Removed File! : C:\Windows\System32\winkp32.exe
Removed File! : C:\Windows\System32\winni32.exe
Removed File! : C:\Windows\System32\winoz.exe
Removed File! : C:\Windows\System32\wintb32.exe
Removed File! : C:\Windows\System32\wints.exe
Removed File! : C:\Windows\System32\winvp.exe
Removed File! : C:\Windows\System32\winwn32.exe
Removed File! : C:\Windows\System32\wjkpp.dll
Removed File! : C:\Windows\System32\wtako.dat
Removed File! : C:\Windows\System32\xlrlp.dat
Removed File! : C:\Windows\System32\xwufd.dat
Removed File! : C:\Windows\System32\ylban.dat
Removed File! : C:\Windows\System32\yrtex.dll
Removed File! : C:\Windows\System32\yuehr.dat
Removed File! : C:\Windows\System32\yxgai.dat
Removed File! : C:\Windows\System32\zgdfy.dat
Removed File! : C:\Windows\System32\zlhpd.dll
Removed File! : C:\Windows\System32\zvygn.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 9:40:13 PM




Logfile of HijackThis v1.99.1
Scan saved at 7:26:42 PM, on 6/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\TJ Scheidel\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\TJ Scheidel\Application Data\Mozilla\Profiles\default\i1rhdl2p.slt\prefs.js)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
WOW, you had a mess there.


I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R3 - Default URLSearchHook is missing


THese aren't bad but are resource hogs and not needed at startup.

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office10\OSA.EXE

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Office10\EXCEL.EXE/3000


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Hi LDTate,

Here is the most current HJT log. I had a question about the AboutBuster log. Were all of those deleted files replicated from the original infection?



Logfile of HijackThis v1.99.1
Scan saved at 8:46:59 PM, on 6/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Winamp3\winampa.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\TJ Scheidel\Desktop\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\TJ Scheidel\Application Data\Mozilla\Profiles\default\i1rhdl2p.slt\prefs.js)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\billmind.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

I had a question about the AboutBuster log. Were all of those deleted files replicated from the original infection?

I would say yes, they were hidding in there.



Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Great job :thumbup:

You're more then welcome.
Glad we were able to help

Peace be with you :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI