This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another winfixer victim

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Another victim of winfixer 2005. I have ran spybot destroyer and adware. Also I have Norton Internet Security and zone alarm.

Here is my hijack this log
TIA Cindy
Logfile of HijackThis v1.99.1
Scan saved at 9:09:09 AM, on 9/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Propel Accelerator\propelac.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\CMMON32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Cindy\Desktop\Hijackthis.exe\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://service.bfast.com/bfast/click?bfmid…fpage=homelink3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ev1.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.academicplanet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.ev1.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AcademicPlanet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\Propel Accelerator\prpl_IePopupBlocker.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\Propel Accelerator\trayctl.exe" /STARTUPLAUNCH
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\AG CreataCard\AGremind.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Allow pop-ups from this site - C:\Program Files\Propel Accelerator\pac-addwl.html
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\Propel Accelerator\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\Propel Accelerator\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: PlanetChat - {BA72591D-F006-4A09-88BE-0303179D9604} - http://www.academicplanet.com/chat2.asp (file missing) (HKCU)
O9 - Extra button: PageMagic - {ECBA32E1-7C57-4609-B5F2-789315D5C862} - http://www.academicplanet.com/pagebuilder.asp (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E2D608F0-1730-44ED-9686-164F11263C58}: NameServer = 209.63.0.6 207.173.86.6
O20 - Winlogon Notify: tcptask - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Download/install APM

Run APM

Click on each item in the upper window

Then look in the lower window. Check to see which processes are using this DLL:

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

Post back letting me know which ones are using that DLL.

Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\$NtUninstallKB837001$\ /ah > files.txt
dir C:\WINDOWS\$NtUninstallKB837001$\ >> files.txt
notepad files.txt

Save it to your desktop as ff.bat.

Now, the ff.bat file on the desktop. A Notepad window will open up.

Please paste it's contents into your next post.
:)
I hope I am doing this right. This is what it showed. 484 C:\Windows\system32\winlogon.exe dir C:\WINDOWS\$NtUninstallKB837001$\ /ah > files.txt dir C:\WINDOWS\$NtUninstallkB837001$\ .files.txt notepad files.txt TIA Cindy
Copy the text in the following quote box into Notepad:

cd C:\WINDOWS\$NtUninstallKB837001$\
dir /ah > files.txt
dir >> files.txt
notepad files.txt

Save it to your desktop as ff.bat.

Close Notepad.

Now, the ff.bat file on the desktop. A Notepad window will open up.

Please paste it's contents into your next post.

This is supposed to give me a listing of files on your machine so I can pick out the "good" from the "bad".

:)
Volume in drive C has no label. Volume Serial Number is B018-757A Directory of C:\WINDOWS\$NtUninstallKB837001$ 03/31/2003 07:00 AM 557,128 dao360.dll 03/31/2003 07:00 AM 380,445 expsrv.dll 09/15/2005 04:28 PM 0 files.txt 03/31/2003 07:00 AM 512,031 msexch40.dll 03/31/2003 07:00 AM 319,519 msexcl40.dll 03/31/2003 07:00 AM 1,503,262 msjet40.dll 03/31/2003 07:00 AM 348,195 msjetol1.dll 03/31/2003 07:00 AM 348,195 msjetoledb40.dll 03/31/2003 07:00 AM 151,626 msjint40.dll 03/31/2003 07:00 AM 53,322 msjter40.dll 03/31/2003 07:00 AM 241,695 msjtes40.dll 03/31/2003 07:00 AM 213,023 msltus40.dll 03/31/2003 07:00 AM 348,191 mspbde40.dll 03/31/2003 07:00 AM 421,919 msrd2x40.dll 03/31/2003 07:00 AM 315,466 msrd3x40.dll 03/31/2003 07:00 AM 552,991 msrepl40.dll 03/31/2003 07:00 AM 253,983 mstext40.dll 03/31/2003 07:00 AM 831,562 mswdat10.dll 03/31/2003 07:00 AM 614,474 mswstr10.dll 03/31/2003 07:00 AM 344,095 msxbde40.dll 09/11/2004 09:36 AM spuninst 03/31/2003 07:00 AM 30,992 vbajet32.dll 21 File(s) 8,342,114 bytes 1 Dir(s) 150,567,415,808 bytes free
Still having a bit of trouble "getting on the same page", Cindy.

Lets' do this.

1. Download the file attached to this post (ff.txt) to your desktop.

2. on it and Rename it to ff.bat (the forum won't allow me to upload "bat" files).

3. Double-click the ff.bat file on the desktop. A Notepad Window will open up. Paste it's contents into this post.

I think some of the contents of the "bat" file are getting lost in the translation from the forum to your C: drive.

What I need before I can proceed is a list on the "hidden" files in this folder on your machine:

C:\WINDOWS\$NtUninstallKB837001$

This file will show on the list, along with others:

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

This malware creates "hidden" files. I need all of their names in order to get rid of your problem.
:)

Attachments:

Sorry I am not what my ds calls computer smart. Is this what your looking for? Volume in drive C has no label. Volume Serial Number is B018-757A Directory of C:\WINDOWS\$NtUninstallKB837001$ 09/15/2005 08:34 PM . 09/15/2005 08:34 PM .. 08/26/2005 11:52 AM 178,623 ksatpct.bak1 09/15/2005 12:51 PM 515,794 ksatpct.bak2 09/15/2005 08:34 PM 516,503 ksatpct.ini 08/26/2005 11:52 AM 516,116 tcptask.dll 4 File(s) 1,727,036 bytes 2 Dir(s) 150,561,402,880 bytes free Volume in drive C has no label. Volume Serial Number is B018-757A Directory of C:\WINDOWS\$NtUninstallKB837001$ 03/31/2003 07:00 AM 557,128 dao360.dll 03/31/2003 07:00 AM 380,445 expsrv.dll 09/15/2005 08:32 PM 2,760 files.txt 03/31/2003 07:00 AM 512,031 msexch40.dll 03/31/2003 07:00 AM 319,519 msexcl40.dll 03/31/2003 07:00 AM 1,503,262 msjet40.dll 03/31/2003 07:00 AM 348,195 msjetol1.dll 03/31/2003 07:00 AM 348,195 msjetoledb40.dll 03/31/2003 07:00 AM 151,626 msjint40.dll 03/31/2003 07:00 AM 53,322 msjter40.dll 03/31/2003 07:00 AM 241,695 msjtes40.dll 03/31/2003 07:00 AM 213,023 msltus40.dll 03/31/2003 07:00 AM 348,191 mspbde40.dll 03/31/2003 07:00 AM 421,919 msrd2x40.dll 03/31/2003 07:00 AM 315,466 msrd3x40.dll 03/31/2003 07:00 AM 552,991 msrepl40.dll 03/31/2003 07:00 AM 253,983 mstext40.dll 03/31/2003 07:00 AM 831,562 mswdat10.dll 03/31/2003 07:00 AM 614,474 mswstr10.dll 03/31/2003 07:00 AM 344,095 msxbde40.dll 09/11/2004 09:36 AM spuninst 03/31/2003 07:00 AM 30,992 vbajet32.dll 21 File(s) 8,344,874 bytes 1 Dir(s) 150,561,398,784 bytes free
Step 1:

Please download Process Explorer by Systernals from:

Process Explorer

Also download/unzip KillBox by Option^Explicit from:

Killbox.zip

Step 2:

Download this file and save it to your desktop:

FixVundo Registry File

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak1
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak2
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.ini


Step 3:

Print out the following instructions as you will not have Internet Access for the rest of this fix.

Reboot in "safe" mode.

The rest of this fix must be done in safe mode.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of:

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

once and then click the kill button.

After you have killed all of:

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

under winlogon click OK.

If you see any of the files listed below, kill them as well.

Files to look for:
————————–
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak1
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak2
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. This is OK.

Next double-click on explorer.exe, select the Threads tab, and again click once on each instance of:

C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

then click the kill button.

If you see any of the files listed below kill them as well.

Files to look for:
————————–
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak1
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.bak2
C:\WINDOWS\$NtUninstallKB837001$\ksatpct.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. This is OK.

Once you have done that click OK again.

Next run Hijack This! and place a check beside each of the following.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

O20 - Winlogon Notify: tcptask - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll

Now click Fix checked and close HijackThis.

Now double-click on the vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.

Step 4:

On the desktop, open the "killme.txt" file with Notepad.

Then copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C):

Close "killme.txt".

Double click on Killbox.exe and then check the Delete on reboot button.

In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new log file into this thread. :)
Quick question I got to the winlogon.exe brought up the Threads screen you said to click on each instance of c:\windows\$NtUninstallKB837001$\tcptask.dll I have seen ones with the tcptask.dll but not the first part Do I click on the ones that have the tcptask.dll and kill them? Sorry for being such a pain. TIA Cindy
Volume in drive C has no label. Volume Serial Number is B018-757A Directory of C:\WINDOWS\$NtUninstallKB837001$ 09/16/2005 11:53 PM . 09/16/2005 11:53 PM .. 09/16/2005 11:53 PM 422,712 ksatpct.ini 1 File(s) 422,712 bytes 2 Dir(s) 150,522,327,040 bytes free Volume in drive C has no label. Volume Serial Number is B018-757A Directory of C:\WINDOWS\$NtUninstallKB837001$ 03/31/2003 07:00 AM 557,128 dao360.dll 03/31/2003 07:00 AM 380,445 expsrv.dll 09/15/2005 08:32 PM 2,760 files.txt 08/26/2005 11:52 AM 178,623 ksatpct.bak1 09/16/2005 09:28 PM 422,329 ksatpct.bak2 03/31/2003 07:00 AM 512,031 msexch40.dll 03/31/2003 07:00 AM 319,519 msexcl40.dll 03/31/2003 07:00 AM 1,503,262 msjet40.dll 03/31/2003 07:00 AM 348,195 msjetol1.dll 03/31/2003 07:00 AM 348,195 msjetoledb40.dll 03/31/2003 07:00 AM 151,626 msjint40.dll 03/31/2003 07:00 AM 53,322 msjter40.dll 03/31/2003 07:00 AM 241,695 msjtes40.dll 03/31/2003 07:00 AM 213,023 msltus40.dll 03/31/2003 07:00 AM 348,191 mspbde40.dll 03/31/2003 07:00 AM 421,919 msrd2x40.dll 03/31/2003 07:00 AM 315,466 msrd3x40.dll 03/31/2003 07:00 AM 552,991 msrepl40.dll 03/31/2003 07:00 AM 253,983 mstext40.dll 03/31/2003 07:00 AM 831,562 mswdat10.dll 03/31/2003 07:00 AM 614,474 mswstr10.dll 03/31/2003 07:00 AM 344,095 msxbde40.dll 09/11/2004 09:36 AM spuninst 08/26/2005 11:52 AM 516,116 tcptask.dll 03/31/2003 07:00 AM 30,992 vbajet32.dll 24 File(s) 9,461,942 bytes 1 Dir(s) 150,522,327,040 bytes free
Logfile of HijackThis v1.99.1
Scan saved at 11:39:28 PM, on 9/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Cindy\Desktop\Hijackthis.exe\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://service.bfast.com/bfast/click?bfmid…fpage=homelink3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ev1.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.academicplanet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.ev1.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AcademicPlanet.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\Propel Accelerator\prpl_IePopupBlocker.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\Propel Accelerator\trayctl.exe" /STARTUPLAUNCH
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\AG CreataCard\AGremind.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: PlanetChat - {BA72591D-F006-4A09-88BE-0303179D9604} - http://www.academicplanet.com/chat2.asp (file missing) (HKCU)
O9 - Extra button: PageMagic - {ECBA32E1-7C57-4609-B5F2-789315D5C862} - http://www.academicplanet.com/pagebuilder.asp (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.academicplanet.com
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O20 - Winlogon Notify: tcptask - C:\WINDOWS\$NtUninstallKB837001$\tcptask.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI