This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PopUps, and Annoyances

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 11:56:31 AM, on 8/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\oep4fto5.exe
C:\WINDOWS\vdymzze.EXE
C:\Program Files\CMAPP\Client\cmappclient.exe
c:\windows\system32\lzxpoep.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\sbehpgm.exe
C:\PROGRA~1\MOZILL~1\firefox.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Chris & Jenn H\Desktop\HJT\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: VBRunDLL Class - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - C:\WINDOWS\System32\vbrundll.dll
O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\pbenjsuh.dll
O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [regsync] C:\WINDOWS\System32\regsync.exe
O4 - HKLM\..\Run: [oep4fto5] C:\WINDOWS\System32\oep4fto5.exe
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [ucgbqp25] C:\WINDOWS\System32\ucgbqp25.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [vdymzze] C:\WINDOWS\vdymzze.EXE
O4 - HKLM\..\Run: [pbgbww] c:\windows\system32\lzxpoep.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\sbehpgm.exe
Logfile of HijackThis v1.99.1
Scan saved at 1:07:58 PM, on 8/25/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\sbehpgm.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ucgbqp25.exe
C:\WINDOWS\vdymzze.EXE
C:\Program Files\CMAPP\Client\cmappclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\IceChat5\IceChat5.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Chris & Jenn H\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: VBRunDLL Class - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - C:\WINDOWS\System32\vbrundll.dll (file missing)
O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\pbenjsuh.dll
O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [regsync] C:\WINDOWS\System32\regsync.exe
O4 - HKLM\..\Run: [oep4fto5] C:\WINDOWS\System32\oep4fto5.exe
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [ucgbqp25] C:\WINDOWS\System32\ucgbqp25.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [vdymzze] C:\WINDOWS\vdymzze.EXE
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - (no file)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\sbehpgm.exe
Greetings and welcome to TomCoyote.org!

Please disable Teatimer, it can interfere with the cleaning process:

How to Disable Teatimer

After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - SOFTWARE - (no file)

O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: VBRunDLL Class - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - C:\WINDOWS\System32\vbrundll.dll (file missing)

O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\pbenjsuh.dll

O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - C:\PROGRA~1\Lycos\IEagent\IEagent.dll (file missing)

O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll

O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe

O4 - HKLM\..\Run: [regsync] C:\WINDOWS\System32\regsync.exe

O4 - HKLM\..\Run: [oep4fto5] C:\WINDOWS\System32\oep4fto5.exe

O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe

O4 - HKLM\..\Run: [ucgbqp25] C:\WINDOWS\System32\ucgbqp25.exe

O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe

O4 - HKLM\..\Run: [vdymzze] C:\WINDOWS\vdymzze.EXE

O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe

O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - (no file)

O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\sbehpgm.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column for:

Windows Overlay Components

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\sbehpgm.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\cmapp <— FOLDER

c:\windows\sbehpgm.exe <— file

c:\windows\system32\gah95on6.exe <— file

c:\windows\system32\lanbrup.exe <— file

c:\windows\system32\oep4fto5.exe <— file

c:\windows\system32\pbenjsuh.dll <— file

c:\windows\system32\regsync.exe <— file

c:\windows\system32\richedtr.dll <— file

c:\windows\system32\richup.exe <— file

c:\windows\system32\ucgbqp25.exe <— file

c:\windows\vdymzze.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
do not have run command on start button menu. used command prompt to open.
this program was stopped, and disabled when I opened the menu. C:\WINDOWS\sbehpgm.exe



did check show hidden files and folders in folder options.
applied to all folders.

not present c:\windows\sbehpgm.exe <— file

not present c:\windows\system32\gah95on6.exe <— file

not present c:\windows\system32\regsync.exe <— file

not present c:\windows\system32\richedtr.dll <— file

not present c:\windows\vdymzze.exe <— file

new log.


Logfile of HijackThis v1.99.1
Scan saved at 10:48:39 PM, on 9/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cvqraus.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\CJH\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [mckkff] C:\WINDOWS\System32\cvqraus.exe r
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
In the 3 weeks since your last post, you have developed more serious infections.
:(

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit ewido. DO NOT scan yet.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Download CleanUp
Install the program, dont run it yet, we will later.

Please download this file: Nailfix Utility
Save it to your desktop.
DO NOT run it yet.

Download dsrfix.zip
Save it to your desktop.
  • Unzip dsrfix.zip and extract it to your desktop.
  • This will create a new folder on your desktop named dsrfix.
  • Do Not open that folder yet.
Please download APT and unzip the contents to a new folder on your desktop.
  • Open the folder you just created and click on apt.exe and search in the window for C:\WINDOWS\System32\cvqraus.exe.
  • Open your C:\Windows\system32 folder and search for C:\WINDOWS\System32\cvqraus.exe.
    Don't delete it yet, just leave the system32 folder open so you can see the bad file.
  • In APT again, Select C:\WINDOWS\System32\cvqraus.exe and Click Kill3
  • Then immediately delete C:\WINDOWS\System32\cvqraus.exe from your system32 folder.
Close APT.

To reboot into SafeMode with Windows XP, you can follow these steps from Microsoft:

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, start tapping press F8 key.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on nailfix.exe.
Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish".
Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Now open ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Now scan with HJT and place a checkmark next to each of the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll

O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe

O4 - HKLM\..\Run: [mckkff] C:\WINDOWS\System32\cvqraus.exe r

O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

Close all open windows except for HJT, then click the Fix Checked button. Close HJT.

Now open the folder dsrfix on your desktop.
  • Double-Click on dsrfix.bat
  • A window will pop up briefly then close, this is normal.
Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK

Now using Windows Explorer find and remove the following folders/files

c:\windows\nail.exe <— file

c:\windows\dinst.exe <— file

c:\windows\dsr.dll <— file

c:\windows\svcproc.exe <— file

c:\windows\system32\cvqraus.exe <— file

Now run the CleanUp program:

*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Finally, restart your computer back into Normal Mode and please post a new HJT log, as well as the ewido report log from the Ewido scan by using Add Reply
the following were not present

C:\WINDOWS\System32\cvqraus.exe

O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll

O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe

O4 - HKLM\..\Run: [mckkff] C:\WINDOWS\System32\cvqraus.exe r

O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

c:\windows\nail.exe <— file

c:\windows\dinst.exe <— file

c:\windows\dsr.dll <— file

c:\windows\svcproc.exe <— file

c:\windows\system32\cvqraus.exe <— file

new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 12:45:09 PM, on 9/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\CJH\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


ewido log

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 12:33:15 PM, 9/14/2005
+ Report-Checksum: 840FB66C

+ Scan result:

HKLM\SOFTWARE\IEagent -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\143 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\206 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\339 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\348 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\387 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\675 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\757 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2 -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2\ppops -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-236263764-1417818515-3399203189-1006\Software\_rtneg2\ssites -> Spyware.Begin2Search : Cleaned with backup
[904] C:\WINDOWS\System32\gkfsse.exe -> Trojan.Agent.cp : Cleaned with backup
[1052] VM_012E0000 -> Adware.BetterInternet : Error during cleaning
:mozilla.27:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.52:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.69:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.70:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.71:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.72:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.74:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.91:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.92:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.93:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.106:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.121:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.122:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.137:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.148:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.153:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.154:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.156:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.159:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.160:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.161:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.162:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.164:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.165:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.166:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.167:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.168:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.169:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.172:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.173:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.174:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.175:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.176:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.178:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.197:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.198:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.204:C:\Documents and Settings\CJH\Application Data\Mozilla\Firefox\Profiles\v64cmaut.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\[removed][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@edge.ru4[2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\CJH@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\CJH\Cookies\[removed][2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\CJH\Desktop\HJT\backups\backup-20050913-222912-757.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\labpengs.tmp -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\Stb.exe -> TrojanDownloader.Agent.tf : Cleaned with backup
C:\Documents and Settings\CJH\Local Settings\Temp\thin-94-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\CMSystem\CMSystem.exe -> Spyware.CASClient : Cleaned with backup
C:\Program Files\CMSystem\plugin.dll -> Spyware.CASClient : Cleaned with backup
C:\Program Files\Netscape\Netscape 6\Plugins\npwthost.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\aigxgg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Buddy.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\offun.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\sbehpgm.exe -> TrojanDropper.Agent.tb : Cleaned with backup
C:\WINDOWS\system32\70tovmto.ini -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\system32\gkfsse.exe -> Trojan.Pakes : Cleaned with backup
C:\WINDOWS\system32\in4bdlA.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\msdioo.exe -> Trojan.Small.i : Cleaned with backup
C:\WINDOWS\system32\msfaol.dll -> Spyware.ClientMan : Cleaned with backup
C:\WINDOWS\system32\msnimk.gif -> Spyware.Ipend : Cleaned with backup
C:\WINDOWS\system32\nsaC3C.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\nsvB89.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\system32\redtrsha.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\wirelanb.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\System320nse12E0 -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\vdymzze.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\yxpwmjogek.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.18:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.32:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.33:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.40:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Linkbuddies : Cleaned with backup
:mozilla.41:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.42:F:\WINDOWS\Application Data\Mozilla\Firefox\Profiles\at42drs2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
F:\WINDOWS\Cookies\anyuser@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
G:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.RiskWare.Downloader.PopCap.a : Cleaned with backup
G:\Documents and Settings\Somer\Cookies\Somer@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
G:\Documents and Settings\Somer\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-37b2f810-3c9511aa.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
G:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
I:\Program Files\1stpage\IScripts\Buttons\Six buttons from hell.izs -> Trojan.Loop : Cleaned with backup
J:\current c compaq\Program Files\Evrsoft\1st Page 2000\IScripts\Buttons\Six buttons from hell.izs -> Trojan.Loop : Cleaned with backup


::Report End
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)

Then click "Fix checked" and close Hijack This!.

Reboot.

That should do it…. :thumbup:

How's it running? :unsure:

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Thank you very much. I've had many of my friends look at it, and one of them loaded HJT, took one look and said I needed to see the experts and sent me to this site. You guys really know your stuff. Thanks very much. The computer is actually responding faster than it's usual 'watching paint dry' response times.
I've had a popup on my computer, and when I boot all the stuff that I removed teatimer lets it reinstall everytime I boot up. I can't get into my yahoo mail, I could barely get into tom coyote, I had to log in three times just to add this reply.
here is my log.

Logfile of HijackThis v1.99.1
Scan saved at 1:21:33 PM, on 9/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
J:\PROGRA~1\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Common Files\AOL\ACS\acsd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Documents and Settings\CJH\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c;=2c02&lc;=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - (no file)
O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - (no file)
O2 - BHO: (no name) - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - (no file)
O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - (no file)
O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - (no file)
O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - (no file)
O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - (no file)
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {71D1708F-973D-4600-AF01-AD86688403AE} - (no file)
O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - (no file)
O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - (no file)
O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - (no file)
O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - (no file)
O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - (no file)
O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - (no file)
O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - (no file)
O2 - BHO: (no name) - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] J:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - J:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

I installed kerio personal firewall 4 and I kept getting this pop up for a dialup request, something about dialup number changed to 2.0.0.0 for a VPN, it was showing up every 15 seconds and was really pissing me off when I clicked no close connection it would be back in 15 seconds so I gave up and clicked yes, allow it. (just stop bugging ME!!!!)


please I have to get back into my email for business purposes, I'm lost without it.
Nothing major is visible in the log…..
:scratch:

Please disable Teatimer, it can interfere with the cleaning process:

How to Disable Teatimer

After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - SOFTWARE - (no file)

O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)

O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - (no file)

O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - (no file)

O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - (no file)

O2 - BHO: (no name) - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - (no file)

O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - (no file)

O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - (no file)

O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - (no file)

O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - (no file)

O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - (no file)

O2 - BHO: (no name) - {71D1708F-973D-4600-AF01-AD86688403AE} - (no file)

O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - (no file)

O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - (no file)

O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - (no file)

O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - (no file)

O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - (no file)

O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - (no file)

O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - (no file)

O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - (no file)

O2 - BHO: (no name) - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - (no file)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Run Ewido per previous instructions.

Reboot in normal mode and "copy/paste" a new Hijack This! log file,and the report.txt file from Ewido into this thread. :)
I know it looks the same, but I ran ewido, and deleted all that stuff in hjt with it being the only program open.
when I boot up, tea timer allows the installation of all the 02 line bho's again because it says it's on its white list.

Logfile of HijackThis v1.99.1
Scan saved at 5:39:07 PM, on 9/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
J:\Program Files\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris & Jenn Heckman\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - (no file)
O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - (no file)
O2 - BHO: (no name) - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - (no file)
O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - (no file)
O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - (no file)
O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - (no file)
O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - (no file)
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {71D1708F-973D-4600-AF01-AD86688403AE} - (no file)
O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - (no file)
O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - (no file)
O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - (no file)
O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - (no file)
O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - (no file)
O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - (no file)
O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - (no file)
O2 - BHO: (no name) - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] J:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - J:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
I don't think you're getting Teatimer "turned off".

Open Spybot S&D in advanced mode, click Tools –> Resident, and remove the check from "Resident Tea-Timer".

Reboot after unchecking the entry.

After the reboot, check in the right hand corner of the screen to see if the icon for Spybot resident is still there. If it is, click it and choose Exit.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - SOFTWARE - (no file)

O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)

O2 - BHO: (no name) - {011DD5C9-0331-40DC-9B70-50AC6503C109} - (no file)

O2 - BHO: (no name) - {11770B9A-DDC5-4A57-9895-626F028A7A7C} - (no file)

O2 - BHO: (no name) - {17C84130-6998-443F-BE32-C3DD64A9E25B} - (no file)

O2 - BHO: (no name) - {197B8CA4-E215-46DD-8F33-E0544A80E5C4} - (no file)

O2 - BHO: (no name) - {1DFDCD3B-B96E-49B7-A08D-F6CC79CF4BEC} - (no file)

O2 - BHO: (no name) - {1E84E19A-B124-4051-B4B4-886F4FBDCA0B} - (no file)

O2 - BHO: (no name) - {34233346-D37E-4D5D-9E0B-EF71F9338A0F} - (no file)

O2 - BHO: (no name) - {38B55545-211E-48CE-A8AB-1428A2856E83} - (no file)

O2 - BHO: (no name) - {5D5C2F72-9F09-4800-8DC5-96BBC0A1D641} - (no file)

O2 - BHO: (no name) - {71D1708F-973D-4600-AF01-AD86688403AE} - (no file)

O2 - BHO: (no name) - {79C17497-EE8B-4E74-9F58-D293FD62F0E4} - (no file)

O2 - BHO: (no name) - {87B1A096-3A77-46B0-B969-9240EAFDFD91} - (no file)

O2 - BHO: (no name) - {8BA67305-8C10-4A77-A9D0-589D8D31CFEE} - (no file)

O2 - BHO: (no name) - {A02D5F62-B22B-41F2-913E-A0F29304B259} - (no file)

O2 - BHO: (no name) - {AAAB4F0A-2D55-47A2-B22F-F7B906AF1B57} - (no file)

O2 - BHO: (no name) - {AD5F4A33-5088-4DD5-A8EB-80BFA1887FE4} - (no file)

O2 - BHO: (no name) - {E1B898A2-0868-42D2-BE77-A46162F37BDB} - (no file)

O2 - BHO: (no name) - {F63248AE-CE2B-434F-A0C0-5235DEFC750D} - (no file)

O2 - BHO: (no name) - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - (no file)

O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\cmapp <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
I have something called the best offers on my programs installed list… I tried to uninstall it, but when it ran, kerio said it launched a file called thunst.exe, and then it said I was getting attacked from the net. I've tried what you've offered, a few times since my last post, but i will try it one more time and get you some more logs. oh and I completely uninstalled firefox, and spybot S&D. I found adaware by lavasoft, as it had gone awol, ie is missing from my start menu, along with most of the applications that are supposed to be sitting in the programs folder on the start menu… firefox wouldn't let me log into yahoo, unless it was in a really good mood. but IE has no troubles getting into yahoo. one of my games I installed yesterday is all kinds of messed up, and so I uninstalled it too. and spybot was letting all those bhos install at each reboot. I'll go try this, post back in a bit.
I uninstalled tea timer and had deleted all the 02's again before I read your post. when I booted into safe mode, no 02's were present. also, the folder, with hidden files and folders shown, c:\program files\CMAPP does not exist, I do see the line in HJT that I fixed in safe mode has returned, the 04 that tells it to run. I cannot see the folder in normal windows mode either. perhaps it is hidden another way?


Logfile of HijackThis v1.99.1
Scan saved at 6:43:55 PM, on 9/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\RAM Idle\RAM_XP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
J:\Program Files\AIM\aim.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris & Jenn Heckman\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presario.net/scripts/redirect…&c=2c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle\RAM_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] J:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - J:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: Dice Derby by pogo - http://checkeredflag.pogo.com/applet/check…g-ob-assets.cab
O16 - DPF: Squelchies by pogo - http://squelchies.pogo.com/applet/squelchi…s-ob-assets.cab
O16 - DPF: {248DD896-BB45-11CF-9ABC-0080C7E7B78D} (Microsoft WinSock Control, version 6.0) - http://activex.microsoft.com/controls/vb6/MSWinSck.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Please don't run Hijack This! in "safe mode" unless instructed to do so.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\cmapp <— FOLDER
(If you can't find it - don't worry about it)

These are other files this malware may/may not have deposited on your machine:

c:\program files\asys\Stb.exe <— file

c:\program files\asys\VFX8.0-1.exe <— file

C:\WINDOWS\lupd.dat <— file

C:\WINDOWS\nxui.dat <— file

C:\WINDOWS\ofxnm.dat <— file

C:\WINDOWS\sfwv.dat <— file

C:\WINDOWS\sfxnm.dat <— file

C:\WINDOWS\tfxnm.dat <— file

C:\WINDOWS\tmpdlfl.dat <— file

C:\WINDOWS\uid24.key <— file

C:\WINDOWS\sysnet.exe <— file

C:\WINDOWS\snuninst.exe <— file

C:\WINDOWS\visfxun.exe <— file

C:\Documents and Settings\Chris & Jenn Heckman\Local Settings\Temp\cmappsetup.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI