This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Instant access and aurora

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Any help would be appreciated…………here is my log.


Logfile of HijackThis v1.99.1
Scan saved at 9:15:40 PM, on 6/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\tywlcdm.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\SYSTEM32\qttask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BestPopUpKiller\BestPopupKiller.exe
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLHOS~1.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLServiceHost.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Program Files\SpyKiller\SpyKiller.exe
C:\Documents and Settings\Stacey Faria\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104810257\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [cbnfab] c:\windows\system32\tywlcdm.exe r
O4 - HKLM\..\RunOnce: [0000 - C:\Documents and Settings\Stacey Faria\Start Menu\Programs\HP DeskJet 610C Series v11.2] C:\WINDOWS\command.com /c rmdir "C:\Documents and Settings\Stacey Faria\Start Menu\Programs\HP DeskJet 610C Series v11.2"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [nddenb32] C:\WINDOWS\System32\nddenb32.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O16 - DPF: Win32 Classes -
O16 - DPF: {1CD49DC9-FD88-41FA-B892-47E037267D45} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1059_XP.cab
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1057_XP.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {BFC9677B-8006-4336-9D49-2C797AEFCB9E} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1058_XP.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


thanks
Hello Half10 and welcome to TomCoyote. :wavey:

You have SpyKiller on your computer. This program is on the "rogue/suspect list" because it uses false positives as goad to purchase. You can read about it here. This is optional but I strongly recommend checking this entry than removing this program with Add/Remove Programs.

You have BestPopUpKiller on your computer. This program is of dubious repute from Swanksoft.com. I recommend removing it with Add/Remove Programs. You can download Google Toolbar which is a great program for blocking unwanted pop-ups.

Here are two highly recommended free malware scanners:

Spybot Search and Destroy 1.4
AdAware SE v1.06
Set-up Instructions for Spybot S&D; and Adaware SE

If you have them already, check to make sure that they are the newest version.


Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please download Nailfix from here:
http://www.noidea.us/easyfile/file.php?dow…050515010747824
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Next please run HijackThis, click Scan, and check the following (if still present):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKLM\..\Run: [cbnfab] c:\windows\system32\tywlcdm.exe r
O4 - HKCU\..\Run: [nddenb32] C:\WINDOWS\System32\nddenb32.exe

O16 - DPF: Win32 Classes -
O16 - DPF: {1CD49DC9-FD88-41FA-B892-47E037267D45} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1059_XP.cab
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1057_XP.cab
O16 - DPF: {BFC9677B-8006-4336-9D49-2C797AEFCB9E} - http://akamai.downloadv3.com/binaries/EGDA…ESS_1058_XP.cab

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Close all open windows except for HijackThis and click Fix Checked.


While still in Safe Mode, please delete the following files:

c:\windows\system32\tywlcdm.exe
C:\WINDOWS\System32\nddenb32.exe

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Here are the logs from today after following your direction above.


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 6:22:15 PM, 6/13/2005
+ Report-Checksum: F7249DEE

+ Date of database: 6/14/2005
+ Version of scan engine: v3.0

+ Duration: 57 min
+ Scanned Files: 45918
+ Speed: 13.27 Files/Second
+ Infected files: 102
+ Removed files: 102
+ Files put in quarantine: 102
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\WINDOWS\SYSTEM32\EGDACCESS_1058.dll -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\SYSTEM32\EGDACCESS_1059.dll -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\WINDOWS\lhtvknhndii.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Local Settings\Temp\p2psetup.exe -> Spyware.P2PNetworking -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Local Settings\Temporary Internet Files\Content.IE5\0HU3OLA3\thnall1m[1].exe -> Spyware.BetterInternet.f -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Cookies\stacey faria@atdmt[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Cookies\stacey faria@tradedoubler[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Cookies\stacey faria@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Cookies\stacey [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Stacey Faria\Cookies\stacey faria@advertising[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP96\A0029901.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP97\A0030901.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP99\A0031902.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP99\A0031934.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP99\A0031956.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP100\A0031986.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP100\A0032000.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP100\A0032014.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP101\A0033014.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP101\A0033026.EXE -> TrojanDownloader.Agent.ae -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033047.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033048.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033049.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033050.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033053.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033054.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033060.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033061.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033075.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033077.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033083.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033086.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033088.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033089.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033090.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033091.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033099.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033100.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033105.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033110.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033112.dll -> Spyware.ImiBar.d -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033113.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033114.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033115.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033117.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033123.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033124.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033126.EXE -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP102\A0033127.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033202.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033209.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033216.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033218.exe -> Trojan.Nail -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033219.exe -> Trojan.Stervis.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033220.dll -> Trojan.Agent.db -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033235.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033237.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033250.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033251.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP103\A0033252.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP79\A0023806.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP79\A0023827.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP79\A0023854.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP79\A0023877.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP79\A0023909.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0023941.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024040.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024058.exe -> Trojan.Imiserv.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024078.exe -> Spyware.AltnetBDE -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024079.dll -> Spyware.Altnet.b -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024086.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP80\A0024102.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP83\A0024166.dll -> Spyware.NaviPromo.c -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027502.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027523.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027541.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027564.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027585.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027613.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027637.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP92\A0027664.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP93\A0027686.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP93\A0027710.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP94\A0028707.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP94\A0029707.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP94\A0029734.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029795.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029815.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029827.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029829.dll -> Spyware.P2PNetworking -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029830.exe -> Spyware.P2PNetworking -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029839.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029852.dll -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{44DB0449-2767-4688-AFDD-25980D2055FF}\RP95\A0029870.dll -> Dialer.Generic -> Cleaned with backup
C:\Recycled\Dc39.exe -> Trojan.Nail -> Cleaned with backup
C:\Recycled\Dc46.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Recycled\Dc50.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Recycled\Dc56.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Recycled\Dc100.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Recycled\Dc121.txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Recycled\Dc137.txt -> Spyware.Tracking-Cookie -> Cleaned with backup


Logfile of HijackThis v1.99.1
Scan saved at 6:36:12 PM, on 6/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\SYSTEM32\qttask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLHOS~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Stacey Faria\Desktop\HijackThis.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLServiceHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104810257\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [nddenb32] C:\WINDOWS\System32\nddenb32.exe
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Please download the List Installed Programs script from here. Unzip it and double click InstalledPrograms.vbs to run it. It will create a notepad file. Copy/Paste that information as a reply to this thread.
Your antivirus program will need to allow scripts to be able to use this file.
Here it is………..I notice some of these items aren't even on the machine any longer. INSTALLED SOFTWARE (59) - HPPAV - 6/13/2005 8:37:06 PM Adaptec UDF Reader Adobe Acrobat 4.0 Ver: 4.0 Adobe Acrobat Reader 3.01 Adobe Download Manager 1.2 (Remove Only) Adobe PhotoDeluxe 2.0 Adobe Reader 6.0.1 Ver: 006.000.001 Installed: 5/15/2004 Ahead InCD Ahead InCD EasyWrite Reader Ahead NeroMediaPlayer America Online (Choose which version to remove) AOL Coach Version 1.0(Build:20030807.3) AOL Connectivity Services BackWeb BroadJump Client Foundation Centipede CompuServe 2000 Creative Recorder ewido security suite Family Health HijackThis 1.99.1 Ver: 1.99.1 HP Internet Center HP Printer Scanner Copier Enhancer InterVideo WinDVD ItsDeductible Express Ver: 1.00.0000 Installed: 4/14/2005 Java 2 Runtime Environment Standard Edition v1.3.1_02 Kai's Power Goo SE Learn2 Player (Uninstall Only) Macromedia Flash Player Ver: 7.0.19.0 Installed: 4/9/2005 Microsoft Encarta 97 Encyclopedia Microsoft Office XP Professional with FrontPage Ver: 10.0.2627.0 Installed: 8/21/2004 Microsoft Works 2000 Ver: 1.0.0.0000 Installed: 6/30/2000 MusicMatch Jukebox My Yahoo! for HP Nero Express Ver: 5.5.9 Installed: 8/20/2004 NetWaiting Ver: 2.5.5 One-touch Multimedia Keyboard Online Health Manager PhotoPrinter 2.0 Quicken Basic 2000 QuickLink III QuickTime QuickTime for Windows (32-bit) RealPlayer Basic SafeCast Shared Components SBC Self Support Tool SBC Yahoo! Applications ScanSpyware v3.8.0.4 Shockwave Flash The ABI Network- A Division of Direct Revenue TurboTax Deluxe 2002 TurboTax Deluxe 2004 V92 PCI Voice Faxmodem Viewpoint Media Player wbnjemv WebFldrs XP Ver: 9.50.5318 Installed: 8/21/2004 WexTech AnswerWorks Ver: 1.00.000 Windows XP Hotfix (SP1) [See Q321856 for more information] WinRAR archiver Yahoo! Install Manager
Download "Registry Search Tool" (RegSrch.vbs) from here.

Start it and paste in wbnjemv, wait, hit ok. Then when wordpad opens, copy that back here please.
Here it is REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "wbnjemv" 6/13/2005 9:39:56 PM ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "wbnjemv"="c:\\windows\\system32\\wbnjemv.exe -start" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wbnjemv] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wbnjemv] "UninstallString"="c:\\windows\\system32\\wbnjemv.exe -uninstall" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wbnjemv] "DisplayName"="wbnjemv"
Step 1
Download and install Reglite. We'll use this program later in the fix.

Step 2
Download Pocket Killbox from here: http://www.downloads.subratam.org/KillBox.zip

Unzip the files to a folder, then open and double-click on Killbox.exe to run it. In the "Paste Full Path of File to Delete" box, copy and paste the following:

C:\WINDOWS\System32\wbnjemv.exe

Check the option for "Delete on Reboot". Click the button with the red circle with a white X in it. Click 'yes'. When asked to reboot choose 'no'. Copy the next filepath and paste it in the box, and repeat the above steps.

C:\WINDOWS\Downlo~1\EGDACCESS.inf
C:\WINDOWS\system32\EGDACCESS_1057.dll


When all of the filepaths are done, allow it to reboot.
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.


While the computer is booting up, tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter'.


Step 3
Open RegLite and copy/paste the following string in the address window then click go.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


Right click the "wbnjemv"="c:\\windows\\system32\\wbnjemv.exe -start" value in the right pane and delete.



Then copy/paste the following and click go.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wbnjemv

Right click the wbnjemv key in the left pane and delete.

Exit Reglite.


Step 4
Open C:\Windows\Prefetch, select all and delete. (This will cause your computer to boot-up slower for the first few boots. Please do not be alarmed.)

Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\Every username\Local Settings\Temp\
Also delete your Temporary Internet Files (Start > Control Panel > Internet Options > Delete Files), be sure to also select delete all offline content.
Empty the Recycle Bin.


Step 5
Reboot normally and run at least two of the following online virus scans making sure to reboot in between each one. Allow them to fix anything they find.
You need to use Internet Explorer or Netscape browsers.
Bitdefender
Pandasoftware
Trend Micro << Click Auto Clean
Symantec Security Check << click scan for viruses
RAV Online Virus Scanner << Enter your e-mail address and click on To continue without subscribing
McAfee

Write down anything that can not be fixed.


Step 6
Scan with HijackThis and post the new log as a reply to this thread. Include anything that can not be fixed by the online scans. Let us know if the popups stop.
I have done all of the things you have instructed and don't seem to be having anymore popups……………while running the online scans they found files and either disinfected or deleted them…….now even after rebooting between running them they are not finding any files…..I really appreciate all the help………here is the latest hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 10:03:46 PM, on 6/14/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\SYSTEM32\qttask.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110481~1\EE\AOLServiceHost.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\Documents and Settings\Stacey Faria\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104810257\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [nddenb32] C:\WINDOWS\System32\nddenb32.exe
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


do I leave all of these programs that you had me install and run on teh machine or should I remove them? also what is teh best way to prevent this from happening again?
thanks
Your new log appears clean. :)

List Installed Programs, Registry Search Tool, and Reglite can all be removed.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.


I notice that you have no protection on your computer in the form of Antivirus, Firewall, or Realtime Registry protection. The following list of programs will help to prevent the problems from re-occuring.


MOST IMPORTANT: You Need to Update Windows and IE to get all the Latest Security Patches to protect your computer from the malware that is on the internet.
I recommend going to the following link and update to SP2. This adds more security and extra features including a pop-up blocker for Internet Explorer.
Microsoft Windows and Internet Explorer Updates

Here is a great link that explains the procedure for updating to SP2 with less complications (scroll down to the second post).


I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
SpywareGuard - Real-time protection from spyware installation attempts
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.

AVG AntiVirus - Free antivirus program if you currently are not using one.
ZoneAlarm - Free firewall program if you currently are not using one.

Here are three very good and free malware scanners:

Spybot Search and Destroy 1.4
AdAware SE v1.06
Set-up Instructions for Spybot S&D; and Adaware SE
a² Free Trojan Remover

If you have them already, check to make sure that they are the newest version.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
Your welcome. Glad the computer is working better.

As this topic has been resolved, the thread will be closed.

If you need this topic reopened, please request this by sending an email to us at the following link:
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI