This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack Log cfgmgr52.dll

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've tried adaware and norton anti-virus.

Whenever I boot the computer, I receive a message saying that cfgmgr52.dll is missing.

Also, I have endless popups. Mostly from:
Ebates Moneymaker, Adintelligence Apropos Toolbar, and Peopleonpage.

HELP PLEASE!

Hijack Log:

Logfile of HijackThis v1.99.1
Scan saved at 6:23:34 PM, on 6/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\qcawan.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\powbde40.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
O2 - BHO: (no name) - {15EE3E64-7B09-15A8-9378-5024D890E05A} - C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [rllzpe] c:\windows\system32\rllzpe.exe
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitebof32.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\kljlkm.exe reg_run
O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - HKLM\..\Run: [sac] c:\program files\180searchassistant\sac.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [37oj39R] qcawan.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Iw7tRVd6T] powbde40.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114480066078
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {D02E8435-0594-4424-B127-E096600317B7} (MailEdit Control) - http://mail.korea.com/bin/KorMail55.Cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello pchhelp57 and welcome to TomCoyote. :wavey:

Download this tool : LQfix.zip
  • Unzip it to your Desktop.
  • Don't use it yet!
IMPORTANT! Reboot the computer into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').

Doubleclick LQfix.bat that you saved on your desktop before.A dos window will open and close again, that is normal.
Reboot the computer normally.

You stated that you ran a scan with Ad-Aware but please run another according to the following set-up instructions. If you have the latest version, ignore the part about downloading it. Also, run a scan with SpyBot S&D.

Please download and install Ad-Aware SE and Spybot S&D according to the following instructions. If you already have these programs, please make sure they are the latest version (Ad-Aware SE Personal 1.06, Spybot Search and Destroy 1.4), than run scans as described below.

Scanning With Spybot S&D;:
  • Downloaded and Install Spybot S&D; accepting the Default Settings.
  • In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.
  • Close ALL windows except Spybot S&D.
  • Click the button to ‘Search for Updates’ then download and install the Updates.
  • Next click the button ‘Check for Problems’
  • When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
  • Do not enable Tea Timer until the log is clean as it will prevent the fix from working.
Scanning With Ad-Aware SE:
  • Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window.
    • In the ‘General’ window make sure the following are selected in green:
      • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to udate outdated definitions - set the number of days
    • Click on the ‘Scanning’ button on the left and select in green :
      • Under Driver, Folders & Files:
        • Scan Within Archives
      • Under Select drives & folders to scan -
        • choose all hard drives
      • Under Memory & Registry: all green
      • Scan active processes
      • Scan registry
      • Deep-scan registry
      • Scan my IE favorites for banned URLs
      • Scan my Hosts file
    • Click on the ‘Advanced’ button on the left and select in green:
      • Under Shell Integration:
        • Move deleted files to recycle bin
      • Under Logfile Detail Level: (all green)
        • include addtional object information
        • DESELECT - include negligible objects information
        • include environment information
      • Under Alternate Data Streams:
        • Don't log streams smaller than 0 bytes
        • Don't log ADS with the following names: CA_INOCULATEIT
    • Click the ‘Tweak’ button and select in green:
      • Under the ‘Scanning Engine’:
        • Unload recognized processes during scanning
        • Scan registry for all users instead of current user only
      • Under the ‘Cleaning Engine’:
        • Always try to unload modules before deletion
        • During removal, unload Explorer and IE if necessary
        • Let Windows remove files in use at next reboot
      • Under the Log Files:
        • Include basic Ad-aware SE settings in logfile
        • Include additional Ad-aware SE settings in logfile
        • Please do not check or make green: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
    • Choose:'Perform Full System Scan'
    • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window, click "Next".
  • The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".
  • Save the log file when it asks and then click ‘finish’.
  • REBOOT to complete the removal of what Ad-Aware SE found.
Scan with HijackThis and post a fresh log as a reply to this topic.
Ok I did everything you said to do. Thanks for responding and helping so..quickly!
This has been a very crazy experience.
:weee:

the RUNDLL message:
error loading c:\windows\cfgmgr52.dll specific mode could not be found still pops up when booting up the computer.

The "out of control" POPUPS has stopped!! Can I hope that it is gone? :D

This is the newest hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:29:00 PM, on 7/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\mqpsw.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\mpneamci.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {15EE3E64-7B09-15A8-9378-5024D890E05A} - C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [rllzpe] c:\windows\system32\rllzpe.exe
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\kljlkm.exe reg_run
O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - HKLM\..\Run: [sac] c:\program files\180searchassistant\sac.exe
O4 - HKLM\..\Run: [37oj39R] mqpsw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Iw7tRVd6T] mpneamci.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://v5.windowsupdate.microsoft.com/v5co…b?1114480066078
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -
O16 - DPF: {D02E8435-0594-4424-B127-E096600317B7} (MailEdit Control) - http://mail.korea.com/bin/KorMail55.Cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

:P
Step 1
Open HijackThis, run a scan, then check the following:

O2 - BHO: (no name) - {15EE3E64-7B09-15A8-9378-5024D890E05A} - C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll (file missing)

O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [rllzpe] c:\windows\system32\rllzpe.exe
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\kljlkm.exe reg_run
O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - HKLM\..\Run: [sac] c:\program files\180searchassistant\sac.exe
O4 - HKLM\..\Run: [37oj39R] mqpsw.exe
O4 - HKCU\..\Run: [Iw7tRVd6T] mpneamci.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"

O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_01) -

O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll


With all other programs and browsers closed, click fix checked.


Step 2
Go to Add/Remove Programs and remove the following items (if found):

Uninstall 180 search assistant
Zango
CasinoClient or Cas
WeirdOnTheWeb
VirtualBouncer
VBouncer



Step 3
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 4
Please delete the following files/folders:
These Files
C:\WINDOWS\System32\PSof1.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\cfgmgr52.dll
C:\WINDOWS\System32\richup.exe
c:\windows\system32\rllzpe.exe
C:\WINDOWS\VCMnet11.exe
C:\WINDOWS\System32\kljlkm.exe
C:\WINDOWS\System32\mqpsw.exe
C:\WINDOWS\System32\mpneamci.exe

These Folders
C:\Program Files\VBouncer
C:\Program Files\WeirdOnTheWeb
c:\program files\180searchassistant
C:\Program Files\Cas

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 5
Reboot normally. Please download the trial version of Ewido security suite.

Install and Update Ewido:
  • Download and install Ewido security suite.
  • Launch Ewido, there should be an icon on your desktop for it to double-click.
    • The program will prompt you to update, click the OK button.
    • The program will now go to the main screen.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Click on Start.
    • The update will start and a progress bar will show the updates being installed.
  • Once the updates are installed, close the program.
Scanning With Ewido:
  • Reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').
  • Launch Ewido again.
  • Click on scanner.
  • Make sure the following boxes are checked before scanning:
  • Binder
  • Crypter
  • Archives
[*]Click on Start Scan.
  • Let the program scan the machine.
  • While the scan is in progress you will be prompted to clean files, click OK.

[*]Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
  • Click Save report.
  • Save the report to your desktop.

[*]Reboot the computer to finish the removal process.

Step 6
Scan with HijackThis. Post the new log as a reply to this thread. Please turn off Word Wrap in Notepad before posting the log (In Notepad, click Format and uncheck Word Wrap).
Please let us know of any complications you had and how the computer is behaving.
Here we go! :lol:

Step 1: fixed
Step 2: add/remove- none found
Step 3: done
Step 4: Deleted the following
C:\WINDOWS\System32\mqpsw.exe
C:\WINDOWS\System32\mpneamci.exe

*** should I removed these files which were created the day of the BIG problems?
C:\WINDOWS\aurora.dll
C:\WINDOWS\win.ini
C:\WINDOWS\HGHMIHPN.INI

Step 5: Impressive program
2. There was no prompt

Step 6: Here is the new Hijackthis Log file

Logfile of HijackThis v1.99.1
Scan saved at 7:30:57 PM, on 7/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1114480066078
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D02E8435-0594-4424-B127-E096600317B7} (MailEdit Control) - http://mail.korea.com/bin/KorMail55.Cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

**** once again thanks for all your wonderful and patient help! :D ***
The computer seems to be running ok! 1. error loading c:\windows\cfgmgr52.dll message is gone. 2. norton found this: c:\programfiles\aprps\cxtpls.exe c:\windows\system32\installerv3.exe :unsure:
Did you save the report with Ewido? I'd like to have a look at it so I can see what was removed.

This file is a legit file: C:\WINDOWS\win.ini

Right click on the file and choose 'properties', than on the 'version' tab note what the "Company" and "Version" are. Do this for both files.

C:\WINDOWS\aurora.dll
C:\WINDOWS\HGHMIHPN.INI


If you still are unsure what this file is, please submit it to the following links for a scan.
http://www.kaspersky.com/scanforvirus
http://virusscan.jotti.org/


Did Norton remove or quarantine these files? If not delete them as they are both malware files.
c:\programfiles\aprps\cxtpls.exe
c:\windows\system32\installerv3.exe
:o 1. The pointer (mouse arrow) keeps showing the hourglass every few minutes. 2. There was no company or version associated with the two files. The web sites said they were ok and no virus was detected. 3. Norton deleted the two files. 4. Here is the Ewido log: ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 7:27:20 PM, 7/8/2005 + Report-Checksum: CBA03544 + Scan result: HKLM\SOFTWARE\AutoLoader -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\AutoLoader\30711LMSIZPZ -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\AutoLoader\307N1LMSIZPZ -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup HKLM\SOFTWARE\SafeSurfing -> Spyware.SafeSurfing : Cleaned with backup HKLM\SOFTWARE\SafeSurfing\System -> Spyware.SafeSurfing : Cleaned with backup :mozilla.6:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.8:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.11:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.12:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.13:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.20:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.31:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.33:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.34:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.35:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.36:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.42:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.50:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.61:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.96:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.149:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.150:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.151:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.152:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.193:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Specificpop : Cleaned with backup :mozilla.218:C:\Documents and Settings\lee4572\Application Data\Mozilla\Firefox\Profiles\5emv66zw.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup :mozilla.6:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.9:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.10:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.11:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.12:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.29:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.48:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.49:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.50:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.51:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.54:C:\Documents and Settings\mom & dad\Application Data\Mozilla\Firefox\Profiles\fu36pzfj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.14:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.26:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.27:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.33:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.36:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.37:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.38:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.39:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.41:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.43:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.44:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.45:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.63:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.64:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.65:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.66:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup :mozilla.67:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.68:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.69:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.71:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.75:C:\Documents and Settings\phybertek\Application Data\Mozilla\Firefox\Profiles\asym7z50.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.6:C:\Documents and Settings\phybertek\Application Data\Mozilla\Profiles\default\2a00qhkw.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.7:C:\Documents and Settings\phybertek\Application Data\Mozilla\Profiles\default\2a00qhkw.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.9:C:\Documents and Settings\phybertek\Application Data\Mozilla\Profiles\default\2a00qhkw.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.9:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.10:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.11:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.13:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.23:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.26:C:\Documents and Settings\sonya\Application Data\Mozilla\Firefox\Profiles\3dehhitz.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.12:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.13:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.14:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.15:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.16:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.18:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.19:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.20:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.21:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.22:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.37:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.38:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.39:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.40:C:\Documents and Settings\susui\Application Data\Mozilla\Firefox\Profiles\1f9p0vzr.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup C:\Program Files\Aprps\CxtPls.dll -> Heuristic.Win32.Hijacker1 : Cleaned with backup C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD : Cleaned with backup C:\RECYCLER\NPROTECT\00000064.EXE -> TrojanDownloader.Apropo.g : Cleaned with backup C:\RECYCLER\NPROTECT\00000066.EXE -> Spyware.AproposMedia : Cleaned with backup ::Report End Thanks again! :D
Download and install CleanUp!. Here is the information page on it.
  • Click Start > All Programs > "CleanUp!" > "CleanUp!".
  • A dialog will appear. Click on the button labeled "CleanUp!".
  • Reboot.
Delete the following folder:

c:\programfiles\aprps


The first file, I'm thinking may be part of another infection but harmless by itself and the second, I have no idea about. Please locate the following files. Right click on it and choose send to < Compressed (zipped) Folder. Please email the zipped folder to here so it can be examined and sent to the proper people. Be sure to include a link to this thread in the email.
C:\WINDOWS\aurora.dll
C:\WINDOWS\HGHMIHPN.INI
I've downloaded and installed Cleanup. I have CCleaner too. Is this the same thing? And I deleted the folder and sent the zip file via email with the link. The hourglass still shows up and I hold my breath hoping a pop-up doesn't show up! Do you want another Hijack log? Thanks a zillion billion for all your help since I was pulling out all my hair from fustration! :lol:
I'm not really sure what to tell you about the mouse showing the hourglass cursor every few minutes. Is this the only noticable problem with the computer now?

Let's run another scan to see if it can find anything else.
Click here to download mwavscan.
  • Double-click it to run it.
  • Read then accept the agreement.
  • Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
  • Once it finds something, it will prompt you so click OK.
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it with the mouse, copy it (CTRL+C), and paste (CTRL+V) it in your next reply.
Note : It will find many orphaned registry entries so please do not be alarmed by the amount of items that show.


It may take a few days to hear back on the submitted files.
You can delete those two files.

arora.dll is nothing more then a list of "hijacked" domains.
As far as I could establish distributed by web-nexus

The ini is encrypted and should be harnmless by itself.

Regards,

Pieter
Ok the two files have been deleted! Thanks… Here's the log and have a great weekend! :weee: MWAVSCAN results: 57 virus found and 110 errors Object "sidefind Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "Gator Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "precisiontime Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "slmss Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "DownloadWare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "CWS.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\IEGator.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\Clea0ENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\Clea2ENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\QCleaENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\QLTENU.chm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\Clea3ENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\UPlugENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\QltCoENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\Clea4ENU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\QuickClean Lite\tlsxpand.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Shredder\shredder.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Shredder\ShrEnu.chm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Shredder\ShredEnu.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentDEU.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentITA.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentESP.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentFRA.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentNLD.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Central\CentPTB.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RupEnu.chm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\tlsxpand.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{039CD332-FB27-4F71-93D2-DB6610BB84D3}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{03C512E0-0444-11D2-9A7F-0000E8A2F1D2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\MCutList.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{09076121-9B82-463F-AB64-571692399646}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0966fc7d-dfb0-cccc-53bb-907c50ca5c88}" refers to invalid object "C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{119E34C1-8108-11D5-91D7-00004CD94BFF}" refers to invalid object "C:\Program Files\Ulead Systems\Ulead VideoStudio 7 SE Basic\uFileIO.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{119E34C2-8108-11D5-91D7-00004CD94BFF}" refers to invalid object "C:\Program Files\Ulead Systems\Ulead VideoStudio 7 SE Basic\uFileIO.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{119E34C3-8108-11D5-91D7-00004CD94BFF}" refers to invalid object "C:\Program Files\Ulead Systems\Ulead VideoStudio 7 SE Basic\uFileIO.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{12ff3c61-5208-12a4-9477-522dd093e750}" refers to invalid object "C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1E5CC1BF-9B43-47BA-AFA9-BB38A9068722}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1E951F23-9C37-11D3-BA52-0000E8497C01}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\Dvsf.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{307A6C42-0000-0010-8000-00AA00389B71}" refers to invalid object "c:\program files\warcraft iii\blizzard.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{39AEA79A-BF43-475F-B4F9-15347CFBF2B3}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\Dvsf.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3D1EB621-38A1-11D4-AB8F-0000E875BA48}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\Dvsf.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4281B857-D41F-4165-B9E6-BE3DD5B24109}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRDrv.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{442D12A1-2641-11d2-90FB-006008A1F441}" refers to invalid object "a3d.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4573D9BF-F1AE-4516-B9B3-F9B1B9A9BDDC}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{46A06300-914A-11D3-BA52-0000E8497C01}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\Dvsf.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{46A06303-914A-11D3-BA52-0000E8497C01}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\Dvsf.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{49527153-FCFD-42FC-A7B8-07B6CADB4D2D}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{49d84e1e-a711-4652-afb1-ab48459bf2ce}" refers to invalid object "C:\WINDOWS\System32\rgwgr.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4a334055-5278-e088-7922-90f520b4771e}" refers to invalid object "C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4DBC1640-F95A-11D1-9A7F-0000E8A2F1D2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\MCutList.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5B2D374F-B988-481F-BF09-3626AA4B7F8F}" refers to invalid object "C:\PROGRA~1\SONYCO~1\PICTUR~1\PICTUR~1\EzVCD.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{61CAAD5D-29B6-4207-A3AA-E9AFEDA8510C}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\NTICdDrv.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{648C0939-1F4F-4D10-8B8C-A54C65A00560}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\mpgaparse.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{70DC80A9-D4F8-4383-A0D7-93179AA8305E}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7630D6A2-4512-4ca2-915D-F457BC782564}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7808A677-4F0E-4431-9E86-D5A68C76341E}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\mpgmux.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7D24FC1F-750E-4f0c-B0B2-F029D6F3D22B}" refers to invalid object "C:\PROGRA~1\SONYCO~1\PICTUR~1\PICTUR~1\EzVCD.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{80DB7AC0-5EB4-11D6-A62F-0010B5549630}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\DibOutput.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8188FE20-61FC-11D6-A62F-0010B5549630}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\DibReceive.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8293D547-38DD-4325-B35A-F1817EDFA5FC}" refers to invalid object "C:\Program Files\Cas\Client\casmf.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{92FA2C24-253C-11d2-90FB-006008A1F441}" refers to invalid object "a3dapi.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{94515F8C-8451-4067-9816-4166B3418F0B}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9885A107-6FB9-4D28-8864-8DB73413B7E9}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XLogUtil.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{99AC5564-0CF3-4c5b-A594-651AC625DE15}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12}" refers to invalid object "C:\WINDOWS\System32\nsn44.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9D35EDAD-0E77-41E6-9F75-E66FFDF5C3A2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\uinftee.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9dcc00e4-e4a7-b19c-6599-203640a65322}" refers to invalid object "C:\WINDOWS\System32\cdmdownld\hlxphbqrwt.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9EFBF860-5685-11D3-AA3D-00C04F4C5275}" refers to invalid object "cdooff.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9F179100-F940-11D1-9A7F-0000E8A2F1D2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\MCutList.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AADE03FE-7BB6-4312-981D-E9F6DAAA3D75}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AC8BF71E-E41F-4FE7-B58C-E4AC3555C0BF}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LDrtBurn.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AD6BF5C0-7B88-11D5-A5DE-444553540000}" refers to invalid object "C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\BMPCapture.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B4346D2E-E989-49B1-B3AB-4506028194C6}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdrtDisc.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BB37EFA1-7BA6-437D-99AA-16E023451DE2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BC54B24C-5A97-4C19-9181-8B8A05B2E931}" refers to invalid object "C:\WINDOWS\System32\nsn44.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BD9584EF-C28C-4F6D-8D49-0CEE3C0E442F}" refers to invalid object "C:\WINDOWS\System32\nsn44.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C2316705-49F3-46a6-B178-FD617FA235D8}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LdvdEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C7888681-1A83-4C14-B9A5-95F91240B44F}" refers to invalid object "C:\WINDOWS\System32\nsn44.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C8CE6FC1-CCF1-11D6-B8A5-000064657374}" refers to invalid object "C:\Program Files\mozilla.org\Mozilla\PalmSyncProxy.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F20-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulspmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F28-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulspmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F30-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Uldsmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F38-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Uldsmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F40-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Uldsmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F48-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Uldsmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F50-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulesmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F58-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulesmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F59-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulesmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F5A-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulesmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F5B-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\Ulesmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF957F80-77FE-4192-A59F-95CA43BD04BA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\ulmxmpeg.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D19355DC-9045-4B3A-B321-1710330B5AB8}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}" refers to invalid object "C:\WINDOWS\system32\SWLAD1.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D7BCD582-12D9-41DE-A0DD-1140A140D8C3}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{d8f1eee0-f634-11cf-8700-00a0245d918b}" refers to invalid object "a3d.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DC377543-0DAB-4737-87DF-A7BB78769370}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\LDVDRec.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{dd7450c0-3e14-11d0-b599-10005a11ba95}" refers to invalid object "C:\Program Files\McAfee\McAfee Shared Components\Shredder\shredder.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DF5F4E46-D041-416C-B77E-6F8E662E2734}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E0D84E7C-1997-4F77-97C4-74D79FCF6B50}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\MPEG\mpgvparse.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E69C308A-0582-4BFF-B3DA-697BB2BB5CDA}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\DVD\XDiscLayer.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E7563EE0-F93F-11D1-9A7F-0000E8A2F1D2}" refers to invalid object "C:\Program Files\Common Files\Ulead Systems\Filters\MCutList.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F79A2C4B-8776-4ED7-8B2F-4786A4A3500A}" refers to invalid object "C:\WINDOWS\System32\richedtr.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FE5FB940-2608-4471-80BC-DA77F8B5C5F8}" refers to invalid object "C:\PROGRA~1\SONYCO~1\PICTUR~1\PICTUR~1\PxReSize.ax". Action Taken: No Action Taken. Entry "HKCR\AOLCoach.TrainerOCXCtrl" refers to invalid object "{E04EAE82-14Ad-41CB-BF5A-45556ABB8347}". Action Taken: No Action Taken. Entry "HKCR\AOLCoach.TrainerOCXCtrl.9" refers to invalid object "{E04EAE82-14Ad-41CB-BF5A-45556ABB8347}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMSServer.Server" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken. Entry "HKCR\WMSServer.Server.9" refers to invalid object "{845FB959-4279-11D2-BF23-00805FBE84A6}". Action Taken: No Action Taken. File C:\Hijack\aawsepersonal.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\AIM95\unwise32.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\DownloadWare\Downloads\217.dat tagged as "not-a-virus:AdWare.WindowEnhancer". Action Taken: No Action Taken. File C:\Program Files\iolo\System Mechanic\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Lavasoft\Ad-Aware SE Personal\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\09532F5F.exe infected by "Trojan-Downloader.Win32.Agent.qg" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\14E36B5D.exe infected by "Trojan-Downloader.Win32.Qoologic.o" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\1D3D10D0.exe tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\1D413ACD.exe infected by "Trojan-Downloader.Win32.Small.abd" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\1D470EC5.dll tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\1D470EC5.exe infected by "Trojan-Downloader.Win32.Small.abd" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\1D4A38C2.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\249B688D.exe infected by "Trojan-Downloader.Win32.Apropo.g" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\2D964E3D.exe infected by "Trojan-Dropper.Win32.Agent.hl" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\31A73FD0.dll tagged as "not-a-virus:AdWare.BookedSpace.e". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\35267E91.exe tagged as "not-a-virus:AdWare.WeirWeb.b". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\38222413.exe tagged as "not-a-virus:AdWare.ToolBar.HotSearchBar.i". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\38264E10.dll tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\3829780C.dll tagged as "not-a-virus:AdWare.ToolBar.HotSearchBar.i". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\3829780C.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\382C2208.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\382F4C05.dll tagged as "not-a-virus:AdWare.SafeSurfing.j". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\38337601.exe infected by "Trojan-Dropper.Win32.Small.qn" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\38361FFE.exe tagged as "not-a-virus:AdWare.VirtualBouncer.j". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\40B63A8F.exe infected by "Trojan-Downloader.Win32.Small.ayh" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\48C837CD.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\4CE677E3.exe tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\5E6E7DEF.dll tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\5E7127EC.exe infected by "Trojan-Downloader.Win32.Agent.qg" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\5E7451E8.cpl infected by "Trojan-Downloader.Win32.Qoologic.p" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\5E7451E8.exe infected by "Trojan-Downloader.Win32.Qoologic.p" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\5E777BE4.dll infected by "Trojan-Downloader.Win32.Qoologic.p" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\6BDF61D1.exe tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\735976EA.exe infected by "Trojan-Downloader.Win32.Apropo.g" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\735C20E6.dll tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\73661EDB.exe tagged as "not-a-virus:AdWare.WinAD.aw". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\736948D8.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\736D72D4.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\776F1DCF.exe infected by "Trojan.Win32.Agent.ay" Virus! Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\7AEE5C90.dll tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\7AEE5C90.exe tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken. File C:\Program Files\Norton AntiVirus\Quarantine\7DC37360.exe infected by "Trojan-Downloader.Win32.Apropo.u" Virus! Action Taken: No Action Taken. File C:\Program Files\Return to Castle Wolfenstein\Uninstall\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Wolfenstein - Enemy Territory\Uninstall\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Zip\eDonkey0.45.exe tagged as "not-a-virus:AdWare.ToolBar.Ucmore.a". Action Taken: No Action Taken. File C:\Zip\edonkey0.50.1.exe tagged as "not-a-virus:AdWare.MetaDirect.b". Action Taken: No Action Taken. File C:\Zip\Metaframe Folder\ScrewDrivers Client fXP 2.1.07.07.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Downloads\aawsepersonal.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Thanks Metallica for the information on the two files. :thumbup:


Delete this file as well.

C:\Program Files\DownloadWare\Downloads\217.dat

How is the computer behaving now?
I've removed the file but alas…. the hourglass still shows up. :blink: Can you recommend a popup killer and something that would help prevent malware? Thanks! :P

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI