This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

180search assistant, media access, etc

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi i'm new here and thanks for your help in advance =). actually this post is just to seek professional clarification that my comp is clean now. my comp had previously been infected with 180search assistant, media access, internet optimizer and the likes. and had been unable to open task manager and run regedit. was also not allowed access to sites like symantec mcafee amazon etc.

but have compulsively been scanning with spydoctor xoftspy ad-aware and ewido and editting my hosts file and now it seems that my comp is clean. but i just wanna be sure so here's my hijackthis log please revert back to me i'll really appreciate it!

Logfile of HijackThis v1.99.1
Scan saved at 5:23:45 PM, on 17-Jun-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\ViCki\Desktop\Stupid Scums\HijackThis.exe

O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\PROGRA~1\DAP\dapbho.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [System Services] khujfep.exe
O4 - HKCU\..\RunServices: [System Services] khujfep.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/M…0,2/mcmysec.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…514/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
We are sorry for the delay in replying to you. If you still require help, please post a fresh Hijackthis log as a reply to this thread. I'll receive an e-mail notification of your reply and will respond as soon as possible. Thank you for your patience.
hi this is my new hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 8:31:43 PM, on 21-Jul-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\DAP\DAP.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ViCki\Desktop\Stupid Scums\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [System Services] khujfep.exe
O4 - HKCU\..\RunServices: [System Services] khujfep.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/M…0,2/mcmysec.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…514/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE


the 180 solutions adware still appears once a while when i run spybot, adaware se and xoftspy. hope you would help look at my log and see if my comp is clean.

and can i ask if a virus/adware can attach itself to a .avi file cos i downloaded a video clip lately and i can't run it or even delete it. i downloaded a ffdshow, xp codec pack and also videofixer to try to fix it to no avail, so im suspecting that it might be some virus/adware. hope you can advise on this too.

much thanks! will appreciate your speedy reply!
Hello psyche and welcome to TomCoyote. :wavey:

You have a worm on your computer caused by the lack of Windows Updates and security programs on your computer.

Step 1
Open HijackThis, run a scan, then check the following:

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKCU\..\Run: [System Services] khujfep.exe
O4 - HKCU\..\RunServices: [System Services] khujfep.exe


With all other programs and browsers closed, click fix checked.


Step 2
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 3
Please delete the following files/folders:

You'll need to search for these files with Explorer to delete. They may be in C:\WINDOWS\system32\ or C:\WINDOWS\
(Start > Search > All files and folders > More advanced options place a check in the first three boxes)

khujfep.exe

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 4
Run at least two of the following online virus scans making sure to reboot in between each one. Allow them to fix anything they find.You need to use Internet Explorer or Netscape browsers.
Bitdefender
Pandasoftware
Trend Micro << Click Auto Clean
Symantec Security Check << click scan for viruses
RAV Online Virus Scanner << Enter your e-mail address and click on To continue without subscribing
McAfee
Write down anything that can not be fixed. Include the file name and the path to the file.


Step 5
I see no signs of a Firewall or Antivirus program on your computer. I recommend downloading and installing the following free programs:
ZoneAlarm Firewall
AVG7 Antivirus.

Be sure to check for updates after installation.


Step 6
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread. Include anything that can not be fixed by the online scans.
Please let us know of any complications you had and how the computer is behaving.
hi alsocom thanks for your help :rofl:
here's my new hijackthis log and some problems encountered (forgive me if i mention unimportant stuff cos i'm quite an idiot at this):


Logfile of HijackThis v1.99.1
Scan saved at 3:19:49 PM, on 23-Jul-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\DAP\DAP.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\ViCki\Desktop\Stupid Scums\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O8 - Extra context menu item: &Download; with &DAP; - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all; with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…/ICSScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/M…0,2/mcmysec.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…514/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


1) at step 3 i couldn't find khujfep.exe both in typical and safe mode. so i assume it's gone.

2) couldn't assess bitdefender's page, couldn't use pandasoftware, is there anything wrong? used trend micro and symantac security check, both yielded no problems.

3) zonealarm firewall returned with these registy keys n cookie after a pre-download scan, which i deleted (i suppose im expected to delete?):
HKEY_CURRENT_USER\Software\iMesh\
HKEY_LOCAL_MACHINE\SOFTWARE\iMesh\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RelatedLinks\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{01E04581-4EEE-11D0-BFE9-00AA005B4383}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Cookie:[removed]/

4) avg7 antivirus found these 2 viruses which cannot be healed so i didn't do anything about them:
Result: Virus identified Java/OpenStream
Status: Infected, Embedded object

C:\Documents and Settings\Vicki\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-39154b06.zip:\javainstaller\InstallerApplet.class

Result: Virus identified Java/OpenStream
Status: Infected, Archive

C:\Documents and Settings\Vicki\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-39154b06.zip

5) finally, i still can't seem to open or delete the video clip i downloaded (mentioned in previous post), may u advise? and what can i do to remove AC3 Filter in my control panel window?

thank you! B)
hey sorry you can ignore my problem with bitdefender i guess i followed the wrong link from your msg i could now access it through its main homepage =)) be waiting for your analysis. p/s: there's no virus with my video clip after i scanned it with avg3 antivirus but i just couldn't do anything with it, can't even right-click properties - basically the file just hangs when i try to click on it. is it a corrupted file and if i can't play it how can i remove it?
I see that they have changed the location of the BitDefender online scan. Thank you for letting me know.

New log appears clean of malware. :thumbup:


The items that AVG can not heal are in your Java Cache. Here is how to clear these out :

Go to Start < Control Panel < Java. This will open the Java Control Panel.
On the General tab click Delete Files.. Make sure all three boxes are checked and click OK.
Then OK on the Java Control Panel to exit.



You are way behind on your Windows and Internet Explorer updates. I recommend going to the following link and update to SP2. This adds more security and extra features including a pop-up blocker for Internet Explorer.
Microsoft Windows and Internet Explorer Updates

Here is a great link that explains the procedure for updating to SP2 with less complications (scroll down to the second post).


What program did you use to download the video from? If it was a file-sharing program, you will need to delete it from within that program.


If you still can not remove it, let me know the full path to the file and the file name such as
C:\Documents and Settings\(username)\My Documents\name of file.avi
i'm so sorry for posting multiple messages :o i just did a bitdefender online scan this is the result…which i don't quite understand…are the viruses removed cos only a handful of them said 'deleted'.


C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Suspected of: JS.Trojan.Downloader.IstBar.A

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Disinfection failed

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Deleted

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[2].php
Suspected of: JS.Trojan.Downloader.IstBar.A

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[2].php
Disinfection failed

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[2].php
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025943.exe
Infected with: Trojan.WinAd.18436

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025943.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025943.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025948.dll
Infected with: Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025948.dll
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025948.dll
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025949.exe
Infected with: Trojan.Delautoexec.51272.A

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025949.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025949.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025956.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025956.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025956.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025960.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025960.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0025960.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026113.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026113.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026113.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026134.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026134.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026134.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026136.dll
Infected with: Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026136.dll
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026136.dll
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026137.exe
Infected with: Trojan.Delautoexec.51272.A

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026137.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026137.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026138.exe
Infected with: Trojan.WinAd.18436

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026138.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026138.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026155.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026155.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026155.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026164.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026164.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026164.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026166.dll
Infected with: Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026166.dll
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026166.dll
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026180.exe
Infected with: Trojan.Delautoexec.51272.A

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026180.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026180.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026181.exe
Infected with: Trojan.WinAd.18436

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026181.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026181.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026193.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026193.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026193.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026203.dll
Infected with: Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026203.dll
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026203.dll
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026204.exe
Infected with: Trojan.Delautoexec.51272.A

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026204.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026204.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026205.exe
Infected with: Trojan.WinAd.18436

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026205.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026205.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026208.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026208.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026208.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026219.dll
Infected with: Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026219.dll
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026219.dll
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026225.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026225.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026225.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026227.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026227.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026227.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026335.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026335.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026335.exe
Deleted

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP113\A0026833.exe
Infected with: Dropped:Trojan.Winad.L.DLL

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP113\A0026833.exe
Disinfection failed

C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP113\A0026833.exe
Deleted



concurrently this is my avg7 antivirus detection. i put them in the virus vault as i'm not sure how to delete them:

Virus identified I-Worm/Mytob.HM
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026132.exe

Virus identified I-Worm/Mytob.HM
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026191.exe

Trojan horse Downloader.Dyfica.3.AI
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026210.exe

Trojan horse IRC/BackDoor.SdBot.BLK
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026334.com

Virus identified I-Worm/Mytob.HM
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026423.exe

Trojan horse IRC/BackDoor.SdBot.BLK
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP111\A0026424.exe

Trojan horse IRC/BackDoor.SdBot.BLK
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP113\A0026834.com

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Suspected of: JS.Trojan.Downloader.IstBar.A

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Disinfection failed

C:\Documents and Settings\ViCki\Local Settings\Temporary Internet Files\Content.IE5\7Y7HOGS9\prompt[1].php
Deleted

What this shows is the same entry three times.
First –> What the item is
Second –> The item was unable to be fixed.
Third –> Item was deleted since it was unrepairable.

concurrently this is my avg7 antivirus detection. i put them in the virus vault as i'm not sure how to delete them:

Virus identified I-Worm/Mytob.HM
C:\System Volume Information\_restore{0DCCC01C-1B21-4F6C-98F1-7D5333CD10F7}\RP110\A0026132.exe

These items are all in your System Restore which will be cleaned out once we are sure your computer is clean.
i've cleared the Java Cache and deleted my .avi file (yeah it was easy, silly me).
you mentioned that the items shown by my avg scan will be cleared from the system restore, how? here's my new log file and i hope it's clean and we could proceed from here:


Logfile of HijackThis v1.99.1
Scan saved at 7:45:51 PM, on 23-Jul-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\ViCki\Desktop\Stupid Scums\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…/ICSScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/M…0,2/mcmysec.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…514/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
oh. and does having AC3 Filter in my control panel affects anything? cos i don't remember downloading it (but it could have come from the xp codec pack that i downloaded and uninstalled already). any way to remove it too? it's only on the control panel menu and not under the list populated by add/remove programs. thanks for being so patient. good day! :wavey:
You can remove these with HijackThis also:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm



Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.



You have started downloading the updates for Windows and Internet Explorer. Be sure to get them all as this is the most important thing you can do to keep your computer secure. Keep checking back for updates until it shows no more critical updates are available.

Once this is all done, post a fresh HijackThis log and if the computer is still working well, I'll give you some more recommendations to better secure the computer.
i guess it's well already thank you so much :)

Logfile of HijackThis v1.99.1
Scan saved at 5:13:03 PM, on 24-Jul-05
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_SICN03.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ViCki\Desktop\Stupid Scums\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.mozilla.org/firefox?client=fi…:en-US:official
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.can.com.sg/mwf/mgaxctrl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…/ICSScanner.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/M…0,2/mcmysec.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…514/mcfscan.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Your new log appears clean. :)

I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
ie-spyad - Puts over 12,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI