This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

winfixer2000 removal help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been attached by winfixer2000 and probably other ad-ware stuff. Can you help me remove this stuff? Here is my hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 9:02:29 PM, on 9/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Nhksrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\windows\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\DELLMMKB.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\windows\System32\devldr32.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\SIERRA\Planner\PLNRnote.exe
C:\WINDOWS\System32\HPHipm09.exe
C:\Program Files\Netropa\OSD.exe
C:\windows\System32\wuauclt.exe
C:\Documents and Settings\Gary\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaul…://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.trustyhound.com/sidebar-search.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\windows\System32\awtsq.dll
O2 - BHO: (no name) - {8E13DDE1-E013-47ec-9C4C-27C2F78BDD26} - C:\windows\system32\geebx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\douqjbv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = C:\SIERRA\Planner\PLNRnote.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…ials/ymmapi.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup…er/imloader.cab
O20 - Winlogon Notify: awtsq - C:\windows\System32\awtsq.dll
O20 - Winlogon Notify: awtsr - C:\windows\System32\awtsr.dll
O20 - Winlogon Notify: awtss - C:\windows\System32\awtss.dll
O20 - Winlogon Notify: awvtu - C:\windows\System32\awvtu.dll
O20 - Winlogon Notify: ckpNotify - C:\windows\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: ddayx - C:\windows\System32\ddayx.dll
O20 - Winlogon Notify: ddccy - C:\windows\System32\ddccy.dll
O20 - Winlogon Notify: ddcya - C:\windows\System32\ddcya.dll
O20 - Winlogon Notify: gebcb - C:\windows\System32\gebcb.dll
O20 - Winlogon Notify: gebyv - C:\windows\System32\gebyv.dll
O20 - Winlogon Notify: gebyw - C:\windows\System32\gebyw.dll
O20 - Winlogon Notify: gebyy - C:\windows\System32\gebyy.dll
O20 - Winlogon Notify: geeba - C:\windows\System32\geeba.dll
O20 - Winlogon Notify: geebx - C:\windows\SYSTEM32\geebx.dll
O20 - Winlogon Notify: jkhhe - C:\windows\System32\jkhhe.dll
O20 - Winlogon Notify: mllji - C:\windows\System32\mllji.dll
O20 - Winlogon Notify: mllmj - C:\windows\System32\mllmj.dll
O20 - Winlogon Notify: mllmm - C:\windows\System32\mllmm.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: pmkhg - C:\windows\System32\pmkhg.dll
O20 - Winlogon Notify: ssqpp - C:\windows\System32\ssqpp.dll
O20 - Winlogon Notify: ssqrr - C:\windows\System32\ssqrr.dll
O20 - Winlogon Notify: sstqo - C:\windows\System32\sstqo.dll
O20 - Winlogon Notify: sstqr - C:\windows\System32\sstqr.dll
O20 - Winlogon Notify: vtsqr - C:\windows\System32\vtsqr.dll
O20 - Winlogon Notify: vturo - C:\windows\System32\vturo.dll
O20 - Winlogon Notify: vtutq - C:\windows\System32\vtutq.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\windows\Nhksrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe

:blink: :(
Greetings and welcome to TomCoyote.org!

Run Hijack This!

Click the "Open the Misc Tools section" button.

Click the "Open process manager" button.

Check the "Show DLLs" box (upper right).

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using these DLL's:

c:\windows\system32\awtsq.dll
c:\windows\system32\awtsr.dll
c:\windows\system32\awtss.dll
c:\windows\system32\awvtu.dll
c:\windows\system32\ddayx.dll
c:\windows\system32\ddccy.dll
c:\windows\system32\ddcya.dll
c:\windows\system32\gebcb.dll
c:\windows\system32\gebyv.dll
c:\windows\system32\gebyw.dll
c:\windows\system32\gebyy.dll
c:\windows\system32\geeba.dll
c:\windows\system32\geebx.dll
c:\windows\system32\jkhhe.dll
c:\windows\system32\mllji.dll
c:\windows\system32\mllmj.dll
c:\windows\system32\mllmm.dll
c:\windows\system32\pmkhg.dll
c:\windows\system32\ssqpp.dll
c:\windows\system32\ssqrr.dll
c:\windows\system32\sstqo.dll
c:\windows\system32\sstqr.dll
c:\windows\system32\vtsqr.dll
c:\windows\system32\vturo.dll
c:\windows\system32\vtutq.dll


Post back letting me know all processes using those DLL's.

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe

http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing .

This will scan your computer and it may appear nothing is happening, then, after a minute or 2, Notepad will open with a log. Copy/paste the contents of that log into this thread.


IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
There are three processes that have a few of the dll's in them. These are; 784 C:|windows\system32\winlogon.exe 208 C:\windows\explorer.exe 3672 C:\Program Files\Internet Explorer\iexplorer.exe Below is the l2mfix.log L2MFIX find log 1.04a These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtsq] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\awtsq.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtsr] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\awtsr.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtss] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\awtss.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvtu] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\awvtu.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ckpNotify] "Asynchronous"=dword:00000000 "DLLName"="ckpNotify.dll" "Impersonate"=dword:00000001 "Logoff"="WLEventLogOff" "Logon"="WLEventLogOn" "Shutdown"="WLEventShutDown" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\ 6c,00,00,00 "Logoff"="ChainWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet] "Asynchronous"=dword:00000000 "Impersonate"=dword:00000000 "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\ 6c,00,6c,00,00,00 "Logoff"="CryptnetWlxLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll] "DLLName"="cscdll.dll" "Logon"="WinlogonLogonEvent" "Logoff"="WinlogonLogoffEvent" "ScreenSaver"="WinlogonScreenSaverEvent" "Startup"="WinlogonStartupEvent" "Shutdown"="WinlogonShutdownEvent" "StartShell"="WinlogonStartShellEvent" "Impersonate"=dword:00000000 "Asynchronous"=dword:00000001 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddayx] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\ddayx.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddccb] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\ddccb.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddccy] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\ddccy.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcya] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\ddcya.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcb] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\gebcb.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\gebyv.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyw] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\gebyw.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyy] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\gebyy.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geeba] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\geeba.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geebx] "Asynchronous"=dword:00000001 "DllName"="geebx.dll" "Impersonate"=dword:00000000 "Logon"="Logon" "Logoff"="Logoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhe] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\jkhhe.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhi] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\jkhhi.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllji] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\mllji.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\mllmj.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmm] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\mllmm.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] "DllName"="C:\\WINDOWS\\System32\\NavLogon.dll" "StartShell"="NavStartShellEvent" "Logoff"="NavLogoffEvent" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg] "Asynchronous"=dword:00000001 "DllName"="C:\\windows\\System32\\pmkhg.dll" "Impersonate"=dword:00000000 "Startup"="SysLogon" "Logoff"="SysLogoff"
Actually, all I need from the log is the "end":

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:


From that point to the end of the log is really all I need.
:) :thumbup:
Here is what you are asking for. Thanks for letting me know this is the worst case of SHI### you have seen. At least i know i have a job infront of me that is not wasting your time. KEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: C:\WINDOWS\SYSTEM32\ awtsq.dll Sat Sep 24 2005 7:09:02a ..SH. 516,116 504.02 K awtsr.dll Fri Sep 23 2005 7:07:56a ..SH. 516,116 504.02 K awtss.dll Sat Sep 10 2005 5:34:06a ..SH. 516,116 504.02 K awvtu.dll Tue Sep 13 2005 8:56:34p ..SH. 516,116 504.02 K ddaya.dll Sat Aug 27 2005 11:54:28p A…. 14,303 13.96 K ddayx.dll Thu Sep 15 2005 8:58:22p ..SH. 516,116 504.02 K ddccb.dll Sun Sep 25 2005 8:32:08a ..SH. 516,116 504.02 K ddccy.dll Thu Sep 8 2005 11:33:50p ..SH. 516,116 504.02 K ddcya.dll Tue Aug 30 2005 7:20:36a ..SH. 516,116 504.02 K gebcb.dll Mon Sep 5 2005 7:26:18p ..SH. 516,116 504.02 K gebyv.dll Wed Sep 14 2005 8:58:14p ..SH. 516,116 504.02 K gebyw.dll Fri Sep 16 2005 8:59:56p ..SH. 516,116 504.02 K gebyy.dll Sat Sep 3 2005 5:42:22p ..SH. 516,116 504.02 K geeba.dll Mon Sep 19 2005 10:58:04p ..SH. 516,116 504.02 K geebx.dll Tue Aug 23 2005 10:18:22p A.SH. 25,088 24.50 K icm32.dll Tue Jun 28 2005 9:54:58p A…. 237,056 231.50 K jkhhe.dll Tue Sep 13 2005 8:56:36p ..SH. 516,116 504.02 K jkhhi.dll Mon Sep 26 2005 4:48:48p ..SH. 516,116 504.02 K mllji.dll Mon Aug 29 2005 6:22:10a ..SH. 516,116 504.02 K mllmj.dll Sat Sep 17 2005 9:21:34p ..SH. 516,116 504.02 K mllmm.dll Thu Sep 8 2005 11:33:48p ..SH. 516,116 504.02 K mscms.dll Tue Jun 28 2005 9:54:58p A…. 68,608 67.00 K mshtml.dll Mon Jul 18 2005 4:22:12p A…. 2,699,264 2.57 M pmkhg.dll Wed Sep 7 2005 11:33:30p ..SH. 516,116 504.02 K ssqpp.dll Tue Sep 6 2005 7:56:20p ..SH. 516,116 504.02 K ssqrr.dll Thu Sep 8 2005 11:33:48p ..SH. 516,116 504.02 K sstqo.dll Fri Sep 16 2005 8:59:56p ..SH. 516,116 504.02 K sstqq.dll Mon Sep 26 2005 4:48:52p ..SH. 516,116 504.02 K sstqr.dll Tue Sep 20 2005 11:12:32p ..SH. 516,116 504.02 K tapisrv.dll Fri Jul 8 2005 12:09:48p A…. 238,592 233.00 K umpnpmgr.dll Wed Jun 29 2005 10:15:30p A…. 107,520 105.00 K vtsqr.dll Sun Sep 18 2005 9:33:48p ..SH. 516,116 504.02 K vturo.dll Sun Sep 11 2005 6:58:36a ..SH. 516,116 504.02 K vtutq.dll Thu Sep 8 2005 11:33:52p ..SH. 516,116 504.02 K 34 items found: 34 files (28 H/S), 0 directories. Total of file sizes: 17,325,563 bytes 16.52 M Locate .tmp files: C:\WINDOWS\SYSTEM32\ mcrh.tmp Thu Sep 22 2005 5:23:28p A…. 0 0.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 0 bytes 0.00 K ********************************************************************************** Directory Listing of system files: Volume in drive C is DRV2_VOL1 Volume Serial Number is BC1C-E103 Directory of C:\windows\System32 09/26/2005 08:35 PM 424,937 qstwa.ini 09/26/2005 04:48 PM 303 qqtss.ini 09/26/2005 04:48 PM 516,116 sstqq.dll 09/26/2005 04:48 PM 303 ihhkj.ini 09/26/2005 04:48 PM 516,116 jkhhi.dll 09/25/2005 09:05 PM 423,679 qstwa.bak2 09/25/2005 08:32 AM 303 bccdd.ini 09/25/2005 08:32 AM 516,116 ddccb.dll 09/24/2005 08:44 PM 425,306 rstwa.ini 09/24/2005 07:09 AM 516,116 awtsq.dll 09/23/2005 08:27 PM 422,298 rstwa.bak2 09/23/2005 08:21 PM 423,857 sstwa.ini 09/23/2005 06:10 PM DLLCACHE 09/23/2005 07:07 AM 516,116 awtsr.dll 09/23/2005 07:07 AM 423,647 sstwa.bak2 09/20/2005 11:12 PM 303 rqtss.ini 09/20/2005 11:12 PM 516,116 sstqr.dll 09/19/2005 10:58 PM 303 abeeg.ini 09/19/2005 10:58 PM 516,116 geeba.dll 09/18/2005 09:33 PM 303 rqstv.ini 09/18/2005 09:33 PM 516,116 vtsqr.dll 09/18/2005 10:32 AM 423,714 aycdd.ini 09/17/2005 09:21 PM 303 jmllm.ini 09/17/2005 09:21 PM 516,116 mllmj.dll 09/17/2005 09:21 PM 423,111 aycdd.bak2 09/16/2005 08:59 PM 303 wybeg.ini 09/16/2005 08:59 PM 303 oqtss.ini 09/16/2005 08:59 PM 516,116 gebyw.dll 09/16/2005 08:59 PM 516,116 sstqo.dll 09/15/2005 08:58 PM 303 xyadd.ini 09/15/2005 08:58 PM 516,116 ddayx.dll 09/14/2005 08:58 PM 303 vybeg.ini 09/14/2005 08:58 PM 516,116 gebyv.dll 09/13/2005 08:56 PM 303 ehhkj.ini 09/13/2005 08:56 PM 303 utvwa.ini 09/13/2005 08:56 PM 516,116 jkhhe.dll 09/13/2005 08:56 PM 516,116 awvtu.dll 09/11/2005 06:58 AM 303 orutv.ini 09/11/2005 06:58 AM 516,116 vturo.dll 09/10/2005 05:34 AM 516,116 awtss.dll 09/08/2005 11:33 PM 303 yccdd.ini 09/08/2005 11:33 PM 303 qtutv.ini 09/08/2005 11:33 PM 516,116 vtutq.dll 09/08/2005 11:33 PM 516,116 ddccy.dll 09/08/2005 11:33 PM 303 rrqss.ini 09/08/2005 11:33 PM 303 mmllm.ini 09/08/2005 11:33 PM 516,116 ssqrr.dll 09/08/2005 11:33 PM 516,116 mllmm.dll 09/07/2005 11:33 PM 303 ghkmp.ini 09/07/2005 11:33 PM 516,116 pmkhg.dll 09/06/2005 07:56 PM 303 ppqss.ini 09/06/2005 07:56 PM 516,116 ssqpp.dll 09/05/2005 07:26 PM 303 bcbeg.ini 09/05/2005 07:26 PM 516,116 gebcb.dll 09/03/2005 05:42 PM 303 yybeg.ini 09/03/2005 05:42 PM 516,116 gebyy.dll 09/01/2005 05:27 PM 179,317 ijllm.ini 09/01/2005 05:17 PM 179,640 ijllm.bak2 08/30/2005 07:20 AM 516,116 ddcya.dll 08/29/2005 06:22 AM 178,370 ijllm.bak1 08/29/2005 06:22 AM 516,116 mllji.dll 08/23/2005 10:18 PM 25,088 geebx.dll 08/04/2005 12:04 AM Microsoft 08/29/2002 06:41 AM 569,344 oleaut32.dll 08/29/2002 06:41 AM 323,072 msvcrt.dll 08/29/2002 06:41 AM 401,462 msvcp60.dll 08/18/2001 08:00 AM 995,383 mfc42.dll 08/18/2001 08:00 AM 106,496 OLEPRO32.DLL 08/18/2001 08:00 AM 9,728 REGSVR32.EXE 08/18/2001 08:00 AM 50,688 msvcirt.dll 68 File(s) 20,350,935 bytes 2 Dir(s) 114,686,517,248 bytes free
Step 1:

Please download Process Explorer by Systernals from:

Process Explorer

Also download/unzip KillBox by Option^Explicit from:

Killbox.zip

Step 2:

Download this file and save it to your desktop:

FixVundo Registry File

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\SYSTEM32\awtsq.dll
C:\WINDOWS\SYSTEM32\qstwa.bak2
C:\WINDOWS\SYSTEM32\qstwa.ini
C:\WINDOWS\SYSTEM32\awtsr.dll
C:\WINDOWS\SYSTEM32\rstwa.bak2
C:\WINDOWS\SYSTEM32\rstwa.ini
C:\WINDOWS\SYSTEM32\awtss.dll
C:\WINDOWS\SYSTEM32\sstwa.bak2
C:\WINDOWS\SYSTEM32\sstwa.ini
C:\WINDOWS\SYSTEM32\awvtu.dll
C:\WINDOWS\SYSTEM32\utvwa.ini
C:\WINDOWS\SYSTEM32\ddaya.dll
C:\WINDOWS\SYSTEM32\ddayx.dll
C:\WINDOWS\SYSTEM32\xyadd.ini
C:\WINDOWS\SYSTEM32\ddccb.dll
C:\WINDOWS\SYSTEM32\bccdd.ini
C:\WINDOWS\SYSTEM32\ddccy.dll
C:\WINDOWS\SYSTEM32\yccdd.ini
C:\WINDOWS\SYSTEM32\ddcya.dll
C:\WINDOWS\SYSTEM32\aycdd.bak2
C:\WINDOWS\SYSTEM32\aycdd.ini
C:\WINDOWS\SYSTEM32\gebcb.dll
C:\WINDOWS\SYSTEM32\bcbeg.ini
C:\WINDOWS\SYSTEM32\gebyv.dll
C:\WINDOWS\SYSTEM32\vybeg.ini
C:\WINDOWS\SYSTEM32\gebyw.dll
C:\WINDOWS\SYSTEM32\wybeg.ini
C:\WINDOWS\SYSTEM32\gebyy.dll
C:\WINDOWS\SYSTEM32\yybeg.ini
C:\WINDOWS\SYSTEM32\geeba.dll
C:\WINDOWS\SYSTEM32\abeeg.ini
C:\WINDOWS\SYSTEM32\geebx.dll
C:\WINDOWS\SYSTEM32\jkhhe.dll
C:\WINDOWS\SYSTEM32\ehhkj.ini
C:\WINDOWS\SYSTEM32\jkhhi.dll
C:\WINDOWS\SYSTEM32\ihhkj.ini
C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\ijllm.bak1
C:\WINDOWS\SYSTEM32\ijllm.bak2
C:\WINDOWS\SYSTEM32\ijllm.ini
C:\WINDOWS\SYSTEM32\mllmj.dll
C:\WINDOWS\SYSTEM32\jmllm.ini
C:\WINDOWS\SYSTEM32\mllmm.dll
C:\WINDOWS\SYSTEM32\mmllm.ini
C:\WINDOWS\SYSTEM32\pmkhg.dll
C:\WINDOWS\SYSTEM32\ghkmp.ini
C:\WINDOWS\SYSTEM32\ssqpp.dll
C:\WINDOWS\SYSTEM32\ppqss.ini
C:\WINDOWS\SYSTEM32\ssqrr.dll
C:\WINDOWS\SYSTEM32\rrqss.ini
C:\WINDOWS\SYSTEM32\sstqo.dll
C:\WINDOWS\SYSTEM32\oqtss.ini
C:\WINDOWS\SYSTEM32\sstqq.dll
C:\WINDOWS\SYSTEM32\qqtss.ini
C:\WINDOWS\SYSTEM32\sstqr.dll
C:\WINDOWS\SYSTEM32\rqtss.ini
C:\WINDOWS\SYSTEM32\vtsqr.dll
C:\WINDOWS\SYSTEM32\rqstv.ini
C:\WINDOWS\SYSTEM32\vturo.dll
C:\WINDOWS\SYSTEM32\orutv.ini
C:\WINDOWS\SYSTEM32\vtutq.dll
C:\WINDOWS\SYSTEM32\qtutv.ini
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\douqjbv.exe


Step 3:

Print out the following instructions as you will not have Internet Access for the rest of this fix.

Reboot in "safe" mode.

The rest of this fix must be done in safe mode.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of:

awtsq.dll

once and then click the kill button.

After you have killed all of:

awtsq.dll

under winlogon click OK.

If you see any of the files listed below, kill them as well.

Files to look for:
————————–
abeeg.ini
awtsr.dll
awtss.dll
awvtu.dll
aycdd.bak2
aycdd.ini
bcbeg.ini
bccdd.ini
ddaya.dll
ddayx.dll
ddccb.dll
ddccy.dll
ddcya.dll
ehhkj.ini
gebcb.dll
gebyv.dll
gebyw.dll
gebyy.dll
geeba.dll
geebx.dll
ghkmp.ini
ihhkj.ini
ijllm.bak1
ijllm.bak2
ijllm.ini
jkhhe.dll
jkhhi.dll
jmllm.ini
mllji.dll
mllmj.dll
mllmm.dll
mmllm.ini
oqtss.ini
orutv.ini
pmkhg.dll
ppqss.ini
qqtss.ini
qstwa.bak2
qstwa.ini
qtutv.ini
rqtss.ini
rqstv.ini
rrqss.ini
rstwa.bak2
rstwa.ini
ssqpp.dll
ssqrr.dll
sstqo.dll
sstqq.dll
sstqr.dll
sstwa.bak2
sstwa.ini
utvwa.ini
vtsqr.dll
vturo.dll
vtutq.dll
vybeg.ini
wybeg.ini
xyadd.ini
yccdd.ini
yybeg.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK.

Next double-click on explorer.exe, select the Threads tab, and again click once on each instance of:

awtsq.dll

then click the kill button.

If you see any of the files listed below kill them as well.

Files to look for:
————————–
abeeg.ini
awtsr.dll
awtss.dll
awvtu.dll
aycdd.bak2
aycdd.ini
bcbeg.ini
bccdd.ini
ddaya.dll
ddayx.dll
ddccb.dll
ddccy.dll
ddcya.dll
ehhkj.ini
gebcb.dll
gebyv.dll
gebyw.dll
gebyy.dll
geeba.dll
geebx.dll
ghkmp.ini
ihhkj.ini
ijllm.bak1
ijllm.bak2
ijllm.ini
jkhhe.dll
jkhhi.dll
jmllm.ini
mllji.dll
mllmj.dll
mllmm.dll
mmllm.ini
oqtss.ini
orutv.ini
pmkhg.dll
ppqss.ini
qqtss.ini
qstwa.bak2
qstwa.ini
qtutv.ini
rqtss.ini
rqstv.ini
rrqss.ini
rstwa.bak2
rstwa.ini
ssqpp.dll
ssqrr.dll
sstqo.dll
sstqq.dll
sstqr.dll
sstwa.bak2
sstwa.ini
utvwa.ini
vtsqr.dll
vturo.dll
vtutq.dll
vybeg.ini
wybeg.ini
xyadd.ini
yccdd.ini
yybeg.ini

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK

Once you have done that click OK again.

Next run Hijack This! and place a check beside each of the following.

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\windows\System32\awtsq.dll

O2 - BHO: (no name) - {8E13DDE1-E013-47ec-9C4C-27C2F78BDD26} - C:\windows\system32\geebx.dll

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\douqjbv.exe

O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup…er/imloader.cab

O20 - Winlogon Notify: awtsq - C:\windows\System32\awtsq.dll

O20 - Winlogon Notify: awtsr - C:\windows\System32\awtsr.dll

O20 - Winlogon Notify: awtss - C:\windows\System32\awtss.dll

O20 - Winlogon Notify: awvtu - C:\windows\System32\awvtu.dll

O20 - Winlogon Notify: ddayx - C:\windows\System32\ddayx.dll

O20 - Winlogon Notify: ddccy - C:\windows\System32\ddccy.dll

O20 - Winlogon Notify: ddcya - C:\windows\System32\ddcya.dll

O20 - Winlogon Notify: gebcb - C:\windows\System32\gebcb.dll

O20 - Winlogon Notify: gebyv - C:\windows\System32\gebyv.dll

O20 - Winlogon Notify: gebyw - C:\windows\System32\gebyw.dll

O20 - Winlogon Notify: gebyy - C:\windows\System32\gebyy.dll

O20 - Winlogon Notify: geeba - C:\windows\System32\geeba.dll

O20 - Winlogon Notify: geebx - C:\windows\SYSTEM32\geebx.dll

O20 - Winlogon Notify: jkhhe - C:\windows\System32\jkhhe.dll

O20 - Winlogon Notify: mllji - C:\windows\System32\mllji.dll

O20 - Winlogon Notify: mllmj - C:\windows\System32\mllmj.dll

O20 - Winlogon Notify: mllmm - C:\windows\System32\mllmm.dll

O20 - Winlogon Notify: pmkhg - C:\windows\System32\pmkhg.dll

O20 - Winlogon Notify: ssqpp - C:\windows\System32\ssqpp.dll

O20 - Winlogon Notify: ssqrr - C:\windows\System32\ssqrr.dll

O20 - Winlogon Notify: sstqo - C:\windows\System32\sstqo.dll

O20 - Winlogon Notify: sstqr - C:\windows\System32\sstqr.dll

O20 - Winlogon Notify: vtsqr - C:\windows\System32\vtsqr.dll

O20 - Winlogon Notify: vturo - C:\windows\System32\vturo.dll

O20 - Winlogon Notify: vtutq - C:\windows\System32\vtutq.dll

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Now click Fix checked and close HijackThis.

Now double-click on the vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.

Step 4:

On the desktop, open the "killme.txt" file with Notepad.

Then copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C):

Close "killme.txt".

Double click on Killbox.exe and then check the Delete on reboot button.

In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new Hijack This! log file into this thread. :)
Boy you are good. Thanks for all your help. This is the hijackthis log after performing all your requests.

Thanks again.

Logfile of HijackThis v1.99.1
Scan saved at 11:39:33 PM, on 9/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Nhksrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\windows\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\DELLMMKB.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\windows\System32\devldr32.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\HPHipm09.exe
C:\SIERRA\Planner\PLNRnote.exe
C:\Program Files\Netropa\OSD.exe
C:\windows\System32\wuauclt.exe
C:\windows\System32\wuauclt.exe
C:\Documents and Settings\Gary\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaul…://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.trustyhound.com/sidebar-search.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\douqjbv.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = C:\SIERRA\Planner\PLNRnote.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…ials/ymmapi.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O20 - Winlogon Notify: ckpNotify - C:\windows\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\windows\Nhksrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
You got rid of the worst of it!!! :thumbup:

A few things remain….

Go to:

Start –> Run

In the "run" box, paste the next line in, then hit (or click OK):

sc delete .NET Connection Service

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

C:\WINDOWS\System32\douqjbv.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe


CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\douqjbv.exe

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new log file into this thread. :)
Thank you so much. You guys are good. This was a chore. It's amasing what you know. I learn a lot when dealing with these types of problems.

Thanks again. Here is the HIJACKTHIS log. I hope it is the last one.

Logfile of HijackThis v1.99.1
Scan saved at 10:09:37 PM, on 9/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\Nhksrv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\windows\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\DELLMMKB.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\windows\System32\devldr32.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\HPHipm09.exe
C:\Program Files\Netropa\OSD.exe
C:\SIERRA\Planner\PLNRnote.exe
C:\windows\System32\wuauclt.exe
C:\windows\System32\wuauclt.exe
C:\Documents and Settings\Gary\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/ymsgr/defaul…://my.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.trustyhound.com/sidebar-search.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = C:\SIERRA\Planner\PLNRnote.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…ials/ymmapi.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O20 - Winlogon Notify: ckpNotify - C:\windows\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\windows\Nhksrv.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe

:P :wavey: :weee: B)
:scratch:
This is still in the log:

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

But, since it says "(file missing)", it's not anything to worry about.

I think you're "good to go". :thumbup:

GOD bless you!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI