This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

More info Repeating StartPage-DU

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a Hijackthis.log re-posting from earlier today with more info of my problems. McAfee finds the trojan file named jnvdk.dll (id a StartPage-DU trojan) every time I launch internet explorer although McAfee can NOT clean or delete this file so it returns every time I launch internet explorer. Either McAfee or the virus terminates internet explorer every time its opened. This trojan seems to create many other issues including New PolyWin32 virus, Malware trojans, many pop-ups, and hal.dll issues with windows. McAfee support tells me their program will fix these issues, but this is not the case. I have the latest McAfee updates and I have also run Adware SE and Spybot, which find and remove some problems but they do not stop the jnvdk.dll from returning. The Hijackthis.log identifies the jnvdk.dll in lines R1. Can I fix these items with Hijackthis? Can I remove/fix any other lines which may be contributing to the above problems? Please help.

:blink:


Re-posting Hijackthis.log below:

Logfile of HijackThis v1.99.1
Scan saved at 12:29:29 PM, on 9/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\HiJackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jnvdk.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jnvdk.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jnvdk.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jnvdk.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Class - {F6EE5F6F-2DB0-5CE5-4CBE-0DB05DBFBB07} - C:\WINDOWS\system32\apiqn32.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [ntvt32.exe] C:\WINDOWS\ntvt32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8…pdatePortal.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InterPlot IMF Printer Driver Service - Unknown owner - C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
Hello dsaltlandhelp, welcome to the forum

Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet)

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above starting with Reboot in Safe Mode.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
LDTate-

Thanks for your reply. I ran the SpSeHjfix a few times and it never re-boot upon completion. I read the log produced by this scan and it repeats that it ended without reboot and it identifies the same file McAfee finds (but can not eliminate) named jnvdk.dll. I also ran CWShredder (rebooted) and then HJT. See logs for SpSeHjfix and HJT below.



SpSeHjfix Log:


(9/9/05 9:13:55 PM) SPSeHjFix started v1.1.2
(9/9/05 9:13:55 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 9:13:55 PM) Language: english
(9/9/05 9:13:55 PM) Win-Path: C:\WINDOWS
(9/9/05 9:13:55 PM) System-Path: C:\WINDOWS\system32
(9/9/05 9:13:55 PM) Temp-Path: C:\DOCUME~1\DREWAL~1\LOCALS~1\Temp\
(9/9/05 9:13:56 PM) Disinfection started
(9/9/05 9:13:56 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:13:56 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:13:57 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:13:57 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\system32\jnvdk.dll/sp.html#37049
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\system32\jnvdk.dll/sp.html#37049
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(9/9/05 9:13:57 PM) Stealth-String not found
(9/9/05 9:13:57 PM) No locked Files to delete. End without Reboot
(9/9/05 9:14:14 PM) Disinfection started
(9/9/05 9:14:14 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:14:14 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:14 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:14 PM) Bad IE-pages: (none)
(9/9/05 9:14:14 PM) Stealth-String not found
(9/9/05 9:14:14 PM) No locked Files to delete. End without Reboot
(9/9/05 9:14:23 PM) Disinfection started
(9/9/05 9:14:23 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:14:23 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:23 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:23 PM) Bad IE-pages: (none)
(9/9/05 9:14:23 PM) Stealth-String not found
(9/9/05 9:14:23 PM) No locked Files to delete. End without Reboot
(9/9/05 9:14:48 PM) Disinfection started
(9/9/05 9:14:48 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:14:48 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:48 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:48 PM) Bad IE-pages: (none)
(9/9/05 9:14:48 PM) Stealth-String not found
(9/9/05 9:14:48 PM) No locked Files to delete. End without Reboot
(9/9/05 9:14:49 PM) Disinfection started
(9/9/05 9:14:49 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:14:49 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:49 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:49 PM) Bad IE-pages: (none)
(9/9/05 9:14:49 PM) Stealth-String not found
(9/9/05 9:14:49 PM) No locked Files to delete. End without Reboot
(9/9/05 9:14:57 PM) Disinfection started
(9/9/05 9:14:57 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:14:57 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:57 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:14:57 PM) Bad IE-pages: (none)
(9/9/05 9:14:57 PM) Stealth-String not found
(9/9/05 9:14:57 PM) No locked Files to delete. End without Reboot
(9/9/05 9:15:53 PM) Disinfection started
(9/9/05 9:15:53 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:15:53 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:15:53 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:15:53 PM) Bad IE-pages: (none)
(9/9/05 9:15:53 PM) Stealth-String not found
(9/9/05 9:15:53 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:00 PM) Disinfection started
(9/9/05 9:16:00 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:00 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:00 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:00 PM) Bad IE-pages: (none)
(9/9/05 9:16:00 PM) Stealth-String not found
(9/9/05 9:16:00 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:02 PM) Disinfection started
(9/9/05 9:16:02 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:02 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:02 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:02 PM) Bad IE-pages: (none)
(9/9/05 9:16:02 PM) Stealth-String not found
(9/9/05 9:16:02 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:03 PM) Disinfection started
(9/9/05 9:16:03 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:03 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:03 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:03 PM) Bad IE-pages: (none)
(9/9/05 9:16:03 PM) Stealth-String not found
(9/9/05 9:16:03 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:04 PM) Disinfection started
(9/9/05 9:16:04 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) Bad IE-pages: (none)
(9/9/05 9:16:04 PM) Stealth-String not found
(9/9/05 9:16:04 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:04 PM) Disinfection started
(9/9/05 9:16:04 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) Bad IE-pages: (none)
(9/9/05 9:16:04 PM) Stealth-String not found
(9/9/05 9:16:04 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:04 PM) Disinfection started
(9/9/05 9:16:04 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:04 PM) Bad IE-pages: (none)
(9/9/05 9:16:04 PM) Stealth-String not found
(9/9/05 9:16:04 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:06 PM) Disinfection started
(9/9/05 9:16:06 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:06 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:06 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:06 PM) Bad IE-pages: (none)
(9/9/05 9:16:06 PM) Stealth-String not found
(9/9/05 9:16:06 PM) No locked Files to delete. End without Reboot
(9/9/05 9:16:32 PM) Disinfection started
(9/9/05 9:16:32 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:16:32 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:32 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:16:32 PM) Bad IE-pages: (none)
(9/9/05 9:16:32 PM) Stealth-String not found
(9/9/05 9:16:32 PM) No locked Files to delete. End without Reboot
(9/9/05 9:38:12 PM) Disinfection started
(9/9/05 9:38:12 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:38:12 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:12 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:12 PM) Bad IE-pages: (none)
(9/9/05 9:38:12 PM) Stealth-String not found
(9/9/05 9:38:12 PM) No locked Files to delete. End without Reboot
(9/9/05 9:38:18 PM) Disinfection started
(9/9/05 9:38:18 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:38:18 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:18 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:18 PM) Bad IE-pages: (none)
(9/9/05 9:38:18 PM) Stealth-String not found
(9/9/05 9:38:18 PM) No locked Files to delete. End without Reboot
(9/9/05 9:38:35 PM) Disinfection started
(9/9/05 9:38:35 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:38:35 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:35 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:35 PM) Bad IE-pages: (none)
(9/9/05 9:38:35 PM) Stealth-String not found
(9/9/05 9:38:35 PM) No locked Files to delete. End without Reboot
(9/9/05 9:38:39 PM) Disinfection started
(9/9/05 9:38:39 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:38:39 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:39 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:38:39 PM) Bad IE-pages: (none)
(9/9/05 9:38:39 PM) Stealth-String not found
(9/9/05 9:38:39 PM) No locked Files to delete. End without Reboot
(9/9/05 9:39:19 PM) Disinfection started
(9/9/05 9:39:19 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:39:19 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:39:19 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:39:19 PM) Bad IE-pages: (none)
(9/9/05 9:39:19 PM) Stealth-String not found
(9/9/05 9:39:19 PM) No locked Files to delete. End without Reboot
(9/9/05 9:41:05 PM) Disinfection started
(9/9/05 9:41:05 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:41:05 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:05 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:05 PM) Bad IE-pages: (none)
(9/9/05 9:41:05 PM) Stealth-String not found
(9/9/05 9:41:05 PM) No locked Files to delete. End without Reboot
(9/9/05 9:41:09 PM) Disinfection started
(9/9/05 9:41:09 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:41:09 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:09 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:09 PM) Bad IE-pages: (none)
(9/9/05 9:41:09 PM) Stealth-String not found
(9/9/05 9:41:09 PM) No locked Files to delete. End without Reboot
(9/9/05 9:41:10 PM) Disinfection started
(9/9/05 9:41:10 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:41:10 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:10 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:10 PM) Bad IE-pages: (none)
(9/9/05 9:41:10 PM) Stealth-String not found
(9/9/05 9:41:10 PM) No locked Files to delete. End without Reboot
(9/9/05 9:41:16 PM) Disinfection started
(9/9/05 9:41:16 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:41:16 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:16 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:16 PM) Bad IE-pages: (none)
(9/9/05 9:41:16 PM) Stealth-String not found
(9/9/05 9:41:16 PM) No locked Files to delete. End without Reboot
(9/9/05 9:41:23 PM) Disinfection started
(9/9/05 9:41:23 PM) Bad-Dll(IEP): c:\windows\system32\jnvdk.dll
(9/9/05 9:41:23 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:23 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:23 PM) Bad IE-pages: (none)
(9/9/05 9:41:23 PM) Stealth-String not found
(9/9/05 9:41:23 PM) No locked Files to delete. End without Reboot


(9/9/05 9:41:32 PM) SPSeHjFix started v1.1.2
(9/9/05 9:41:32 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 9:41:32 PM) Language: english
(9/9/05 9:41:32 PM) Win-Path: C:\WINDOWS
(9/9/05 9:41:32 PM) System-Path: C:\WINDOWS\system32
(9/9/05 9:41:32 PM) Temp-Path: C:\DOCUME~1\DREWAL~1\LOCALS~1\Temp\
(9/9/05 9:41:35 PM) Disinfection started
(9/9/05 9:41:35 PM) Bad-Dll(IEP): (not found)
(9/9/05 9:41:35 PM) Bad-Dll(IEP) in BHO: (not found)
(9/9/05 9:41:35 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:35 PM) UBF: 7 - UBB: 2 - UBR: 21
(9/9/05 9:41:35 PM) Bad IE-pages: (none)
(9/9/05 9:41:35 PM) Stealth-String not found
(9/9/05 9:41:35 PM) Not infected->END



New HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:49:22 PM, on 9/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Class - {F6EE5F6F-2DB0-5CE5-4CBE-0DB05DBFBB07} - C:\WINDOWS\system32\apiqn32.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [ntvt32.exe] C:\WINDOWS\ntvt32.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8…pdatePortal.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InterPlot IMF Printer Driver Service - Unknown owner - C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {F6EE5F6F-2DB0-5CE5-4CBE-0DB05DBFBB07} - C:\WINDOWS\system32\apiqn32.dll

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [ntvt32.exe] C:\WINDOWS\ntvt32.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.





Search for and delete these files if listed:
C:\WINDOWS\ntvt32.exe
c:\windows\system32\jnvdk.dll
C:\WINDOWS\system32\apiqn32.dll



Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Okay I ran HJT as recommended and none of the R0's you ask to put a check in appeared in the HJT scan. I proceeding with the rest of your recommendations. When I searched for the ntvt32.exe, jnvdk.dll, and apiqn32.dll files they were not found. I looked in the directories as well and not there. I displayed hidden files directed. I completed all other task.

Final reboot worked fine, however some preferences removed, mainly wallpaper. I am still launching internet explore from run menu as iexplore.exe to about:blank as home page, as this seems to bypass virus. I think internet explore has been removed/deleted from my computer. I does not show up in start/programs, desktop, or by a search. However it still launches from the run menu.

Lated HJT log is posted below:


Logfile of HijackThis v1.99.1
Scan saved at 11:19:01 PM, on 9/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\javalv.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Class - {C2FD5428-8E7E-9558-F24F-1C6BD302EF96} - C:\WINDOWS\d3kt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [javalv.exe] C:\WINDOWS\javalv.exe
O4 - HKLM\..\RunOnce: [apisg32.exe] C:\WINDOWS\system32\apisg32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8…pdatePortal.cab
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apisg32.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InterPlot IMF Printer Driver Service - Unknown owner - C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
Well it looks like it all came back :rant2:

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Very Important:
Reboot and repeat the process above starting with Reboot in Safe Mode.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.
As directed, I cleaned files. Ran scans in safe mode. SpSehjfix will not re-boot for me at the end of the scan. Rebooted to safe mode and ran shredder. Rebooted and repeated this process multiple times. Logs posted below.


SpSeHifix Log:


(9/9/05 11:50:19 PM) SPSeHjFix started v1.1.2
(9/9/05 11:50:19 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 11:50:19 PM) Language: english
(9/9/05 11:50:19 PM) Win-Path: C:\WINDOWS
(9/9/05 11:50:19 PM) System-Path: C:\WINDOWS\system32
(9/9/05 11:50:19 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(9/9/05 11:50:20 PM) Disinfection started
(9/9/05 11:50:20 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:50:20 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:20 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:20 PM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\system32\frmlm.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\system32\frmlm.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\system32\frmlm.dll/sp.html#37049
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\system32\frmlm.dll/sp.html#37049
(9/9/05 11:50:20 PM) Stealth-String not found
(9/9/05 11:50:20 PM) No locked Files to delete. End without Reboot
(9/9/05 11:50:31 PM) Disinfection started
(9/9/05 11:50:31 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:50:31 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:31 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:31 PM) Bad IE-pages: (none)
(9/9/05 11:50:31 PM) Stealth-String not found
(9/9/05 11:50:31 PM) No locked Files to delete. End without Reboot
(9/9/05 11:50:32 PM) Disinfection started
(9/9/05 11:50:32 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:50:32 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:32 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:32 PM) Bad IE-pages: (none)
(9/9/05 11:50:32 PM) Stealth-String not found
(9/9/05 11:50:32 PM) No locked Files to delete. End without Reboot
(9/9/05 11:50:32 PM) Disinfection started
(9/9/05 11:50:32 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:50:32 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:32 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:50:32 PM) Bad IE-pages: (none)
(9/9/05 11:50:32 PM) Stealth-String not found
(9/9/05 11:50:32 PM) No locked Files to delete. End without Reboot
(9/9/05 11:51:03 PM) Disinfection started
(9/9/05 11:51:03 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:51:03 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:03 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:03 PM) Bad IE-pages: (none)
(9/9/05 11:51:03 PM) Stealth-String not found
(9/9/05 11:51:03 PM) No locked Files to delete. End without Reboot
(9/9/05 11:51:04 PM) Disinfection started
(9/9/05 11:51:04 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:51:04 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:04 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:04 PM) Bad IE-pages: (none)
(9/9/05 11:51:04 PM) Stealth-String not found
(9/9/05 11:51:04 PM) No locked Files to delete. End without Reboot
(9/9/05 11:51:04 PM) Disinfection started
(9/9/05 11:51:04 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:51:04 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:04 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:04 PM) Bad IE-pages: (none)
(9/9/05 11:51:04 PM) Stealth-String not found
(9/9/05 11:51:04 PM) No locked Files to delete. End without Reboot
(9/9/05 11:51:04 PM) Disinfection started
(9/9/05 11:51:04 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:51:05 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:05 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:05 PM) Bad IE-pages: (none)
(9/9/05 11:51:05 PM) Stealth-String not found
(9/9/05 11:51:05 PM) No locked Files to delete. End without Reboot
(9/9/05 11:51:05 PM) Disinfection started
(9/9/05 11:51:05 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:51:05 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:05 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:51:05 PM) Bad IE-pages: (none)
(9/9/05 11:51:05 PM) Stealth-String not found
(9/9/05 11:51:05 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:50 PM) Disinfection started
(9/9/05 11:52:50 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:50 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:50 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:50 PM) Bad IE-pages: (none)
(9/9/05 11:52:50 PM) Stealth-String not found
(9/9/05 11:52:50 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:51 PM) Disinfection started
(9/9/05 11:52:51 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:51 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:51 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:51 PM) Bad IE-pages: (none)
(9/9/05 11:52:51 PM) Stealth-String not found
(9/9/05 11:52:51 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:52 PM) Disinfection started
(9/9/05 11:52:52 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) Bad IE-pages: (none)
(9/9/05 11:52:52 PM) Stealth-String not found
(9/9/05 11:52:52 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:52 PM) Disinfection started
(9/9/05 11:52:52 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) Bad IE-pages: (none)
(9/9/05 11:52:52 PM) Stealth-String not found
(9/9/05 11:52:52 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:52 PM) Disinfection started
(9/9/05 11:52:52 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) Bad IE-pages: (none)
(9/9/05 11:52:52 PM) Stealth-String not found
(9/9/05 11:52:52 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:52 PM) Disinfection started
(9/9/05 11:52:52 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:52 PM) Bad IE-pages: (none)
(9/9/05 11:52:52 PM) Stealth-String not found
(9/9/05 11:52:52 PM) No locked Files to delete. End without Reboot
(9/9/05 11:52:53 PM) Disinfection started
(9/9/05 11:52:53 PM) Bad-Dll(IEP): c:\windows\system32\frmlm.dll
(9/9/05 11:52:53 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:53 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:52:53 PM) Bad IE-pages: (none)
(9/9/05 11:52:53 PM) Stealth-String not found
(9/9/05 11:52:53 PM) No locked Files to delete. End without Reboot


(9/9/05 11:53:56 PM) SPSeHjFix started v1.1.2
(9/9/05 11:53:56 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 11:53:56 PM) Language: english
(9/9/05 11:53:56 PM) Win-Path: C:\WINDOWS
(9/9/05 11:53:56 PM) System-Path: C:\WINDOWS\system32
(9/9/05 11:53:56 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(9/9/05 11:53:57 PM) Disinfection started
(9/9/05 11:53:57 PM) Bad-Dll(IEP): (not found)
(9/9/05 11:53:57 PM) Bad-Dll(IEP) in BHO: (not found)
(9/9/05 11:53:57 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:53:57 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:53:57 PM) Bad IE-pages: (none)
(9/9/05 11:53:57 PM) Stealth-String not found
(9/9/05 11:53:57 PM) Not infected->END


(9/9/05 11:55:44 PM) SPSeHjFix started v1.1.2
(9/9/05 11:55:44 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 11:55:44 PM) Language: english
(9/9/05 11:55:44 PM) Win-Path: C:\WINDOWS
(9/9/05 11:55:44 PM) System-Path: C:\WINDOWS\system32
(9/9/05 11:55:44 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(9/9/05 11:55:45 PM) Disinfection started
(9/9/05 11:55:45 PM) Bad-Dll(IEP): (not found)
(9/9/05 11:55:45 PM) Bad-Dll(IEP) in BHO: (not found)
(9/9/05 11:55:45 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:55:45 PM) UBF: 7 - UBB: 2 - UBR: 19
(9/9/05 11:55:45 PM) Bad IE-pages: (none)
(9/9/05 11:55:45 PM) Stealth-String not found
(9/9/05 11:55:45 PM) Not infected->END


(9/9/05 11:58:47 PM) SPSeHjFix started v1.1.2
(9/9/05 11:58:47 PM) OS: WinXP Service Pack 2 (5.1.2600)
(9/9/05 11:58:47 PM) Language: english
(9/9/05 11:58:47 PM) Win-Path: C:\WINDOWS
(9/9/05 11:58:47 PM) System-Path: C:\WINDOWS\system32
(9/9/05 11:58:47 PM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(9/9/05 11:58:48 PM) Disinfection started
(9/9/05 11:58:48 PM) Bad-Dll(IEP): (not found)
(9/9/05 11:58:48 PM) Bad-Dll(IEP) in BHO: (not found)
(9/9/05 11:58:48 PM) UBF: 7 - UBB: 0 - UBR: 15
(9/9/05 11:58:48 PM) UBF: 7 - UBB: 0 - UBR: 15
(9/9/05 11:58:48 PM) Bad IE-pages: (none)
(9/9/05 11:58:48 PM) Stealth-String not found
(9/9/05 11:58:48 PM) Not infected->END


(9/10/05 12:06:46 AM) SPSeHjFix started v1.1.2
(9/10/05 12:06:46 AM) OS: WinXP Service Pack 2 (5.1.2600)
(9/10/05 12:06:46 AM) Language: english
(9/10/05 12:06:46 AM) Win-Path: C:\WINDOWS
(9/10/05 12:06:46 AM) System-Path: C:\WINDOWS\system32
(9/10/05 12:06:46 AM) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(9/10/05 12:06:47 AM) Disinfection started
(9/10/05 12:06:47 AM) Bad-Dll(IEP): (not found)
(9/10/05 12:06:47 AM) Bad-Dll(IEP) in BHO: (not found)
(9/10/05 12:06:47 AM) UBF: 7 - UBB: 0 - UBR: 15
(9/10/05 12:06:47 AM) UBF: 7 - UBB: 0 - UBR: 15
(9/10/05 12:06:47 AM) Bad IE-pages: (none)
(9/10/05 12:06:47 AM) Stealth-String not found
(9/10/05 12:06:47 AM) Not infected->END


HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 12:08:59 AM, on 9/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\apioa.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O2 - BHO: Class - {EB9EE3BA-CF19-46FB-88A1-146263FF772F} - C:\WINDOWS\system32\javaaf.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [apioa.exe] C:\WINDOWS\system32\apioa.exe
O4 - HKLM\..\RunOnce: [apisg32.exe] C:\WINDOWS\system32\apisg32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8…pdatePortal.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apisg32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InterPlot IMF Printer Driver Service - Unknown owner - C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
Be sure that all windows are closed. Click on START-> RUN. Copy paste the following as it is and click OK.

regsvr32.exe /U frmlm.dll


You should get a message that it has been uninstalled succesfully.
Then be sure that all windows are still closed.

Click on START-> RUN. Copy paste the following as it is and click OK.

regsvr32.exe /U javaaf.dll



Use HijackThis to delete the service. You can click on Config, then Misc Tools, and then press the Delete an NT service.. button. When it opens you should then enter the service name and press OK.

Copy/Paste this into the window. ( 11Fßä#·ºÄÖ`I)




Run hijackthis. Hit None of the above, just start the program button.
Put a check mark on these entries.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\frmlm.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {EB9EE3BA-CF19-46FB-88A1-146263FF772F} - C:\WINDOWS\system32\javaaf.dll

O4 - HKLM\..\Run: [apioa.exe] C:\WINDOWS\system32\apioa.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apisg32.exe" /s (file missing)


Hit FIX CHEKED button.


Delete these files if Listed:
C:\WINDOWS\system32\apioa.exe
C:\WINDOWS\system32\apisg32.exe
C:\WINDOWS\system32\frmlm.dll
C:\WINDOWS\system32\javaaf.dll


Lets also do this:

click Start> Run> type in Cleanmgr. Tap enter and select C: to clean.


Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I tried the first step to to copy/paste the regvr32.exe /u frmlm.dll into run command and I got this message. " frmlm.dll is not an executable file and no registration helper is registered for this file type". Since this first step did not work, I did not go on to the remaining directions. Please advice. Thanks.
Okay I skipped step 1 to run frmlm.dll.

Went to step 2 to run javaaf.dll which worked.

Step 3 using HJT would not delete the 11FB…'I service b/c it was active.

Step 4 re-ran HJT scan and the scan did not find the first 4 lines from above to check mark. I did check mark all other lines and hit fix.

Step 5 re-ran cleanmgr and re-boot.

On reboot I got a message that windows could not find and was searching for apisg32.exe. Windows finished boot anyway.


New HJT log posted below:

Logfile of HijackThis v1.99.1
Scan saved at 11:50:03 AM, on 9/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\mdm.exe
C:\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Media Card Companion Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8…pdatePortal.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apisg32.exe" /s (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InterPlot IMF Printer Driver Service - Unknown owner - C:\win32app\ingr\ipshare\clntutil\bin\pidrpcs.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
We have to kill this service or we won't get anywhere.

Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.

Use HijackThis to delete the service. You can click on Config, then Misc Tools, and then press the Delete an NT service.. button. When it opens you should then enter the service name and press OK.

Copy/Paste this into the window. ( 11Fßä#·ºÄÖ`I)

Step 3 using HJT would not delete the 11FB…'I service b/c it was active.

If you get this again: use Alt/Ctrl/Del and end the process for it.




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rpvcm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rpvcm.dll/sp.html#37049

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apisg32.exe" /s (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI