This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Startup & internet explorer extremely slow

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Daughter is college student. Laptop slow on startup. Main problem is internet explorer is EXTREMELY slow - to the point of being unusable. She has been using firefox instead. She is about to return to college & I would like to fix this before she goes back. Ran adware & spybot (which she does regularly), no change.

Here is her hijackthis log and THANKS,

Danny Cagle


Scan saved at 12:37:40 PM, on 8/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\SARAH\keep\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - C:\WINDOWS\system32\jjqfrbdp.dll
O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - C:\WINDOWS\system32\mmlvpzqv.dll
O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - C:\WINDOWS\System32\axdqwwik.dll
O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - C:\WINDOWS\system32\ufvxqnhu.dll (file missing)
O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - C:\WINDOWS\system32\kdyttxnp.dll
O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - C:\WINDOWS\System32\yimfsblg.dll
O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - C:\WINDOWS\system32\pxnbhrif.dll
O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - C:\WINDOWS\system32\agglvdfb.dll
O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - C:\WINDOWS\system32\abgmoyxh.dll
O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - C:\WINDOWS\system32\mjbnryzg.dll (file missing)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174>
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing
O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscri] c:\WINDOWS\System32\[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscript">
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.c] c:\WINDOWS\System32\[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.com">
O4 - HKLM\..\Run: [
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [fdxbkjau] C:\WINDOWS\system32\fdxbkjau.exe
O4 - HKLM\..\Run: [zieckhvk] C:\WINDOWS\system32\zieckhvk.exe
O4 - HKLM\..\Run: [zmpiapgt] C:\WINDOWS\system32\zmpiapgt.exe
O4 - HKLM\..\Run: [vizekxtn] C:\WINDOWS\system32\vizekxtn.exe
O4 - HKLM\..\Run: [piulyfkp] C:\WINDOWS\system32\piulyfkp.exe
O4 - HKLM\..\Run: [bxotlhdo] C:\WINDOWS\system32\bxotlhdo.exe
O4 - HKLM\..\Run: [xwshvioy] C:\WINDOWS\system32\xwshvioy.exe
O4 - HKLM\..\Run: [ljizifmt] C:\WINDOWS\system32\ljizifmt.exe
O4 - HKLM\..\Run: [iexztlgn] C:\WINDOWS\system32\iexztlgn.exe
O4 - HKLM\..\Run: [auksfnhn] C:\WINDOWS\system32\auksfnhn.exe
O4 - HKLM\..\Run: [wwduqquv] C:\WINDOWS\system32\wwduqquv.exe
O4 - HKLM\..\Run: [tjtwwzqu] C:\WINDOWS\system32\tjtwwzqu.exe
O4 - HKLM\..\Run: [gudsypvj] C:\WINDOWS\system32\gudsypvj.exe
O4 - HKLM\..\Run: [bfkuupmq] C:\WINDOWS\system32\bfkuupmq.exe
O4 - HKLM\..\Run: [xepvulwb] C:\WINDOWS\system32\xepvulwb.exe
O4 - HKLM\..\Run: [qxcahhfb] C:\WINDOWS\system32\qxcahhfb.exe
O4 - HKLM\..\Run: [qalupsej] C:\WINDOWS\system32\qalupsej.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174>
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing
O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscri] c:\WINDOWS\System32\[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscript">
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.c] c:\WINDOWS\System32\[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.com">
O4 - HKCU\..\Run: [
O4 - HKCU\..\Run: [Cuckoo Clock] "C:\PROGRA~1\HARRYP~1\Cuckoo.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} (WTDMMPVersion Class) - http://install.wildtangent.com/bgn/partner…lim/install.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1435/ftp…22/cpbrkpie.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: nnjqlecxboxg (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Looks like you've been invaded by a hijacker that got an "F" in programming….
:rofl:

Fix these with Hijack This! and post a new log file, in this thread.

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174>

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts

O4 - HKLM\..\Run: [ onMouseover="this.style.backgroundColor='#CCCCCC'" onMouseout="this.style.backgroundColor='#F4F6F8'">[image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing

O4 - HKLM\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies

O4 - HKLM\..\Run: [

O4 - HKLM\..\Run: [

O4 - HKLM\..\Run: [

O4 - HKLM\..\Run: [[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscri] c:\WINDOWS\System32\[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscript">

O4 - HKLM\..\Run: [

O4 - HKLM\..\Run: [

O4 - HKLM\..\Run: [[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.c] c:\WINDOWS\System32\[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.com">

O4 - HKLM\..\Run: [

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=finance&host=beneditutti.com&side=1" class=category>Finance

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174><] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/spacer.gif" height=1 width=174>

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=travel&host=beneditutti.com&side=1" class="category">Travel

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=gift&host=beneditutti.com&side=1" class=category>Gifts

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=home&host=beneditutti.com&side=1" class=category>Home

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=health&host=beneditutti.com&side=1" class=category>Health

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=entertainment&host=beneditutti.com&side=1" class=category>Entertainment

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=shopping&host=beneditutti.com&side=1" class=category>Shopping

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=computing&host=beneditutti.com&side=1" class=category>Computing

O4 - HKCU\..\Run: [ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies<] c:\WINDOWS\System32\ [image unavailable: image]http://parked.directnic.com/images/arrow.gif" width=4 height=7 hspace=12 vspace=7 align=absmiddle>http://parked.directnic.com/result.php?Keywords=hobby&host=beneditutti.com&side=1" class=category>Hobbies

O4 - HKCU\..\Run: [

O4 - HKCU\..\Run: [

O4 - HKCU\..\Run: [

O4 - HKCU\..\Run: [[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscri] c:\WINDOWS\System32\[image unavailable: image]http://stats.directnic.com/tracker.php?a=noscript">

O4 - HKCU\..\Run: [

O4 - HKCU\..\Run: [

O4 - HKCU\..\Run: [[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.c] c:\WINDOWS\System32\[image unavailable: image]http://parked.directnic.com/tiger.php?host=beneditutti.com">

O4 - HKCU\..\Run: [
Thanks for the fast reply. I fixed the indicated items and rebooted. Here is the new hijackthis log.

Danny

Logfile of HijackThis v1.99.1
Scan saved at 3:03:55 PM, on 8/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\SARAH\keep\HijackThis\HijackThis.exe
C:\SARAH\keep\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - C:\WINDOWS\system32\jjqfrbdp.dll
O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - C:\WINDOWS\system32\mmlvpzqv.dll
O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - C:\WINDOWS\System32\axdqwwik.dll
O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - C:\WINDOWS\system32\ufvxqnhu.dll (file missing)
O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - C:\WINDOWS\system32\kdyttxnp.dll
O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - C:\WINDOWS\System32\yimfsblg.dll
O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - C:\WINDOWS\system32\pxnbhrif.dll
O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - C:\WINDOWS\system32\agglvdfb.dll
O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - C:\WINDOWS\system32\abgmoyxh.dll
O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - C:\WINDOWS\system32\mjbnryzg.dll (file missing)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [fdxbkjau] C:\WINDOWS\system32\fdxbkjau.exe
O4 - HKLM\..\Run: [zieckhvk] C:\WINDOWS\system32\zieckhvk.exe
O4 - HKLM\..\Run: [zmpiapgt] C:\WINDOWS\system32\zmpiapgt.exe
O4 - HKLM\..\Run: [vizekxtn] C:\WINDOWS\system32\vizekxtn.exe
O4 - HKLM\..\Run: [piulyfkp] C:\WINDOWS\system32\piulyfkp.exe
O4 - HKLM\..\Run: [bxotlhdo] C:\WINDOWS\system32\bxotlhdo.exe
O4 - HKLM\..\Run: [xwshvioy] C:\WINDOWS\system32\xwshvioy.exe
O4 - HKLM\..\Run: [ljizifmt] C:\WINDOWS\system32\ljizifmt.exe
O4 - HKLM\..\Run: [iexztlgn] C:\WINDOWS\system32\iexztlgn.exe
O4 - HKLM\..\Run: [auksfnhn] C:\WINDOWS\system32\auksfnhn.exe
O4 - HKLM\..\Run: [wwduqquv] C:\WINDOWS\system32\wwduqquv.exe
O4 - HKLM\..\Run: [tjtwwzqu] C:\WINDOWS\system32\tjtwwzqu.exe
O4 - HKLM\..\Run: [gudsypvj] C:\WINDOWS\system32\gudsypvj.exe
O4 - HKLM\..\Run: [bfkuupmq] C:\WINDOWS\system32\bfkuupmq.exe
O4 - HKLM\..\Run: [xepvulwb] C:\WINDOWS\system32\xepvulwb.exe
O4 - HKLM\..\Run: [qxcahhfb] C:\WINDOWS\system32\qxcahhfb.exe
O4 - HKLM\..\Run: [qalupsej] C:\WINDOWS\system32\qalupsej.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Cuckoo Clock] "C:\PROGRA~1\HARRYP~1\Cuckoo.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: nnjqlecxboxg (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)

O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - C:\WINDOWS\system32\jjqfrbdp.dll

O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - C:\WINDOWS\system32\mmlvpzqv.dll

O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - C:\WINDOWS\System32\axdqwwik.dll

O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - C:\WINDOWS\system32\ufvxqnhu.dll (file missing)

O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - C:\WINDOWS\system32\kdyttxnp.dll

O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - C:\WINDOWS\System32\yimfsblg.dll

O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - C:\WINDOWS\system32\pxnbhrif.dll

O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - C:\WINDOWS\system32\agglvdfb.dll

O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - C:\WINDOWS\system32\abgmoyxh.dll

O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - C:\WINDOWS\system32\mjbnryzg.dll (file missing)

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - (no file)

O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)

O4 - HKLM\..\Run: [fdxbkjau] C:\WINDOWS\system32\fdxbkjau.exe

O4 - HKLM\..\Run: [zieckhvk] C:\WINDOWS\system32\zieckhvk.exe

O4 - HKLM\..\Run: [zmpiapgt] C:\WINDOWS\system32\zmpiapgt.exe

O4 - HKLM\..\Run: [vizekxtn] C:\WINDOWS\system32\vizekxtn.exe

O4 - HKLM\..\Run: [piulyfkp] C:\WINDOWS\system32\piulyfkp.exe

O4 - HKLM\..\Run: [bxotlhdo] C:\WINDOWS\system32\bxotlhdo.exe

O4 - HKLM\..\Run: [xwshvioy] C:\WINDOWS\system32\xwshvioy.exe

O4 - HKLM\..\Run: [ljizifmt] C:\WINDOWS\system32\ljizifmt.exe

O4 - HKLM\..\Run: [iexztlgn] C:\WINDOWS\system32\iexztlgn.exe

O4 - HKLM\..\Run: [auksfnhn] C:\WINDOWS\system32\auksfnhn.exe

O4 - HKLM\..\Run: [wwduqquv] C:\WINDOWS\system32\wwduqquv.exe

O4 - HKLM\..\Run: [tjtwwzqu] C:\WINDOWS\system32\tjtwwzqu.exe

O4 - HKLM\..\Run: [gudsypvj] C:\WINDOWS\system32\gudsypvj.exe

O4 - HKLM\..\Run: [bfkuupmq] C:\WINDOWS\system32\bfkuupmq.exe

O4 - HKLM\..\Run: [xepvulwb] C:\WINDOWS\system32\xepvulwb.exe

O4 - HKLM\..\Run: [qxcahhfb] C:\WINDOWS\system32\qxcahhfb.exe

O4 - HKLM\..\Run: [qalupsej] C:\WINDOWS\system32\qalupsej.exe

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of these noted file(s)/FOLDER(s) you can find:

c:\windows\system32\abgmoyxh.dll <— file

c:\windows\system32\agglvdfb.dll <— file

c:\windows\system32\auksfnhn.exe <— file

c:\windows\system32\axdqwwik.dll <— file

c:\windows\system32\bfkuupmq.exe <— file

c:\windows\system32\bxotlhdo.exe <— file

c:\windows\system32\fdxbkjau.exe <— file

c:\windows\system32\gudsypvj.exe <— file

c:\windows\system32\iexztlgn.exe <— file

c:\windows\system32\jjqfrbdp.dll <— file

c:\windows\system32\kdyttxnp.dll <— file

c:\windows\system32\ljizifmt.exe <— file

c:\windows\system32\mmlvpzqv.dll <— file

c:\windows\system32\piulyfkp.exe <— file

c:\windows\system32\pxnbhrif.dll <— file

c:\windows\system32\qalupsej.exe <— file

c:\windows\system32\qxcahhfb.exe <— file

c:\windows\system32\tjtwwzqu.exe <— file

c:\windows\system32\vizekxtn.exe <— file

c:\windows\system32\wwduqquv.exe <— file

c:\windows\system32\xepvulwb.exe <— file

c:\windows\system32\xwshvioy.exe <— file

c:\windows\system32\yimfsblg.dll <— file

c:\windows\system32\zieckhvk.exe <— file

c:\windows\system32\zmpiapgt.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Done. I couldn't find about 8 of the .dll files. Things are getting much faster. I should also note she gets this message at startup could not find c:\program\wildtangent\apps\cda\cdaengine0400.dll.

Here is the new log.

Thanks!

Danny

Logfile of HijackThis v1.99.1
Scan saved at 3:46:15 PM, on 8/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\SARAH\keep\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - (no file)
O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - (no file)
O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - (no file)
O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - (no file)
O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - (no file)
O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - (no file)
O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - (no file)
O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - (no file)
O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - (no file)
O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\$NtServicePackUninstall$\msconfig.exe /auto
O4 - HKCU\..\Run: [Cuckoo Clock] "C:\PROGRA~1\HARRYP~1\Cuckoo.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: nnjqlecxboxg (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Boot in "safe" mode FIRST.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)

O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - (no file)

O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - (no file)

O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - (no file)

O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - (no file)

O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - (no file)

O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - (no file)

O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - (no file)

O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - (no file)

O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - (no file)

O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - (no file)

O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
(Fixing this should stop the error at bootup)

Then click "Fix checked" and close Hijack This!.

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Better & better. New log:

Logfile of HijackThis v1.99.1
Scan saved at 4:15:54 PM, on 8/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\SARAH\keep\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - (no file)
O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - (no file)
O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - (no file)
O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - (no file)
O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - (no file)
O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - (no file)
O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - (no file)
O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - (no file)
O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - (no file)
O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Cuckoo Clock] "C:\PROGRA~1\HARRYP~1\Cuckoo.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: nnjqlecxboxg (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
That's about as good as it get's without some more "help".

A couple of things.

Your Wild Tangent software has been corrupted.

Go to:

Start –> Control Panel –> Add/Remove Programs

And remove:

Wild Tangent

Then reboot to complete the uninstall.

It is required for some online games, so you will have to download/install it again to play those games.

On a side note, it is considered to be "spyware" in some circles.

But, if you want to play the games that it requires, I guess you'll just have to live with that fact.

And to remove these entries:

O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: (no name) - {06C4EA18-2EE4-1588-D817-79B28393A214} - (no file)
O2 - BHO: (no name) - {21BCD943-C6AE-D46B-5CC3-9239CFE10D01} - (no file)
O2 - BHO: (no name) - {25DFF48A-9B42-A2B0-288F-A79FAF955ABF} - (no file)
O2 - BHO: (no name) - {39A84F80-0000-0000-0500-000000000000} - (no file)
O2 - BHO: (no name) - {5685C933-03A7-9893-400B-8844C758C9F6} - (no file)
O2 - BHO: (no name) - {574AE9EE-0DD9-C496-118E-D08DF716248B} - (no file)
O2 - BHO: (no name) - {60A0456F-1712-5B69-0785-C0F99397EE82} - (no file)
O2 - BHO: (no name) - {C033F4F7-160C-30F4-FEE3-C94545B4082A} - (no file)
O2 - BHO: (no name) - {C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192} - (no file)
O2 - BHO: (no name) - {E0B3F90B-14D1-9217-5325-B3FA18C8B36C} - (no file)

You'll need to download at least one program (maybe 2) to help.

Since it says (no file), the infection is gone, we would just be cleaning up "orphaned" entries in the registry.

Hijack This! isn't working on these.

Let me know if you want to remove them.

If you have the time (and patience) I recommend doing at least one (the first) of these online virus scans to check for things not detected by Hijack This!:

Trend-Micro Housecall

Panda Activescan

Etrust Security Advisor

Bitdefender

Choose "fix" or "clean".

Let them remove any infections found. Reboot after each scan.

Advise me of any infections found but not "cleaned" or removed.

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

I've got trend micro running now. Could be a while. I appreciate your help and will check out your suggestions (not just for my daughter's computer - but for the three I have at home). I may not post any further results today. Thanks for all your help. Danny
OKIE DOKIE. :thumbup:

If you feel comfortable, and know what you're doing, you can remove those orphaned entries with regedit.

If you want to pursue removing them "my way", please do this:

Please download/unzip this:

RegScan.vbs

on Regscan.vbs, and search for these items (one at a time):

{00000000-0000-0000-0000-000000000000}

{06C4EA18-2EE4-1588-D817-79B28393A214}

{21BCD943-C6AE-D46B-5CC3-9239CFE10D01}

{25DFF48A-9B42-A2B0-288F-A79FAF955ABF}

{39A84F80-0000-0000-0500-000000000000}

{5685C933-03A7-9893-400B-8844C758C9F6}

{574AE9EE-0DD9-C496-118E-D08DF716248B}

{60A0456F-1712-5B69-0785-C0F99397EE82}

{C033F4F7-160C-30F4-FEE3-C94545B4082A}

{C5E07EEB-5C82-0E0B-2E56-4B71BF5E4192}

{E0B3F90B-14D1-9217-5325-B3FA18C8B36C}

Paste the contents of the search results into your next post.
:)
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI