This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't get rid of a Trojan and/or Spyware

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.97.7
Scan saved at 5:44:37 PM, on 6/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\mfcqb32.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\d3jt32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\hookdump.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wuhab.dll/sp.html#14044
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\wuhab.dll/sp.html#14044
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E6A5DEB6-DFBB-FF53-9851-961BC9F9B592} - C:\WINDOWS\system32\crgg.dll
O2 - BHO: (no name) - {F69A9573-0B4D-FD1A-341A-6FCC2CAC8DC7} - C:\WINDOWS\system32\crgg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [d3jt32.exe] C:\WINDOWS\system32\d3jt32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKLM\..\RunOnce: [mfcqb32.exe] C:\WINDOWS\system32\mfcqb32.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Spyware Doctor (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab

There are several things happening with the computer. I have Norton AntiVirus and it has detected a virus located in C:\windows\system32\mfcqb.exe Norton Antivirus says that Access to the file is denied, that it is Unable to repair the file, and calls it a Trojan Horse. Also, there is a red circle with a white X that has told me thousands of times that the computer is infected…I know already!!!:) The computer also changes the desktop picture and won't allow it to be changed back to a standard Windows XP picture. The background says that there is Spyware on the computer with a link to remove it. A website involving AntiVirusGold comes up (which by the way installed itself automatically when this happened) saying I need to purchase this software to remove the Spyware. The web browser also now defaults to a random search engine (about:blank) and the homepage is now unchangeable. I have run Norton Anti-Virus several times to no avail; however, it was able to quarantine and delete one or two other virusus. I think that pretty much sums up what is going; it is nightmare for me:) Thank you very much for any assistance you can provide and have a great day.
Michael
BUMP My post has been here since 30June with no replies. Please let me know if you can help me, otherwise I will take it to an expert. Thanks, Michael
BUMP Apologize for my comment about experts, I know that ya'll are very skillfull. The problem is I messed up my friends computer , so I need to get it fixed soon before I move;) Thank you for anything you can help me with. Respectfully, Michael
You have a nasty infection called About:Blank on your computer that we need to fix among other things. But first before we can help you, we need to see an updated log with the latest version of HijackThis (1.99.1).

Update to HijackThis 1.99.1.
  • Open HijackThis and click config.. < Misc. Tools, scroll down and click Check for Update Online.
  • Scan with HijackThis and post the new log as a reply to this thread.
After posting the new HijackThis log as a reply to this thread, do not reboot the computer nor use Internet Explorer if at all possible as this will cause the infection to change. I will receive an email notification of your reply and will respond as quickly as I can.
Logfile of HijackThis v1.99.1
Scan saved at 8:27:22 AM, on 7/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\d3jt32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\hookdump.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\mfcqb32.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {E6A5DEB6-DFBB-FF53-9851-961BC9F9B592} - C:\WINDOWS\system32\crgg.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [d3jt32.exe] C:\WINDOWS\system32\d3jt32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ntjs.exe] C:\WINDOWS\ntjs.exe
O4 - HKLM\..\Run: [javajf.exe] C:\WINDOWS\javajf.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcqb32.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Alan,

Thank you so much for your help! The dog looks awesome… what is he/she (I am guessing at least part lab?) Also, have to ask if you are a U of M fan or Michigan State fan… or neither? I will follow your directions explicitly (except I need to use the internet to get to Tom Coyote). Thank you again and have a great day.

Mike
Hello Mike and welcome to TomCoyote. :wavey:

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare AboutBuster for use:
    • Download AboutBuster.
    • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
    • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
    • Click "Update" to begin the update process.
    • If any updates exist please install them.
    • You should not run the program yet so click the "X" to exit the program.
  • Prepare cwsserviceremove.reg for use:
    • Download cwsserviceremove.zip.
    • Unzip the contents of cwsserviceremove.zip (cwsserviceremove.reg) to your desktop.
    • Delete the cwsserviceremove.zip folder.
    • Please do not do anything with it yet.
  • Reconfigure Windows XP to show hidden files:
    • Click Start. Open My Computer.
    • Select the Tools menu and click Folder Options. Select the View Tab.
    • Under the Hidden files and folders heading select "Show hidden files and folders".
    • Uncheck the "Hide protected operating system files (recommended)" option.
    • Uncheck the "Hide file extensions for known file types" option.
    • Click Yes to confirm. Click OK.
  • Disable the offending service.
    • Go to Start->Run and type Services.msc then hit Ok
    • Scroll down and find the service called : Workstation NetLogon Service
    • When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.
Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Remove the offending service:
    • Double-click on cwsserviceremove.reg you downloaded earlier.
    • When it asks you to merge the information to the registry click "Yes".
  • Run AboutBuster and save the logs:
    • Browse to where you saved AboutBuster and run AboutBuster.exe.
    • Click "Begin Removal" to start the scan.
    • When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK.
    • Another information window will open. Click on Exit.
    • AboutBuster will inform you that a log has been created. Click OK.
  • Fix with Hijackthis:
    • Open Hijackthis, Run a scan and check the following:

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\naodo.dll/sp.html#14044
      R3 - Default URLSearchHook is missing

      O2 - BHO: Class - {E6A5DEB6-DFBB-FF53-9851-961BC9F9B592} - C:\WINDOWS\system32\crgg.dll

      O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
      O4 - HKLM\..\Run: [d3jt32.exe] C:\WINDOWS\system32\d3jt32.exe
      O4 - HKLM\..\Run: [ntjs.exe] C:\WINDOWS\ntjs.exe
      O4 - HKLM\..\Run: [javajf.exe] C:\WINDOWS\javajf.exe
      O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe

      O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    • With all other programs and browsers closed, click fix checked.
  • Delete the following files:C:\WINDOWS\system32\mfcqb32.exe
    C:\WINDOWS\system32\d3jt32.exe
    C:\WINDOWS\ntjs.exe
    C:\WINDOWS\javajf.exe
    C:\WINDOWS\System32\hookdump.exe
    C:\WINDOWS\system32\crgg.dllb
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.
  • Restart your computer normally to return to normal mode.
  • Free TrendMicro Housecall scan:
    • You'll need to use Internet Explorer or Netscape browsers to run this scan.
    • Vist the TrendMicro Housecall website.
    • Select your country from the drop-down list and click "Go".
    • Choose "Yes" at the ActiveX Security Warning prompt.
    • Please wait while the Housecall engine is updated.
    • Select the drives to be scanned by placing a check in their respective boxes.
    • Check the "Auto Clean" box.
    • Click "SCAN" in order to begin scanning your system.
    • Please be patient while Housecall scans your system for malicious files.
    • If not auto-cleaned, remove anything it finds.
    • Click "Close" to exit the Housecall scanner.
    • Choose "Yes" at the HouseCall message prompt.
  • Prepare your reply:
    • Please post a fresh HijackThis log as a reply to this thread.
    • Please post the AboutBuster log.
    • Please note any complications you had.
Good evening.. hope all is well with you! I went thru all the steps and somethings have changed (no more warning of virus/trojan, and I can now change my homepage from something other than about:blank). The only major problem I see now is that the background still says that my computer is in danger and that I need to go to the website www.antivirusgold.com to have the spyware removed. I try to change the background, but no luck. Below is the information you requested. I was not able to find all the files you wanted removed, only hookdump.exe was in the windows file, the others were not there. Alrighty, look forward to your reply. Thanks for the help thus far, this is awesome!

Sincerely,
Michael

Logfile of HijackThis v1.99.1
Scan saved at 7:38:48 PM, on 7/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lee Gitschier\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

AboutBuster 5.0 reference file 30
Scan started on [7/13/2005] at [3:53:49 PM]
————————————————
Removed Stream! C:\WINDOWS\Gone Fishing.bmp:ntvrgu
Removed Stream! C:\WINDOWS\IIS6.LOG:ylowiw
Removed Stream! C:\WINDOWS\KB888302.log:yiznlw
Removed Stream! C:\WINDOWS\KB893066.log:zbpanp
Removed Stream! C:\WINDOWS\KB896358.log:ifikzl
Removed Stream! C:\WINDOWS\KB896422.log:jcinhz
Removed Stream! C:\WINDOWS\NetwkCfg.txt:ikthdq
Removed Stream! C:\WINDOWS\ODBCINST.INI:ifmndh
Removed Stream! C:\WINDOWS\orun32.ini:agfsxs
Removed Stream! C:\WINDOWS\Q813862.log:vsqxyd
Removed Stream! C:\WINDOWS\svcpack.log:xvlinu
Removed Stream! C:\WINDOWS\SYSTEM.INI:qvenqe
Removed Stream! C:\WINDOWS\WMSysPrx.prx:uhecql
Removed Stream! C:\WINDOWS\{9F71E890-0F5A-4805-B556-238CCD3F2B30}.dat:duixac
————————————————
Removed File! : C:\Windows\addaq32.exe
Removed File! : C:\Windows\addck.exe
Removed File! : C:\Windows\addhw.exe
Removed File! : C:\Windows\addlw32.exe
Removed File! : C:\Windows\addmn.exe
Removed File! : C:\Windows\addmv.exe
Removed File! : C:\Windows\addpg.exe
Removed File! : C:\Windows\addvd.exe
Removed File! : C:\Windows\addxj.exe
Removed File! : C:\Windows\addxn.exe
Removed File! : C:\Windows\addyi32.exe
Removed File! : C:\Windows\apiah.exe
Removed File! : C:\Windows\apiay.exe
Removed File! : C:\Windows\apibo32.exe
Removed File! : C:\Windows\apieh32.exe
Removed File! : C:\Windows\apihk32.exe
Removed File! : C:\Windows\apihz.exe
Removed File! : C:\Windows\apiim32.exe
Removed File! : C:\Windows\apiip32.exe
Removed File! : C:\Windows\apijf.exe
Removed File! : C:\Windows\apijq.exe
Removed File! : C:\Windows\apilz.exe
Removed File! : C:\Windows\apink.exe
Removed File! : C:\Windows\apiov.exe
Removed File! : C:\Windows\apiqa.exe
Removed File! : C:\Windows\apiqp.exe
Removed File! : C:\Windows\apisl.exe
Removed File! : C:\Windows\appfv32.exe
Removed File! : C:\Windows\appkc.exe
Removed File! : C:\Windows\appku.exe
Removed File! : C:\Windows\appkw32.exe
Removed File! : C:\Windows\appme32.exe
Removed File! : C:\Windows\appmj32.exe
Removed File! : C:\Windows\appnu32.exe
Removed File! : C:\Windows\appoj.exe
Removed File! : C:\Windows\appom32.exe
Removed File! : C:\Windows\appos.exe
Removed File! : C:\Windows\appqe.exe
Removed File! : C:\Windows\appqp32.exe
Removed File! : C:\Windows\appsh.exe
Removed File! : C:\Windows\appup32.exe
Removed File! : C:\Windows\appvu.exe
Removed File! : C:\Windows\appwi.exe
Removed File! : C:\Windows\appzt.exe
Removed File! : C:\Windows\atlfg32.exe
Removed File! : C:\Windows\atlgm.exe
Removed File! : C:\Windows\atlit32.exe
Removed File! : C:\Windows\atlnc32.exe
Removed File! : C:\Windows\atlnw32.exe
Removed File! : C:\Windows\atloq.exe
Removed File! : C:\Windows\atlqz32.exe
Removed File! : C:\Windows\atlrq.exe
Removed File! : C:\Windows\atltf32.exe
Removed File! : C:\Windows\atltq32.exe
Removed File! : C:\Windows\atltz.exe
Removed File! : C:\Windows\atlua32.exe
Removed File! : C:\Windows\atlvd.exe
Removed File! : C:\Windows\atlyv32.exe
Removed File! : C:\Windows\craw.exe
Removed File! : C:\Windows\crda32.exe
Removed File! : C:\Windows\crik32.exe
Removed File! : C:\Windows\crjg32.exe
Removed File! : C:\Windows\crlv.exe
Removed File! : C:\Windows\crpo.exe
Removed File! : C:\Windows\crre.exe
Removed File! : C:\Windows\crrq.exe
Removed File! : C:\Windows\crsd.exe
Removed File! : C:\Windows\crul.exe
Removed File! : C:\Windows\cruu32.exe
Removed File! : C:\Windows\crvg.exe
Removed File! : C:\Windows\crxp32.exe
Removed File! : C:\Windows\d3bl32.exe
Removed File! : C:\Windows\d3ew32.exe
Removed File! : C:\Windows\d3gz32.exe
Removed File! : C:\Windows\d3ik32.exe
Removed File! : C:\Windows\d3ux32.exe
Removed File! : C:\Windows\d3wh.exe
Removed File! : C:\Windows\d3yr.exe
Removed File! : C:\Windows\d3zy32.exe
Removed File! : C:\Windows\dmxge.dat
Removed File! : C:\Windows\ieaz32.exe
Removed File! : C:\Windows\iebf32.exe
Removed File! : C:\Windows\iecj.exe
Removed File! : C:\Windows\iect32.exe
Removed File! : C:\Windows\iecw32.exe
Removed File! : C:\Windows\ieeb32.exe
Removed File! : C:\Windows\iegj.exe
Removed File! : C:\Windows\ieke.exe
Removed File! : C:\Windows\ielk.exe
Removed File! : C:\Windows\iepl32.exe
Removed File! : C:\Windows\ieug32.exe
Removed File! : C:\Windows\ievb.exe
Removed File! : C:\Windows\ieym32.exe
Removed File! : C:\Windows\ipcp32.exe
Removed File! : C:\Windows\ipgm32.exe
Removed File! : C:\Windows\ipjc32.exe
Removed File! : C:\Windows\ipla32.exe
Removed File! : C:\Windows\ippj.exe
Removed File! : C:\Windows\ippz32.exe
Removed File! : C:\Windows\ipqu.exe
Removed File! : C:\Windows\ipta.exe
Removed File! : C:\Windows\ipth.exe
Removed File! : C:\Windows\ipwb32.exe
Removed File! : C:\Windows\ipwr32.exe
Removed File! : C:\Windows\ipyp32.exe
Removed File! : C:\Windows\javaaz.exe
Removed File! : C:\Windows\javaaz32.exe
Removed File! : C:\Windows\javael.exe
Removed File! : C:\Windows\javagd.exe
Removed File! : C:\Windows\javaic.exe
Removed File! : C:\Windows\javajf.exe
Removed File! : C:\Windows\javajl.exe
Removed File! : C:\Windows\javalr32.exe
Removed File! : C:\Windows\javalx32.exe
Removed File! : C:\Windows\javams32.exe
Removed File! : C:\Windows\javaoj32.exe
Removed File! : C:\Windows\javaqp32.exe
Removed File! : C:\Windows\javarc.exe
Removed File! : C:\Windows\javasd.exe
Removed File! : C:\Windows\javato32.exe
Removed File! : C:\Windows\javaua32.exe
Removed File! : C:\Windows\javayn.exe
Removed File! : C:\Windows\javayy32.exe
Removed File! : C:\Windows\mfccu32.exe
Removed File! : C:\Windows\mfcde.exe
Removed File! : C:\Windows\mfcdt.exe
Removed File! : C:\Windows\mfcgm32.exe
Removed File! : C:\Windows\mfcgr.exe
Removed File! : C:\Windows\mfciu32.exe
Removed File! : C:\Windows\mfcjp32.exe
Removed File! : C:\Windows\mfcni.exe
Removed File! : C:\Windows\mfcuf32.exe
Removed File! : C:\Windows\mfcvi.exe
Removed File! : C:\Windows\mfcwa.exe
Removed File! : C:\Windows\mfcxb32.exe
Removed File! : C:\Windows\mfcyi.exe
Removed File! : C:\Windows\mfczf32.exe
Removed File! : C:\Windows\msbb.exe
Removed File! : C:\Windows\mscn32.exe
Removed File! : C:\Windows\mseb.exe
Removed File! : C:\Windows\msfx32.exe
Removed File! : C:\Windows\msgw32.exe
Removed File! : C:\Windows\msgz.exe
Removed File! : C:\Windows\msha32.exe
Removed File! : C:\Windows\msin.exe
Removed File! : C:\Windows\msiv.exe
Removed File! : C:\Windows\msjw.exe
Removed File! : C:\Windows\msrq.exe
Removed File! : C:\Windows\msul32.exe
Removed File! : C:\Windows\msxx32.exe
Removed File! : C:\Windows\netdc32.exe
Removed File! : C:\Windows\netha.exe
Removed File! : C:\Windows\netio32.exe
Removed File! : C:\Windows\netjh32.exe
Removed File! : C:\Windows\netjr.exe
Removed File! : C:\Windows\netls32.exe
Removed File! : C:\Windows\netmh32.exe
Removed File! : C:\Windows\netnr.exe
Removed File! : C:\Windows\neton32.exe
Removed File! : C:\Windows\netrb32.exe
Removed File! : C:\Windows\netsj.exe
Removed File! : C:\Windows\netsz.exe
Removed File! : C:\Windows\netvc.exe
Removed File! : C:\Windows\netyg.exe
Removed File! : C:\Windows\netyo.exe
Removed File! : C:\Windows\netzf.exe
Removed File! : C:\Windows\netzh32.exe
Removed File! : C:\Windows\ntar32.exe
Removed File! : C:\Windows\ntbb32.exe
Removed File! : C:\Windows\ntfd32.exe
Removed File! : C:\Windows\ntjk.exe
Removed File! : C:\Windows\ntkq.exe
Removed File! : C:\Windows\ntlv32.exe
Removed File! : C:\Windows\ntmv.exe
Removed File! : C:\Windows\nton.exe
Removed File! : C:\Windows\ntpy.exe
Removed File! : C:\Windows\ntqo.exe
Removed File! : C:\Windows\ntrt.exe
Removed File! : C:\Windows\ntvg32.exe
Removed File! : C:\Windows\ntyk.exe
Removed File! : C:\Windows\sdkaq.exe
Removed File! : C:\Windows\sdkat32.exe
Removed File! : C:\Windows\sdkax32.exe
Removed File! : C:\Windows\sdkcf32.exe
Removed File! : C:\Windows\sdkek32.exe
Removed File! : C:\Windows\sdkic32.exe
Removed File! : C:\Windows\sdkjn.exe
Removed File! : C:\Windows\sdkkc32.exe
Removed File! : C:\Windows\sdknm.exe
Removed File! : C:\Windows\sdkqr.exe
Removed File! : C:\Windows\sdkuf32.exe
Removed File! : C:\Windows\sdkwd.exe
Removed File! : C:\Windows\sysaa.exe
Removed File! : C:\Windows\sysae.exe
Removed File! : C:\Windows\sysfq32.exe
Removed File! : C:\Windows\sysjm32.exe
Removed File! : C:\Windows\syskh.exe
Removed File! : C:\Windows\sysne32.exe
Removed File! : C:\Windows\sysra32.exe
Removed File! : C:\Windows\sysyr32.exe
Removed File! : C:\Windows\winan32.exe
Removed File! : C:\Windows\windp.exe
Removed File! : C:\Windows\winea.exe
Removed File! : C:\Windows\wineq.exe
Removed File! : C:\Windows\winfk.exe
Removed File! : C:\Windows\wingp32.exe
Removed File! : C:\Windows\wingw32.exe
Removed File! : C:\Windows\winhb.exe
Removed File! : C:\Windows\winip.exe
Removed File! : C:\Windows\winjd32.exe
Removed File! : C:\Windows\winli32.exe
Removed File! : C:\Windows\winlx32.exe
Removed File! : C:\Windows\winng.exe
Removed File! : C:\Windows\winnv.exe
Removed File! : C:\Windows\winot32.exe
Removed File! : C:\Windows\winrv.exe
Removed File! : C:\Windows\wintc32.exe
Removed File! : C:\Windows\winwb.exe
Removed File! : C:\Windows\System32\addac.exe
Removed File! : C:\Windows\System32\adddc.exe
Removed File! : C:\Windows\System32\addec32.exe
Removed File! : C:\Windows\System32\addgq.exe
Removed File! : C:\Windows\System32\addib32.exe
Removed File! : C:\Windows\System32\addim32.exe
Removed File! : C:\Windows\System32\addko32.exe
Removed File! : C:\Windows\System32\addlm32.exe
Removed File! : C:\Windows\System32\addlv.exe
Removed File! : C:\Windows\System32\addmb.exe
Removed File! : C:\Windows\System32\addna32.exe
Removed File! : C:\Windows\System32\addnx32.exe
Removed File! : C:\Windows\System32\addrm.exe
Removed File! : C:\Windows\System32\addso.exe
Removed File! : C:\Windows\System32\addva.exe
Removed File! : C:\Windows\System32\addvr32.exe
Removed File! : C:\Windows\System32\addxn.exe
Removed File! : C:\Windows\System32\addze.exe
Removed File! : C:\Windows\System32\apiaj32.exe
Removed File! : C:\Windows\System32\apiao.exe
Removed File! : C:\Windows\System32\apibt.exe
Removed File! : C:\Windows\System32\apicp.exe
Removed File! : C:\Windows\System32\apieh.exe
Removed File! : C:\Windows\System32\apier.exe
Removed File! : C:\Windows\System32\apifc32.exe
Removed File! : C:\Windows\System32\apiiw.exe
Removed File! : C:\Windows\System32\apijq32.exe
Removed File! : C:\Windows\System32\apikr32.exe
Removed File! : C:\Windows\System32\apimb.exe
Removed File! : C:\Windows\System32\apins.exe
Removed File! : C:\Windows\System32\apiqx.exe
Removed File! : C:\Windows\System32\apitu32.exe
Removed File! : C:\Windows\System32\apixk32.exe
Removed File! : C:\Windows\System32\apiyk.exe
Removed File! : C:\Windows\System32\appez32.exe
Removed File! : C:\Windows\System32\apphc32.exe
Removed File! : C:\Windows\System32\apphp32.exe
Removed File! : C:\Windows\System32\appis.exe
Removed File! : C:\Windows\System32\applr32.exe
Removed File! : C:\Windows\System32\appru32.exe
Removed File! : C:\Windows\System32\appti32.exe
Removed File! : C:\Windows\System32\apptx32.exe
Removed File! : C:\Windows\System32\appxf32.exe
Removed File! : C:\Windows\System32\atlau.exe
Removed File! : C:\Windows\System32\atlbq32.exe
Removed File! : C:\Windows\System32\atlbr.exe
Removed File! : C:\Windows\System32\atlca.exe
Removed File! : C:\Windows\System32\atlcg32.exe
Removed File! : C:\Windows\System32\atldu32.exe
Removed File! : C:\Windows\System32\atlem32.exe
Removed File! : C:\Windows\System32\atlgz.exe
Removed File! : C:\Windows\System32\atlia.exe
Removed File! : C:\Windows\System32\atlki32.exe
Removed File! : C:\Windows\System32\atlkq.exe
Removed File! : C:\Windows\System32\atllr32.exe
Removed File! : C:\Windows\System32\atlnz32.exe
Removed File! : C:\Windows\System32\atlpm32.exe
Removed File! : C:\Windows\System32\atlui32.exe
Removed File! : C:\Windows\System32\atlxb.exe
Removed File! : C:\Windows\System32\crfb.exe
Removed File! : C:\Windows\System32\crlc32.exe
Removed File! : C:\Windows\System32\croc32.exe
Removed File! : C:\Windows\System32\cron32.exe
Removed File! : C:\Windows\System32\crqt.exe
Removed File! : C:\Windows\System32\crwe32.exe
Removed File! : C:\Windows\System32\crzk32.exe
Removed File! : C:\Windows\System32\crzx.exe
Removed File! : C:\Windows\System32\d3cc32.exe
Removed File! : C:\Windows\System32\d3dg.exe
Removed File! : C:\Windows\System32\d3qa.exe
Removed File! : C:\Windows\System32\d3sm32.exe
Removed File! : C:\Windows\System32\d3tn.exe
Removed File! : C:\Windows\System32\iefh.exe
Removed File! : C:\Windows\System32\iegk32.exe
Removed File! : C:\Windows\System32\iegt32.exe
Removed File! : C:\Windows\System32\iehv32.exe
Removed File! : C:\Windows\System32\ieio.exe
Removed File! : C:\Windows\System32\iejv.exe
Removed File! : C:\Windows\System32\iekw.exe
Removed File! : C:\Windows\System32\iepb.exe
Removed File! : C:\Windows\System32\iepx32.exe
Removed File! : C:\Windows\System32\ieqf32.exe
Removed File! : C:\Windows\System32\ierx32.exe
Removed File! : C:\Windows\System32\ieyz.exe
Removed File! : C:\Windows\System32\iezg32.exe
Removed File! : C:\Windows\System32\ipdv32.exe
Removed File! : C:\Windows\System32\ipdw32.exe
Removed File! : C:\Windows\System32\ipdx32.exe
Removed File! : C:\Windows\System32\ipeo32.exe
Removed File! : C:\Windows\System32\ipgt.exe
Removed File! : C:\Windows\System32\ipgv32.exe
Removed File! : C:\Windows\System32\ipjq.exe
Removed File! : C:\Windows\System32\ipka.exe
Removed File! : C:\Windows\System32\ipky32.exe
Removed File! : C:\Windows\System32\ipmf.exe
Removed File! : C:\Windows\System32\ipml.exe
Removed File! : C:\Windows\System32\iptj32.exe
Removed File! : C:\Windows\System32\ipuu32.exe
Removed File! : C:\Windows\System32\ipxz.exe
Removed File! : C:\Windows\System32\ipyk.exe
Removed File! : C:\Windows\System32\ipzy.exe
Removed File! : C:\Windows\System32\javaaa.exe
Removed File! : C:\Windows\System32\javahf32.exe
Removed File! : C:\Windows\System32\javahy32.exe
Removed File! : C:\Windows\System32\javaiy.exe
Removed File! : C:\Windows\System32\javakw.exe
Removed File! : C:\Windows\System32\javalc32.exe
Removed File! : C:\Windows\System32\javalj.exe
Removed File! : C:\Windows\System32\javalt.exe
Removed File! : C:\Windows\System32\javamk.exe
Removed File! : C:\Windows\System32\javang32.exe
Removed File! : C:\Windows\System32\javann.exe
Removed File! : C:\Windows\System32\javatn.exe
Removed File! : C:\Windows\System32\javatz.exe
Removed File! : C:\Windows\System32\javauy32.exe
Removed File! : C:\Windows\System32\javazj32.exe
Removed File! : C:\Windows\System32\mfcbu32.exe
Removed File! : C:\Windows\System32\mfcff32.exe
Removed File! : C:\Windows\System32\mfcfj.exe
Removed File! : C:\Windows\System32\mfcgi32.exe
Removed File! : C:\Windows\System32\mfchz32.exe
Removed File! : C:\Windows\System32\mfciq32.exe
Removed File! : C:\Windows\System32\mfckc.exe
Removed File! : C:\Windows\System32\mfclo32.exe
Removed File! : C:\Windows\System32\mfcnf32.exe
Removed File! : C:\Windows\System32\mfcom32.exe
Removed File! : C:\Windows\System32\mfcov32.exe
Removed File! : C:\Windows\System32\mfcpg32.exe
Removed File! : C:\Windows\System32\mfcqb32.exe
Removed File! : C:\Windows\System32\mfcvk.exe
Removed File! : C:\Windows\System32\mfcvx.exe
Removed File! : C:\Windows\System32\mfcxb32.exe
Removed File! : C:\Windows\System32\mfcxc.exe
Removed File! : C:\Windows\System32\mfcya.exe
Removed File! : C:\Windows\System32\msck32.exe
Removed File! : C:\Windows\System32\msjr.exe
Removed File! : C:\Windows\System32\msna32.exe
Removed File! : C:\Windows\System32\msnv.exe
Removed File! : C:\Windows\System32\msnz32.exe
Removed File! : C:\Windows\System32\msqu.exe
Removed File! : C:\Windows\System32\msrs.exe
Removed File! : C:\Windows\System32\msun.exe
Removed File! : C:\Windows\System32\msxp32.exe
Removed File! : C:\Windows\System32\netce32.exe
Removed File! : C:\Windows\System32\netdl32.exe
Removed File! : C:\Windows\System32\netfa.exe
Removed File! : C:\Windows\System32\netgm32.exe
Removed File! : C:\Windows\System32\netiv.exe
Removed File! : C:\Windows\System32\netji.exe
Removed File! : C:\Windows\System32\netmn.dll
Removed File! : C:\Windows\System32\netqu32.exe
Removed File! : C:\Windows\System32\netsl32.exe
Removed File! : C:\Windows\System32\nettn32.exe
Removed File! : C:\Windows\System32\nettt32.exe
Removed File! : C:\Windows\System32\netub32.exe
Removed File! : C:\Windows\System32\netyc.exe
Removed File! : C:\Windows\System32\netyl32.exe
Removed File! : C:\Windows\System32\ntbo.exe
Removed File! : C:\Windows\System32\ntbw.exe
Removed File! : C:\Windows\System32\ntdx.exe
Removed File! : C:\Windows\System32\ntej.exe
Removed File! : C:\Windows\System32\ntgh.exe
Removed File! : C:\Windows\System32\ntjm32.exe
Removed File! : C:\Windows\System32\ntju32.exe
Removed File! : C:\Windows\System32\ntkr32.exe
Removed File! : C:\Windows\System32\ntlc.exe
Removed File! : C:\Windows\System32\ntlu32.exe
Removed File! : C:\Windows\System32\ntnd.exe
Removed File! : C:\Windows\System32\ntol32.exe
Removed File! : C:\Windows\System32\nttl.exe
Removed File! : C:\Windows\System32\ntus.exe
Removed File! : C:\Windows\System32\ntwi32.exe
Removed File! : C:\Windows\System32\ntzv.exe
Removed File! : C:\Windows\System32\sdkcd.exe
Removed File! : C:\Windows\System32\sdkdu32.exe
Removed File! : C:\Windows\System32\sdkep.exe
Removed File! : C:\Windows\System32\sdkhi.exe
Removed File! : C:\Windows\System32\sdkih.exe
Removed File! : C:\Windows\System32\sdkmo32.exe
Removed File! : C:\Windows\System32\sdkon.exe
Removed File! : C:\Windows\System32\sdkpp32.exe
Removed File! : C:\Windows\System32\sdkqg32.exe
Removed File! : C:\Windows\System32\sdkrs.exe
Removed File! : C:\Windows\System32\sdkyz32.exe
Removed File! : C:\Windows\System32\sdkze32.exe
Removed File! : C:\Windows\System32\sdkzj32.exe
Removed File! : C:\Windows\System32\sdkzk32.exe
Removed File! : C:\Windows\System32\sdkzo32.exe
Removed File! : C:\Windows\System32\sysgm32.exe
Removed File! : C:\Windows\System32\sysgr32.exe
Removed File! : C:\Windows\System32\syskt32.exe
Removed File! : C:\Windows\System32\sysmf.exe
Removed File! : C:\Windows\System32\sysro32.exe
Removed File! : C:\Windows\System32\sysuo.exe
Removed File! : C:\Windows\System32\syswo32.exe
Removed File! : C:\Windows\System32\sysxy.exe
Removed File! : C:\Windows\System32\wincs.exe
Removed File! : C:\Windows\System32\windp32.exe
Removed File! : C:\Windows\System32\windt.exe
Removed File! : C:\Windows\System32\winif32.exe
Removed File! : C:\Windows\System32\winja32.exe
Removed File! : C:\Windows\System32\winjk.exe
Removed File! : C:\Windows\System32\winoi32.exe
Removed File! : C:\Windows\System32\winsf32.exe
Removed File! : C:\Windows\System32\winuc32.exe
Removed File! : C:\Windows\System32\winwt32.exe
Removed File! : C:\Windows\System32\winyv.exe
————————————————
Scan was COMPLETED SUCCESSFULLY at 3:55:16 PM
The new Hijackthis log appears clean. :)
AboutBuster removed all of the other bad files. We list them just as a double check as it occasionally does not remove all of them on the first try.

Now to get your desktop back to normal.
Please RIGHT-CLICK: HERE and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then reboot the computer.

Let me know if you are now able to change the desktop back to what you had originally. Also, post a fresh HijackThis log so I can verify that it is still clean.

The dog looks awesome… what is he/she (I am guessing at least part lab?) Also, have to ask if you are a U of M fan or Michigan State fan… or neither?

She is all Mutt. :rofl: I would think there is some Black Lab in her also but her mom and dad are both mixed breeds. Still love her to death anyhow.
I don't really have a preference when it comes to the different universities as I'm not much of a sports fan. Are you from Michigan as well?
AWESOME :thumbup: … everything is perfect just in time for my friends return this evening; I can tell he and his wife that the computer is fixed! So, I was wondering about making a donation… do you know what amount people typically give and also can I specify you as the recipient? This is an amazing service for computer illiterate people such as myself, and I would love to see it grow.
There is definitely lab in your pup (my personal favorite), sounds like she has a good home as well. As far as sports, not a huge fan either… my dad and brother completed their Masters at U of M and my cousin just finished his Bachelors at Michigan State… I just enjoy the taunting between my dad and aunt.
Well, below is the final hijack log and hopefully everything is good to go. One last question, I am going to purchase a computer (a laptop and would like to spend about ~$1500) for myself here shortly, you have any recommendations as far as brands (Dell, Gateway, Sony, HP) /specifications (processor speed, hard drive size, RAM size) I should look for. Also, what basic security software do you think are must haves and/or the best ones to purchase? Alright, thank you again so much, this was great… nice to see some folks out there doing some good.

Respectfully,
Michael
:wavey:

Logfile of HijackThis v1.99.1
Scan saved at 3:41:23 PM, on 7/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8b5e9cdb91dddbb342695fbdc36fe0e4\update\update.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lee Gitschier\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Your welcome. It has been a pleasure helping you fix the computer.

So, I was wondering about making a donation… do you know what amount people typically give and also can I specify you as the recipient?

We helpers at TomCoyote volunteer our time to help others with their computer problems and are more than happy to do so without the expectation of anything in return. Donations can be sent to Tom to help pay for the cost of running the website. The link for this is found below in my Signature.

One last question, I am going to purchase a computer (a laptop and would like to spend about ~$1500) for myself here shortly, you have any recommendations as far as brands (Dell, Gateway, Sony, HP) /specifications (processor speed, hard drive size, RAM size) I should look for.

I would not be a very good person to ask this question as I paid way too much for the only computer I've ever purchased. You can post this question in the Other Computer Problems Forum and some of the other helpers may have a better idea for you.

Also, what basic security software do you think are must haves and/or the best ones to purchase?

I'll give you my normal all clean speech which has several programs to help keep the computer clean and a link to explain how to better secure the computer.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.


I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.
ZoneAlarm - Free firewall program if you currently are not using one.

Here are three very good and free malware scanners:

Spybot Search and Destroy 1.4
AdAware SE v1.06
Set-up Instructions for Spybot S&D and Adaware SE
a² Free Trojan Remover

If you have them already, check to make sure that they are the newest version.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI