This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pls help me!

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, can you help review my log file. I think I am being hi-jacked. For, some reason at start-up and closer their is a screen pop-up and it disappears before I can read it. :scratch:

Pls help and Tks
150747 (Michel)

Logfile of HijackThis v1.99.1
Scan saved at 09:56:38, on 2005-07-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\PopUpCop\PCCloser.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\a2\a2guard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michel\Mes documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Exploreur
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O8 - Extra context menu item: Surligner en Jaune - C:\WINDOWS\web\MarqueurFluoYellow.htm
O8 - Extra context menu item: Surligner en Rose - C:\WINDOWS\web\MarqueurFluoPink.htm
O8 - Extra context menu item: Surligner en Vert - C:\WINDOWS\web\MarqueurFluoGreen.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Bloc Notes - {AF4F850B-68FF-404C-8417-549F86B1E236} - notepad.exe (file missing)
O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote K - IE 6.htm (HKCU)
O9 - Extra button: Dictionnaire - {FB4AE6A3-EE20-442c-9189-251885352358} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote D - IE 6.htm (HKCU)
O9 - Extra button: Synonymes - {FDD637F8-2693-49ce-817E-1AD59574900C} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote S - IE 6.htm (HKCU)
O9 - Extra button: Conjugueur - {FF229BEC-9E1F-48c1-99A6-AF34ABEFAB0A} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote C - IE 6.htm (HKCU)
O9 - Extra button: Grammaire - {FFB5EE7F-726F-423e-83C2-572FE7CEB3F0} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote G - IE 6.htm (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120331218961
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.5.0_02) -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} (Java Plug-in 1.4.2_05) -
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe

TKS 150747 (Michel) :wavey:
Hello Michel and welcome to TomCoyote forum. If you are not being helped elsewhere and still need help, please do this in the posted order:

1) You have a New.Net hijacker at least, we will remove it and do a good check to make sure nothing else is lurking. I have not found anyone who downloaded this on purpose, if you did then stop and make me aware.
Follow these instructions to remove the hijacker: http://www.newdotnet.com/removal.html

2) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions on the download page and please do not run it until I ask you to.

3) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php Please do not activate TeaTimer until we are finished with the repair.

4) Ewido scan:
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

5) Run CCleaner but do not use the registry cleaner unless you backup the registry first as prompted for safety. Then restart the computer and post a new HJT log along with the Ewido scan results in this same thread and any feedback you have. Let us know how you are running. We may have more to do.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Well, finally finished all the scans.PROCEDURE 4 from newdotnet did the job.

Pls advise tks …

———————————————————
ewido security suite - Rapport de scan
———————————————————

+ Créé le: 09:06:50, 2005-08-01
+ Somme de contrôle: ECCDB5EB

+ Résultats du scan:

C:\CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Ignoré
C:\Documents and Settings\Administrateur\Cookies\administrateur@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Ignoré
E:\Nouveau dossierBACKUP\Bounce_Out_Blitz_v1[1].01 (www.crack.cd).zip/its.exe -> TrojanDownloader.INService.y : Ignoré
E:\Nouveau dossierBACKUP\CrackSearcher\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Ignoré
J:\CRACKSEARCHER.rar/CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Ignoré
L:\Downloads\Utilitaire\CRACKSEARCHER.rar/CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Ignoré=(Ignored)
M:\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Ignoré
M:\FTP CRACKS\FHCF_My_Personal_Diary_v8_build_1.1.0.zip/Loader.exe -> Not-A-Virus.VirTool.Patcher.a : Ignoré=ignored
C:\CRACKSEARCHER\Cracks\A\-\A-Squared2.zip/fff-a2-crk.exe -> Trojan.Small.cr : Erreur durant le nettoyage
C:\Documents and Settings\Françoise\Cookies\françoise@2o7[1].txt -> Spyware.Cookie.2o7 : Nettoyer et sauvegarder =(Cleaned and Saved)
C:\Documents and Settings\Françoise\Cookies\françoise@a.tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@advertising[1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@atdmt[2].txt -> Spyware.Cookie.Atdmt : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@bs.serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@ehg-yellowpages.hitbox[1].txt -> Spyware.Cookie.Hitbox : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@fastclick[2].txt -> Spyware.Cookie.Fastclick : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@fl01.ct2.comclick[1].txt -> Spyware.Cookie.Comclick : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@hitbox[2].txt -> Spyware.Cookie.Hitbox : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@revenue[2].txt -> Spyware.Cookie.Revenue : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@targetnet[1].txt -> Spyware.Cookie.Targetnet : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@www.smartadserver[2].txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
C:\Documents and Settings\Françoise\Cookies\françoise@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Nettoyer et sauvegarder
C:\Documents and Settings\Michel\Bureau\A-Squared2.zip/fff-a2-crk.exe -> Trojan.Small.cr : Nettoyer et sauvegarder
C:\Documents and Settings\Michel\Mes documents\uninstall6_76.exe -> Spyware.NewDotNet : Nettoyer et sauvegarder
C:\Program Files\Microsoft AntiSpyware\Quarantine\34B669C3-9C2F-4190-927E-C5D9D4\0F0E5BF4-B990-48B0-BE70-236847 -> Spyware.180Solutions : Nettoyer et sauvegarder
C:\Program Files\Microsoft AntiSpyware\Quarantine\34B669C3-9C2F-4190-927E-C5D9D4\F73C85BC-2470-4726-B986-27F983 -> Spyware.180Solutions : Nettoyer et sauvegarder
C:\RECYCLER\S-1-5-21-789336058-839522115-1343024091-1004\Dc5.exe -> TrojanDownloader.QDown.z : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@advertising[1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\[removed][2].txt -> Spyware.Cookie.Falkag : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@fastclick[1].txt -> Spyware.Cookie.Fastclick : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@gator[2].txt -> Spyware.Cookie.Gator : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\[removed][1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@spylog[1].txt -> Spyware.Cookie.Spylog : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\[removed][1].txt -> Spyware.Cookie.Onestat : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@trafic[1].txt -> Spyware.Cookie.Trafic : Nettoyer et sauvegarder
D:\Documents and Settings\Administrateur\Cookies\administrateur@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder
G:\Shared\Microsoft Picture It! Premium 10.zip/Setup.exe -> Worm.VB.an : Nettoyer et sauvegarder
L:\Bounce_Out_Blitz_v1[1].01 (www.crack.cd).zip/its.exe -> TrojanDownloader.INService.y : Nettoyer et sauvegarder
L:\Mes docs\FlashGet[1].v1.65.Incl.Keygen-SND.rar/FlashGet.v1.65.Incl.Keygen-SND\keygen.exe -> Heuristic.Win32.Morphine-Crypted : Nettoyer et sauvegarder
L:\Mes docs\n2k5kgpack.rar/Symantec.Norton.Internet.Security.2005.Keygen-SSG.exe -> TrojanDropper.Delf.fd : Nettoyer et sauvegarder
L:\SmartFTP_v1[1].0.983.20 (www.crack.cd).zip/isc.exe -> TrojanDownloader.INService.cx : Nettoyer et sauvegarder
M:\System Volume Information\_restore{44FE8EB8-F74C-4E46-8139-BB7CCD82B388}\RP215\A0043214.exe -> Spyware.Hijacker.Generic : Nettoyer et sauvegarder


::Fin du rapport
********************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 09:43:10, on 2005-08-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Symantec\DelFax\WFXMOD32.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Exploreur
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\PROGRA~1\PopUpCop\popupcop.dll/imagenew
O8 - Extra context menu item: Surligner en Jaune - C:\WINDOWS\web\MarqueurFluoYellow.htm
O8 - Extra context menu item: Surligner en Rose - C:\WINDOWS\web\MarqueurFluoPink.htm
O8 - Extra context menu item: Surligner en Vert - C:\WINDOWS\web\MarqueurFluoGreen.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Bloc Notes - {AF4F850B-68FF-404C-8417-549F86B1E236} - notepad.exe (file missing)
O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote K - IE 6.htm (HKCU)
O9 - Extra button: Dictionnaire - {FB4AE6A3-EE20-442c-9189-251885352358} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote D - IE 6.htm (HKCU)
O9 - Extra button: Synonymes - {FDD637F8-2693-49ce-817E-1AD59574900C} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote S - IE 6.htm (HKCU)
O9 - Extra button: Conjugueur - {FF229BEC-9E1F-48c1-99A6-AF34ABEFAB0A} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote C - IE 6.htm (HKCU)
O9 - Extra button: Grammaire - {FFB5EE7F-726F-423e-83C2-572FE7CEB3F0} - C:\PROGRA~1\Druide\Antidote\Antidote\Internet Explorer\6\Antidote G - IE 6.htm (HKCU)
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} (Java Plug-in 1.4.2_05) -
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: DelrinaFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE

(Run ok now faster and no popup at starting,but still have one at the closing of Windows . No problem with that one)
Hello Michel, Let me first say that your HJT log is clean. I am concerning by the results with the Ewido scan, some of the items it choose to ignore. What language is this? French? I would like to pursue this a litttle further but you can call off the hunt at any point. You said this:

but still have one at the closing of Windows . No problem with that one)

We should have no popups, would you please describe this one. Some popups will get through when you visit legitimate sites, do you have a popup blocker onboard to stop these. If you don't, I suggest the Google toolbar and popup blocker. If you try this I do not suggest you download more than the basic toolbar/blocker. They offer a lot of other stuff that is just a waste of resources. The toolbar will give you a great search engine and popup blocker and that is really all you should need. You can look at this software here: http://toolbar.google.com/

The Ewido scan…I would consider running that scan in safe mode to see if you can get a clean scan result. Here are instructions for entering safe mode: http://www.bleepingcomputer.com/forums/tutorial61.html Before you run I would clean out all of the cookies showing in the old log unless CCleaner got them for you. Here is some information to help you get better control over cookies: http://support.microsoft.com/default.aspx?…b;EN-US;q283185

I have another free scan I just started trying on my computer. It took me about 30 minutes and did find a few things Ewido missed. It is free to use the scan if you like: http://www.securemywindows.com/

I did see at least one item in System Restore so I would purge thoses files before running any scans also:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam that information will turn off then back on System Restore giving you all clean files.

Since you log is clean: Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

I will leave your thread open for a few days in case you have a question or wish to post any of the scan logs for me to review.

Safe surfing…Phil

Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Hi pskelley! Yes the language is French and will try to get more info on the closing notice window. Will do as you want and will try to translate the Ewido scan log file for you at the same time. A big tks for your help :thumbup: 150747 (Michel)
Hello pskelley!
The problem is fix it was USRprdbA.exe, myUSRobotic modem, by deactivated the modem it fix the problem. No more window at shutting down.

Yes i do have popup bloker (PopUpCop) updated.

********************************************************************

ewido security suite - Rapport de scan (Scan result in SAFE MODE,
System Restore Off
)
———————————————————

+ Créé le: 19:40:03, 2005-08-02
+ Somme de contrôle:(CRC) 818C856A

+ Résultats du scan: (Scan result)

C:\CRACKSEARCHER\Cracks\A\-\A-Squared2.zip/fff-a2-crk.exe -> Trojan.Small.cr : Nettoyer et sauvegarder (DELETED)
C:\CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Administrateur\Cookies\administrateur@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@a.tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@ads.addynamix[2].txt -> Spyware.Cookie.Addynamix : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@advertising[2].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@atdmt[2].txt -> Spyware.Cookie.Atdmt : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@bs.serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@fastclick[2].txt -> Spyware.Cookie.Fastclick : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@servedby.advertising[2].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@targetnet[2].txt -> Spyware.Cookie.Targetnet : Nettoyer et sauvegarder (DELETED)
C:\Documents and Settings\Françoise\Cookies\françoise@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder (DELETED)
E:\Nouveau dossierBACKUP\Bounce_Out_Blitz_v1[1].01 (www.crack.cd).zip/its.exe -> TrojanDownloader.INService.y : Nettoyer et sauvegarder (DELETED)
E:\Nouveau dossierBACKUP\CrackSearcher\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Nettoyer et sauvegarder (DELETED)
J:\CRACKSEARCHER.rar/CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Nettoyer et sauvegarder (DELETED)
L:\Downloads\Utilitaire\CRACKSEARCHER.rar/CRACKSEARCHER\CRACKSEARCHER.EXE -> Not-A-Virus.HackTool.CrackSearch.a : Nettoyer et sauvegarder (DELETED)


::Fin du rapport (END OF REPORT)
********************************************************************

Scan Report Details (Garbage Scan)

Scan Date: 8/2/2005 3:24:15 PM
Computer name: M-J5WM98PQNLT6W
Garbage files :
\system32\3rdpvqj0.dat
\system32\tn88uc5v.dat
Garbage Registry items:
HKEY_CLASSES_ROOT\AppID\MediaGateway.EXE
Garbage Browser cookies:
administrator@tickle[1].txt (All deleted)
********************************************************************

Tks pskelley and long live to The Team and forum :thumbup:

pls adv… and forgive me for my bad spelling (I am French… ;-) )

150747 (Michel)
lol michel, I use spellcheck often when typing in English. Looks like the scans did the job. Make very sure your System Restore is turned back on. Thanks for trying out the Garbage Scan, it's data base did locate a few items missed by Ewido. :)

Bonne chance à vous et à surfer sûr

Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI