This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Please with WinFixer

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am helping a friend with his new PC. Apparently he has the lovely WinFixer pop up. I would greatly appreciate any help you guys could give me.
Here is his HJT Log File:

Logfile of HijackThis v1.99.1
Scan saved at 9:00:00 PM, on 9/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html?p=DS
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Cursors\dvdvb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1124347419656
O20 - Winlogon Notify: dvdvb - C:\WINDOWS\Cursors\dvdvb.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I Have VundoFix and CC cleaner ready as well. Again thank you for any tips to help make sure his PC is clean and good to go.
Greetings and welcome to TomCoyote.org!

Download/install APM

Run APM

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using C:\WINDOWS\Cursors\dvdvb.dll

Post back letting me know all processes using that DLL.

Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\Cursors\ /ah > files.txt
dir C:\WINDOWS\Cursors\ >> files.txt
notepad files.txt

Save it to your desktop as ff.bat.

Now, the ff.bat file on the desktop.

Wait for a Notepad window to open up.

Please paste it's contents into your next post.
:)
Thank You for the welcome Micah!! Here are the 2 processes using C:\WINDOWS\Cursors\dvdvb.dll 672-C:\WINDOWS\system32\winlogon.exe 1560-C:\WINDOWS\explorer.exe Also here is the Contents of the log file you asked for: Volume in drive C has no label. Volume Serial Number is 5457-C93E Directory of C:\WINDOWS\Cursors 08/30/2005 07:27 PM 178,370 bvdvd.bak1 09/10/2005 01:14 AM 179,156 bvdvd.bak2 09/13/2005 08:56 PM 179,182 bvdvd.ini 08/30/2005 07:27 PM 516,116 dvdvb.dll 4 File(s) 1,052,824 bytes 0 Dir(s) 144,407,973,888 bytes free Volume in drive C has no label. Volume Serial Number is 5457-C93E Directory of C:\WINDOWS\Cursors 09/13/2005 08:56 PM . 09/13/2005 08:56 PM .. 08/04/2004 05:00 AM 766 3dgarro.cur 08/04/2004 05:00 AM 766 3dgmove.cur 08/04/2004 05:00 AM 766 3dgnesw.cur 08/04/2004 05:00 AM 766 3dgno.cur 08/04/2004 05:00 AM 766 3dgns.cur 08/04/2004 05:00 AM 766 3dgnwse.cur 08/04/2004 05:00 AM 766 3dgwe.cur 08/04/2004 05:00 AM 766 3dsmove.cur 08/04/2004 05:00 AM 766 3dsns.cur 08/04/2004 05:00 AM 766 3dsnwse.cur 08/04/2004 05:00 AM 766 3dwarro.cur 08/04/2004 05:00 AM 766 3dwmove.cur 08/04/2004 05:00 AM 766 3dwnesw.cur 08/04/2004 05:00 AM 766 3dwno.cur 08/04/2004 05:00 AM 766 3dwns.cur 08/04/2004 05:00 AM 766 3dwnwse.cur 08/04/2004 05:00 AM 766 3dwwe.cur 08/04/2004 05:00 AM 7,962 appstar2.ani 08/04/2004 05:00 AM 7,856 appstar3.ani 08/04/2004 05:00 AM 7,954 appstart.ani 08/04/2004 05:00 AM 326 arrow_i.cur 08/04/2004 05:00 AM 766 arrow_il.cur 08/04/2004 05:00 AM 766 arrow_im.cur 08/04/2004 05:00 AM 766 arrow_l.cur 08/04/2004 05:00 AM 766 arrow_m.cur 08/04/2004 05:00 AM 326 arrow_r.cur 08/04/2004 05:00 AM 766 arrow_rl.cur 08/04/2004 05:00 AM 766 arrow_rm.cur 08/04/2004 05:00 AM 11,904 banana.ani 08/04/2004 05:00 AM 8,660 barber.ani 08/04/2004 05:00 AM 326 beam_i.cur 08/04/2004 05:00 AM 766 beam_il.cur 08/04/2004 05:00 AM 766 beam_im.cur 08/04/2004 05:00 AM 766 beam_l.cur 08/04/2004 05:00 AM 766 beam_m.cur 08/04/2004 05:00 AM 326 beam_r.cur 08/04/2004 05:00 AM 766 beam_rl.cur 08/04/2004 05:00 AM 766 beam_rm.cur 08/04/2004 05:00 AM 326 busy_i.cur 08/04/2004 05:00 AM 766 busy_il.cur 08/04/2004 05:00 AM 766 busy_im.cur 08/04/2004 05:00 AM 766 busy_l.cur 08/04/2004 05:00 AM 766 busy_m.cur 08/04/2004 05:00 AM 326 busy_r.cur 08/04/2004 05:00 AM 766 busy_rl.cur 08/04/2004 05:00 AM 766 busy_rm.cur 08/04/2004 05:00 AM 7,114 coin.ani 08/04/2004 05:00 AM 6,832 counter.ani 08/04/2004 05:00 AM 766 cross.cur 08/04/2004 05:00 AM 326 cross_i.cur 08/04/2004 05:00 AM 766 cross_il.cur 08/04/2004 05:00 AM 766 cross_im.cur 08/04/2004 05:00 AM 766 cross_l.cur 08/04/2004 05:00 AM 766 cross_m.cur 08/04/2004 05:00 AM 326 cross_r.cur 08/04/2004 05:00 AM 766 cross_rl.cur 08/04/2004 05:00 AM 766 cross_rm.cur 08/04/2004 05:00 AM 4,804 dinosau2.ani 08/04/2004 05:00 AM 4,804 dinosaur.ani 08/04/2004 05:00 AM 3,240 drum.ani 08/04/2004 05:00 AM 14,936 fillitup.ani 08/04/2004 05:00 AM 3,292 hand.ani 08/04/2004 05:00 AM 6,356 handapst.ani 08/04/2004 05:00 AM 1,700 handnesw.ani 08/04/2004 05:00 AM 4,066 handno.ani 08/04/2004 05:00 AM 1,698 handns.ani 08/04/2004 05:00 AM 1,700 handnwse.ani 08/04/2004 05:00 AM 7,530 handwait.ani 08/04/2004 05:00 AM 1,698 handwe.ani 08/04/2004 05:00 AM 766 harrow.cur 08/04/2004 05:00 AM 766 hcross.cur 08/04/2004 05:00 AM 326 help_i.cur 08/04/2004 05:00 AM 766 help_il.cur 08/04/2004 05:00 AM 766 help_im.cur 08/04/2004 05:00 AM 766 help_l.cur 08/04/2004 05:00 AM 766 help_m.cur 08/04/2004 05:00 AM 326 help_r.cur 08/04/2004 05:00 AM 766 help_rl.cur 08/04/2004 05:00 AM 766 help_rm.cur 08/04/2004 05:00 AM 766 hibeam.cur 08/04/2004 05:00 AM 766 hmove.cur 08/04/2004 05:00 AM 766 hnesw.cur 08/04/2004 05:00 AM 766 hnodrop.cur 08/04/2004 05:00 AM 766 hns.cur 08/04/2004 05:00 AM 766 hnwse.cur 08/04/2004 05:00 AM 18,722 horse.ani 08/04/2004 05:00 AM 11,832 hourgla2.ani 08/04/2004 05:00 AM 11,830 hourgla3.ani 08/04/2004 05:00 AM 11,824 hourglas.ani 08/04/2004 05:00 AM 766 hwe.cur 08/04/2004 05:00 AM 766 lappstrt.cur 08/04/2004 05:00 AM 766 larrow.cur 08/04/2004 05:00 AM 766 lcross.cur 08/04/2004 05:00 AM 766 libeam.cur 08/04/2004 05:00 AM 766 lmove.cur 08/04/2004 05:00 AM 766 lnesw.cur 08/04/2004 05:00 AM 766 lnodrop.cur 08/04/2004 05:00 AM 766 lns.cur 08/04/2004 05:00 AM 766 lnwse.cur 08/04/2004 05:00 AM 766 lwait.cur 08/04/2004 05:00 AM 766 lwe.cur 09/08/2005 05:13 AM 143 mcrh.tmp 08/04/2004 05:00 AM 5,674 metronom.ani 08/04/2004 05:00 AM 326 move_i.cur 08/04/2004 05:00 AM 766 move_il.cur 08/04/2004 05:00 AM 766 move_im.cur 08/04/2004 05:00 AM 766 move_l.cur 08/04/2004 05:00 AM 766 move_m.cur 08/04/2004 05:00 AM 326 move_r.cur 08/04/2004 05:00 AM 766 move_rl.cur 08/04/2004 05:00 AM 766 move_rm.cur 08/04/2004 05:00 AM 326 no_i.cur 08/04/2004 05:00 AM 766 no_il.cur 08/04/2004 05:00 AM 766 no_im.cur 08/04/2004 05:00 AM 766 no_l.cur 08/04/2004 05:00 AM 766 no_m.cur 08/04/2004 05:00 AM 326 no_r.cur 08/04/2004 05:00 AM 766 no_rl.cur 08/04/2004 05:00 AM 766 no_rm.cur 08/04/2004 05:00 AM 326 pen_i.cur 08/04/2004 05:00 AM 766 pen_il.cur 08/04/2004 05:00 AM 766 pen_im.cur 08/04/2004 05:00 AM 766 pen_l.cur 08/04/2004 05:00 AM 766 pen_m.cur 08/04/2004 05:00 AM 326 pen_r.cur 08/04/2004 05:00 AM 766 pen_rl.cur 08/04/2004 05:00 AM 766 pen_rm.cur 08/04/2004 05:00 AM 4,100 piano.ani 08/04/2004 05:00 AM 9,824 rainbow.ani 08/04/2004 05:00 AM 4,826 raindrop.ani 08/04/2004 05:00 AM 326 size1_i.cur 08/04/2004 05:00 AM 766 size1_il.cur 08/04/2004 05:00 AM 766 size1_im.cur 08/04/2004 05:00 AM 766 size1_l.cur 08/04/2004 05:00 AM 766 size1_m.cur 08/04/2004 05:00 AM 326 size1_r.cur 08/04/2004 05:00 AM 766 size1_rl.cur 08/04/2004 05:00 AM 766 size1_rm.cur 08/04/2004 05:00 AM 326 size2_i.cur 08/04/2004 05:00 AM 766 size2_il.cur 08/04/2004 05:00 AM 766 size2_im.cur 08/04/2004 05:00 AM 766 size2_l.cur 08/04/2004 05:00 AM 766 size2_m.cur 08/04/2004 05:00 AM 326 size2_r.cur 08/04/2004 05:00 AM 766 size2_rl.cur 08/04/2004 05:00 AM 766 size2_rm.cur 08/04/2004 05:00 AM 326 size3_i.cur 08/04/2004 05:00 AM 766 size3_il.cur 08/04/2004 05:00 AM 766 size3_im.cur 08/04/2004 05:00 AM 766 size3_l.cur 08/04/2004 05:00 AM 766 size3_m.cur 08/04/2004 05:00 AM 326 size3_r.cur 08/04/2004 05:00 AM 766 size3_rl.cur 08/04/2004 05:00 AM 766 size3_rm.cur 08/04/2004 05:00 AM 326 size4_i.cur 08/04/2004 05:00 AM 766 size4_il.cur 08/04/2004 05:00 AM 766 size4_im.cur 08/04/2004 05:00 AM 766 size4_l.cur 08/04/2004 05:00 AM 766 size4_m.cur 08/04/2004 05:00 AM 326 size4_r.cur 08/04/2004 05:00 AM 766 size4_rl.cur 08/04/2004 05:00 AM 766 size4_rm.cur 08/04/2004 05:00 AM 818 sizenesw.ani 08/04/2004 05:00 AM 818 sizens.ani 08/04/2004 05:00 AM 818 sizenwse.ani 08/04/2004 05:00 AM 818 sizewe.ani 08/04/2004 05:00 AM 6,712 stopwtch.ani 08/04/2004 05:00 AM 326 up_i.cur 08/04/2004 05:00 AM 326 up_il.cur 08/04/2004 05:00 AM 326 up_im.cur 08/04/2004 05:00 AM 766 up_l.cur 08/04/2004 05:00 AM 766 up_m.cur 08/04/2004 05:00 AM 326 up_r.cur 08/04/2004 05:00 AM 326 up_rl.cur 08/04/2004 05:00 AM 326 up_rm.cur 08/04/2004 05:00 AM 1,894 vanisher.ani 08/04/2004 05:00 AM 2,548 wagtail.ani 08/04/2004 05:00 AM 326 wait_i.cur 08/04/2004 05:00 AM 766 wait_il.cur 08/04/2004 05:00 AM 766 wait_im.cur 08/04/2004 05:00 AM 766 wait_l.cur 08/04/2004 05:00 AM 766 wait_m.cur 08/04/2004 05:00 AM 326 wait_r.cur 08/04/2004 05:00 AM 766 wait_rl.cur 08/04/2004 05:00 AM 766 wait_rm.cur 185 File(s) 308,127 bytes 2 Dir(s) 144,407,957,504 bytes free Thank you again for your help and if there is anymore info you neeed just ask!
Step 1:

Please download Process Explorer by Systernals from:

Process Explorer

Also download/unzip KillBox by Option^Explicit from:

Killbox.zip

Step 2:

Download this file and save it to your desktop:

FixVundo Registry File

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\Cursors\bvdvd.bak1
C:\WINDOWS\Cursors\bvdvd.bak2
C:\WINDOWS\Cursors\bvdvd.ini
C:\WINDOWS\Cursors\dvdvb.dll


Step 3:

Print out the following instructions as you will not have Internet Access for the rest of this fix.

Reboot in "safe" mode.

The rest of this fix must be done in safe mode.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of C:\WINDOWS\Cursors\dvdvb.dll once and then click the kill button.

After you have killed all of the C:\WINDOWS\Cursors\dvdvb.dll under winlogon click OK.

If you see any of the files listed below, kill them as well.

Files to look for:
————————–
C:\WINDOWS\Cursors\bvdvd.bak1
C:\WINDOWS\Cursors\bvdvd.bak2
C:\WINDOWS\Cursors\bvdvd.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present.

Next double-click on explorer.exe, select the Threads tab, and again click once on each instance of C:\WINDOWS\Cursors\dvdvb.dll then click the kill button.

If you see any of the files listed below kill them as well.

Files to look for:
————————–
C:\WINDOWS\Cursors\bvdvd.bak1
C:\WINDOWS\Cursors\bvdvd.bak2
C:\WINDOWS\Cursors\bvdvd.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present.

Once you have done that click OK again.

Next run Hijack This! and place a check beside each of the following.

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Cursors\dvdvb.dll

O20 - Winlogon Notify: dvdvb - C:\WINDOWS\Cursors\dvdvb.dll

Now click Fix checked and close HijackThis.

Now double-click on the vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.

Step 4:

On the desktop, open the "killme.txt" file with Notepad.

Then copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C):

Close "killme.txt".

Double click on Killbox.exe and then check the Delete on reboot button.

In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new log file into this thread. :)
Okay here is the new HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:56:26 PM, on 9/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\stsystra.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html?p=DS
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1124347419656
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks so very much for everything Micah let me know if there is any more info you need or if there is anything else i need to do to this PC.
Only one thing:

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll

My Search

If you uninstall it, reboot afterwards.

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

I will remove it first thing bud. Again I appreciate all your time and help Micah. I guess if anything good has came from his problem is that I have learned some about Winfixer and found a really good site online. Thank you and I will be around, hopefully I can return the favor for someone else!
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI