This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help with My Hijackthis Logfile

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:09:08 PM, on 07/10/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
C:\ewido anti-malware\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Windows\xpupdate.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\VoipStunt\VoipStunt.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_29.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DW4] "F:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Shell] "F:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe"
O4 - HKCU\..\Run: [Key] F:\DOCUME~1\roger\LOCALS~1\Temp\C0.tmp
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [taskdir] F:\WINDOWS\system32\taskdir.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Translate English Word - res://F:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} - http://download.movienetworks.com/install/US/altpmtscab.cab
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} (VacPro.internazionale_ver15) - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O20 - Winlogon Notify: Internet Settings - F:\WINDOWS\system32\l42s0ef7eh2.dll
O20 - Winlogon Notify: lanH32 - F:\WINDOWS\SYSTEM32\lanH32.dll
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - F:\WINDOWS\system32\dcom_14.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - c:\ewido anti-malware\oijdai3.dll
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
Hi Siggyx, sorry I posted in the wrong place, ok here is my most recent HJT log file

Logfile of HijackThis v1.99.1
Scan saved at 9:17:19 AM, on 03/13/2002
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
C:\ewido anti-malware\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Windows\xpupdate.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\VoipStunt\VoipStunt.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
F:\Program Files\Mozilla Firefox\plugins\GetFlash.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_53.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DW4] "F:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Key] F:\DOCUME~1\roger\LOCALS~1\Temp\C0.tmp
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [taskdir] F:\WINDOWS\system32\taskdir.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Translate English Word - res://F:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O20 - Winlogon Notify: Internet Settings - F:\WINDOWS\system32\l42s0ef7eh2.dll (file missing)
O20 - Winlogon Notify: WRNotifier - F:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - c:\ewido anti-malware\oijdai3.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

THANKS VERY MUCH!!!
Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Here is my new HJT log file. Thanks!!!


Logfile of HijackThis v1.99.1
Scan saved at 4:36:27 PM, on 03/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
C:\ewido anti-malware\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Windows\xpupdate.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\WINDOWS\explorer.exe
F:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
F:\Program Files\Mozilla Firefox\firefox.exe
C:\VoipStunt\VoipStunt.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Microsoft Office\Office10\WINWORD.EXE
F:\WINDOWS\msagent\AgentSvr.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_FC.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [InternetCalls] "C:\InternetCalls\InternetCalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Translate English Word - res://F:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://F:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://F:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://F:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://F:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Click here to run ActiveScan.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Paste the contents of the Panda scan report along with a new HijackThis Log in your next reply.
Here are the results of the panda scan and HJT! I still get the " Your Computer is in Danger" message thing.I run smitrem immediately to restore my desktop settings when the screen goes Black with the annoying pop-up Your Computer is in …" message. I also delete/uninstall Bravesentry whenever it tries to install itself. Recently, I can't play any video in Windows Media Player, Error ID:0xC00D11CD/Real Player/Quick Time/DivX, qt-mt331.dll not found/quartz.dll not found. Thanks!


PANDA SCAN RESULT

Incident Status Location

Adware:Adware/SpySheriff Not disinfected C:\WINDOWS\XPUPDATE.EXE
Adware:Adware/SpySheriff Not disinfected C:\Windows\xpupdate.exe
Adware:adware/spysheriff Not disinfected F:\WINDOWS\SYSTEM32\kernels8.exe
Adware:adware/admess Not disinfected F:\WINDOWS\SYSTEM32\tmp3.txt
Adware:adware/adsmart Not disinfected F:\WINDOWS\SYSTEM32\vxgamet4.exe2560.exe
Adware:adware/secure32 Not disinfected F:\WINDOWS\country.exe
Dialer:dialer.bny Not disinfected F:\WINDOWS\pcconfig.dat
Spyware:application/bestoffer Not disinfected F:\WINDOWS\smdat32m.sys
Adware:adware/cws.searchmeup Not disinfected F:\WINDOWS\uniq
Potentially unwanted tool:application/winantivirus2006 Not disinfected F:\PROGRAM FILES\WinAntiVirus Pro 2006
Adware:adware/cws Not disinfected F:\Documents and Settings\roger\Favorites\Going Places
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CLASSES_ROOT\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Dialer:dialer.bkj Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E}
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Cookies\[removed][2].txt
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Cookies\roger@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Cookies\roger@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Cookies\roger@bluestreak[2].txt
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Cookies\roger@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Cookies\roger@mediaplex[1].txt
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Cookies\roger@serving-sys[1].txt
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Cookies\roger@xiti[1].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Casalemedia Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/BurstNet Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Tribalfusion Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/2o7 Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/S109826]
Spyware:Cookie/HotLog Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Falkag Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[as1.falkag.de/]
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Xmts Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.xmts.net/]
Spyware:Cookie/Adtech Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Adverserve Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.adverserve.net/]
Spyware:Cookie/Findwhat Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.findwhat.com/]
Spyware:Cookie/Zedo Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.zedo.com/]
Spyware:Cookie/FastClick Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/cs.sexcounter Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Falkag Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Maxserving Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Overture Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Statcounter Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Clickbank Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Weborama Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Coremetrics Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/dcsoiy6ume9xjyybepcdy5h25_3z9c]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.phg.hitbox.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\roger\Cookies\roger@tucows[1].txt
Adware:Adware/DollarRevenue Not disinfected C:\keyboard1.exe
Potentially unwanted tool:Application/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry1.dll
Adware:Adware/SpySheriff Not disinfected C:\Program Files\BraveSentry\BraveSentry2.dll
Potentially unwanted tool:Application/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry3.dll
Adware:Adware/SpySheriff Not disinfected C:\WINDOWS\xpupdate.exe
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[S109826]
Spyware:Cookie/HotLog Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[dcsoiy6ume9xjyybepcdy5h25_3z9c]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Cookies\[removed][2].txt
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Cookies\roger@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Cookies\roger@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Cookies\roger@bluestreak[2].txt
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Cookies\roger@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Cookies\roger@mediaplex[1].txt
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Cookies\roger@serving-sys[1].txt
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Cookies\roger@xiti[1].txt
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\Cameroon Environmental situation_files\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\smitRem.exe[Process.exe]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected F:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
Potentially unwanted tool:Application/Processor Not disinfected F:\Program Files\Mozilla Firefox\smitRem\Process.exe
Virus:W32/Smitfraud.B Not disinfected F:\WINDOWS\$NtUninstallKB896688$\wininet.dll
Virus:Bck/Haxdoor.IN Not disinfected F:\WINDOWS\country.exe
Virus:Trj/Qhost.Y Not disinfected F:\WINDOWS\system32\drivers\etc\HOSTS.bak
Adware:Adware/Tibs Not disinfected F:\WINDOWS\system32\kernels8.exe
Virus:Trj/Downloader.HZX Not disinfected F:\WINDOWS\system32\syst6t.exe
Virus:Trj/Downloader.HZC Not disinfected F:\WINDOWS\system32\tmp_811.dll


Logfile of HijackThis v1.99.1
Scan saved at 12:31:49 AM, on 03/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
C:\ewido anti-malware\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Windows\xpupdate.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\WINDOWS\explorer.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\Adobelm_Cleanup.0001
F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\Adobelm_Cleanup.0001
F:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
F:\Program Files\Microsoft Office\Office10\POWERPNT.EXE
F:\WINDOWS\msagent\AgentSvr.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_710.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [InternetCalls] "C:\InternetCalls\InternetCalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Google Desktop Search] "F:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://f:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Hi Siggyx, here again are the results of the Panda Scan and a recent HJT log file. Just thought I should let you know. I managed to deal away with the pop ups, but I still get the "Your computer is in Danger" Message thing. And whenever my screen goes Black with the "Your Computer is in …", I run smitrem immediately to restore my desktop settings. Recently, I can't play any video files from CDs. I think this happened after I downloaded Audacity 1.3 Beta. Since thereafter my video applications crashes. I get Error ID=0xC00D11CD in Windows MP, qt-mt331.dll not found error message in DivX, quartz.dll not found error in other applications. Thanks!!!

PANDA SCAN

Incident Status Location

Adware:Adware/SpySheriff Not disinfected C:\WINDOWS\XPUPDATE.EXE
Adware:Adware/SpySheriff Not disinfected C:\Windows\xpupdate.exe
Adware:adware/spysheriff Not disinfected F:\WINDOWS\SYSTEM32\kernels8.exe
Adware:adware/admess Not disinfected F:\WINDOWS\SYSTEM32\tmp3.txt
Adware:adware/adsmart Not disinfected F:\WINDOWS\SYSTEM32\vxgamet4.exe2560.exe
Adware:adware/secure32 Not disinfected F:\WINDOWS\country.exe
Dialer:dialer.bny Not disinfected F:\WINDOWS\pcconfig.dat
Spyware:application/bestoffer Not disinfected F:\WINDOWS\smdat32m.sys
Adware:adware/cws.searchmeup Not disinfected F:\WINDOWS\uniq
Potentially unwanted tool:application/winantivirus2006 Not disinfected F:\PROGRAM FILES\WinAntiVirus Pro 2006
Adware:adware/cws Not disinfected F:\Documents and Settings\roger\Favorites\Going Places
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CLASSES_ROOT\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Dialer:dialer.bkj Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E}
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Cookies\[removed][2].txt
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Cookies\roger@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Cookies\roger@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Cookies\roger@bluestreak[2].txt
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Cookies\roger@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Cookies\roger@mediaplex[1].txt
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Cookies\roger@serving-sys[1].txt
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Cookies\roger@xiti[1].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Casalemedia Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/BurstNet Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Tribalfusion Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/2o7 Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/S109826]
Spyware:Cookie/HotLog Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Falkag Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[as1.falkag.de/]
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Xmts Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.xmts.net/]
Spyware:Cookie/Adtech Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Adverserve Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.adverserve.net/]
Spyware:Cookie/Findwhat Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.findwhat.com/]
Spyware:Cookie/Zedo Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.zedo.com/]
Spyware:Cookie/FastClick Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/cs.sexcounter Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Falkag Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Maxserving Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Overture Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Statcounter Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Clickbank Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/Weborama Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Coremetrics Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[statse.webtrendslive.com/dcsoiy6ume9xjyybepcdy5h25_3z9c]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[.phg.hitbox.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\roger\Cookies\roger@tucows[1].txt
Adware:Adware/DollarRevenue Not disinfected C:\keyboard1.exe
Potentially unwanted tool:Application/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry1.dll
Adware:Adware/SpySheriff Not disinfected C:\Program Files\BraveSentry\BraveSentry2.dll
Potentially unwanted tool:Application/BraveSentry Not disinfected C:\Program Files\BraveSentry\BraveSentry3.dll
Adware:Adware/SpySheriff Not disinfected C:\WINDOWS\xpupdate.exe
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[S109826]
Spyware:Cookie/HotLog Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/WebtrendsLive Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[dcsoiy6ume9xjyybepcdy5h25_3z9c]
Spyware:Cookie/Hitbox Not disinfected F:\Documents and Settings\roger\Application Data\Mozilla\Firefox\Profiles\ck96qx41.default\cookies.txt[]
Spyware:Cookie/PointRoll Not disinfected F:\Documents and Settings\roger\Cookies\[removed][2].txt
Spyware:Cookie/Advertising Not disinfected F:\Documents and Settings\roger\Cookies\roger@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected F:\Documents and Settings\roger\Cookies\roger@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected F:\Documents and Settings\roger\Cookies\roger@bluestreak[2].txt
Spyware:Cookie/Doubleclick Not disinfected F:\Documents and Settings\roger\Cookies\roger@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected F:\Documents and Settings\roger\Cookies\roger@mediaplex[1].txt
Spyware:Cookie/Serving-sys Not disinfected F:\Documents and Settings\roger\Cookies\roger@serving-sys[1].txt
Spyware:Cookie/Xiti Not disinfected F:\Documents and Settings\roger\Cookies\roger@xiti[1].txt
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\Cameroon Environmental situation_files\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected F:\Documents and Settings\roger\Desktop\smitRem.exe[Process.exe]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected F:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
Potentially unwanted tool:Application/Processor Not disinfected F:\Program Files\Mozilla Firefox\smitRem\Process.exe
Virus:W32/Smitfraud.B Not disinfected F:\WINDOWS\$NtUninstallKB896688$\wininet.dll
Virus:Bck/Haxdoor.IN Not disinfected F:\WINDOWS\country.exe
Virus:Trj/Qhost.Y Not disinfected F:\WINDOWS\system32\drivers\etc\HOSTS.bak
Adware:Adware/Tibs Not disinfected F:\WINDOWS\system32\kernels8.exe
Virus:Trj/Downloader.HZX Not disinfected F:\WINDOWS\system32\syst6t.exe
Virus:Trj/Downloader.HZC Not disinfected F:\WINDOWS\system32\tmp_811.dll
Logfile of HijackThis v1.99.1
Scan saved at 4:25:29 PM, on 03/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
C:\ewido anti-malware\ewidoctrl.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Windows\xpupdate.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\WINDOWS\explorer.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Microsoft Hardware\Mouse\POINT32.EXE
F:\Program Files\Microsoft Office\Office10\WINWORD.EXE
F:\WINDOWS\msagent\AgentSvr.exe
C:\VoipStunt\VoipStunt.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_716.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [InternetCalls] "C:\InternetCalls\InternetCalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Google Desktop Search] "F:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://f:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\ewido anti-malware\ewidoctrl.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Download ATF Cleaner:
http://www.atribune.org/content/view/19/2/
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

When done a prompt appears informing of such.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Download SmitRem.exe © noahdfear to your Desktop.
From HERE

[external image: Posted Image]

Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop.

[external image: Posted Image]

Please download the trial version of ewido security suite. Install ewido security suite and start the program from the icon on your desktop, then check for and download updates. Don't Run Yet.


Reboot to safe mode

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Open the smitRem folder, then double click the RunThis.bat file to start the tool.

[external image: Posted Image]

Follow the prompts on screen. Your desktop and icons will disappear and then reappear again — this is normal.
Wait for the tool to complete and Disk Cleanup to finish — this may take a while; please be patient.


Open Ewido Security Suite
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean files, click OK

Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
In the Control Panel click Display > Desktop > Customize desktop > Website > Uncheck "Security Info" if present.

Empty recycle bin.

Reboot Normal.

Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection


You should now be free of the SpyAxe infection.


Then a new hijackthis log please.
:) THANKS VERY MUCH SIGGYX!!! , I am a now happy man :D . I did exactly as you instructed and guess what… my computer is completely freeeeeeeeeee… from that annoying BraveSentry popup "Your Computer is in Danger" message. Here is a copy of the HJT log file which you asked me to send. THANKS INDEED!!! :)

Now the trouble is, I still can't play any video. I get the Error ID=0xC00D11CD, in Windows MP. I guess I should start this as a new topic.

Logfile of HijackThis v1.99.1
Scan saved at 10:56:48 PM, on 03/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\PROGRA~1\MOZILL~1\FIREFOX.EXE
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_3.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [InternetCalls] "C:\InternetCalls\InternetCalls.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Google Desktop Search] "F:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://f:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130
O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll
O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
still some bad stuff on there

Can you please scan this file >>>> C:\windows\openproxy.exe at this site >>> http://virusscan.jotti.org/ and post the log it produces please.

Scan with hijackthis and put a check beside these lines and choose FIX


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank

O4 - HKLM\..\RunServices: [Win32 System Kernel] winservice.exe

O16 - DPF: {315E82DA-3DB2-10BE-5D64-1EDB02F8D059} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {602D46A5-E6B7-7524-7AC3-1A0F3BFF3922} - http://85.255.115.230/1/gdnFR2194.exe
O16 - DPF: {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_06) -
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} - http://advnt01.com/dialer/internazionale_ver15.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{811DFF70-A72E-476B-A4D7-80E503D97350}: NameServer = 83.221.230.130

O20 - AppInit_DLLs: F:\WINDOWS\system32\tmp_811.dll

O21 - SSODL: ewidoantimalware - {484CF139-A003-0B7D-EE06-30B223FEBCFE} - (no file)

Then look for and delete this file

F:\WINDOWS\system32\tmp_811.dll <<
Reboot and a new log and that file scan log please.
:o I thought I was completely free from those bad guys. anyways, they getting kicked out gradually. no hurries.

So first off with the good news, all went well with the HJT log Fix and I was able also to find and delete the F:\WINDOWS\system32\tmp_811.dll <<
Now the sad side. The scan result for file >>>> C:\windows\openproxy.exe at this site >>> gave nothing. this is what it said;

>>>The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file.>>>

This leads me to another problem, my firewall cannot be turned on. when I try to do that, I get a "Due to an unidentied problem, Windows cannot display Windows Firewall settings". error message.



Here is the HJT log file you request. Thanks very very much for all the help!!! :)

Logfile of HijackThis v1.99.1
Scan saved at 6:27:27 AM, on 03/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\PROGRA~1\PicoZip\PicoZipTray.exe
F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
F:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\WINDOWS\system32\wuauclt.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\PROGRA~1\PicoZip\PicoZip.exe
F:\DOCUME~1\roger\LOCALS~1\Temp\pz_3.tmp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 83.221.230.130
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=83.221.230.130:8080
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - F:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [IE.SYS (kernel32)] C:\windows\openproxy.exe
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PicoZip] F:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] F:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [InternetCalls] "C:\InternetCalls\InternetCalls.exe" -nosplash -minimized
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://F:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02E09B2E-2A03-4572-9291-69900C068564} (LCSim Control) - http://www.threepointtech.com/cabs/lcsim.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid;=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup142f1.cab
O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: FreezeScreenSaver - Unknown owner - F:\WINDOWS\system32\FreezeScreenSaver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
:rant: Another problem again. I just discovered I cant access the internet through IE. IE cannot find server. In Moxilla Firefox, I get access but can't access my Yahoo email. It says Server not found Firefox can't find the server at login.yahoo.com. * Check the address for typing errors such as ww.example.com instead of www.example.com * If you are unable to load any pages, check your computer's network connection. * If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web. Thanks!!!!!!!!!
Please download hoster from the link below.

http://www.funkytoad.com/download/hoster.zip

Open Hoster.exe.

Then click on "Restore Original Hosts"

Close program when complete.

NEXT

To repair Internet Explorer in Windows XP, complete the following procedure while you are logged on as an administrator:

Use the System File Checker tool to scan all of the protected files on your computer:

Click Start, and then click Run.
In the Open box, type sfc /scannow, and then click OK.

NEXT

Please download the trial version of Ewido Security Suite here:

http://www.ewido.net/en/

Install it, and update the definitions to the newest files.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI