This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System Integrity Scan Wizard + Ultimate Defender ... Others, too

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a problem with my browser going to some System Update site, came here and found out the problem and got it fixed.
I thought all these pop-ups might be something to do with that, but they're still here.

This is my Dad's computer and he clicks on anything and everything that says "click!" … So since I'm going to be using it for a little while, I want to try and clean it up and do what I can do to prevent things like this from happening in the future.

Here is my HijackThis log …

Logfile of HijackThis v1.99.1
Scan saved at 2:02:06 PM, on 6/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\43dca191.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLServiceHost.exe
c:\program files\common files\aol\1131672637\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLServiceHost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\ewido anti-malware\securitysuite.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Frank Springstead\My Documents\My Pictures\site\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1131672637\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [43dca191.exe] C:\WINDOWS\system32\43dca191.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [43dca191.exe] C:\Documents and Settings\Frank Springstead\Local Settings\Application Data\43dca191.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {015D37C5-514D-116E-2607-08794883D6A2} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {028DE2C3-80FB-0612-827B-65F0684997FF} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {03339E88-5048-6A27-061E-59DD480D58F1} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {04FB317B-9C10-2337-D12B-006E39DDDC76} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {064BBBC3-0A9A-0344-79A6-4FBC37C838A9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0702C1A0-1FA4-5F80-625B-4D04560D898C} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0834AA16-95B8-03C7-D775-79682C18A685} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {08FE0B1B-A8C8-30E0-17C8-1F17226C3DD1} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0A992EF3-A332-7F7F-605D-28697FFCE10D} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0AE19F10-6879-1986-B617-637D66CA3034} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0CB5AB5C-CB1D-0DA8-4665-213A3FAEF5F9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0D60DC7B-5826-6A9F-DEE9-532376E7FA97} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {0EB72432-83A9-20A1-4703-01703CD7B2CF} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1023F96F-20B8-6A31-3804-5A9D013FF77B} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {12CDC8B4-14BC-4BC1-1963-30636EC6C624} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {166D0B85-7AFB-21EA-510C-03164AF7ED9F} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {17663A6C-D671-34A5-F060-0E5277AFAB71} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {185ED802-E290-45D4-C394-7F0C47322F58} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {19760675-FCAF-51F4-1CE0-210817EF96F2} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1B8A7583-68F4-105C-3EF8-061F05357175} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1C81B16F-6CDD-3AB1-7B6C-5A2974A39BEC} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1D0758E0-B04B-7D2F-2C16-064A3A6C2C5F} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {1D7F59A2-752C-3CD9-2D85-393C6BB3B9CE} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1EFA2C3B-AB27-040E-D26B-64380515D1E3} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {1F365E9A-D21E-3040-B4E1-6F2D009E00D9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {22B8FC63-BE18-6D56-1AAB-7D9B570F7053} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {232FD6D1-68F1-4844-916E-7997581DA882} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2569DA4C-8A5A-2499-5D30-362346CB7625} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {28AF6BFB-6E33-7343-240B-24AA59B8014C} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2A2F6945-6DD5-7703-B910-38A36B02A92E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2B57DB4E-B7E8-24EA-88CE-15F6508C0EF9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2B766AD7-7CBA-1D7A-038F-7118568AA229} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2E0D8895-0244-47F0-3E41-52F91BEE0D33} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://aolsvc.aol.com/onlinegames/trytriji…nx.1.0.0.58.cab
O16 - DPF: {300932C4-A69D-182F-104E-0B072278FA97} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3059ABEC-A4AB-00B8-D94D-05930C7932C8} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {31DF68DC-E042-3918-0677-1ADC59AF3539} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {329209AA-9EBE-464A-2B74-435E739CAF99} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {34A43C4F-5A1F-3145-B3DB-0AA77EF0A0D6} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {36ECD040-7BFF-1BC3-DC23-542C2E6A533A} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {3762A596-9F6E-3547-6700-594274DBA453} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {39F10DCE-00F4-75CC-54A6-55F967D2462E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {3B573430-7481-74AA-7FAD-1B5B51D720CE} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {3C61304A-FAE1-096B-1720-28913D94653D} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {3FFB1EFC-402F-793B-6163-429B29474407} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {41C2D936-4FDE-67FB-4926-75430ACAC344} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4213EC12-C178-1F0B-790F-2AA75EA0D6B9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4358757D-7693-470A-7CBB-1E1D7C05DFD7} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4463C6F2-AB48-4391-A256-69FF2C3097B6} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {45939973-E09E-48E4-02B5-6FD14EF06F9E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4687F0DC-7CF7-6DD5-C3F4-5D832FECA701} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4750F67C-4568-2FD6-CABF-3DC064FE25A7} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {479EBC74-BAA6-4559-7DDB-77B512614FCB} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {48F525D5-DC24-300C-F4AD-50117D19EA6F} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4A09DDC0-19EF-303C-398C-5734733C82E2} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4C05D031-4445-6F8C-E0FF-2E5F68A83716} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4C1AFF27-8E56-2C88-7A9A-672B5492E69C} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4D99C551-1F43-5FEA-8F83-299D6E83A3B4} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4E34CF81-9714-4387-772F-207B57F66123} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4ECCA825-2049-5422-F10D-4E3F18A430C2} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {4F72ACD0-F4CA-3D0C-6E98-134B53E5E36E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {4FB83B04-CD2C-2E5D-3483-34FD236798C7} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {509CB429-2433-52C4-677C-381343EE5B57} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {52A4DDB8-F4C7-290F-6DFA-1A77108A9DCD} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {532515F2-D655-05A8-E103-00CE1C703AE6} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {542C111B-3A46-0172-130D-4CB81275C6BC} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {54BB1D5F-361C-1487-57CD-04F848F2D565} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {57C148F3-24CC-7E3F-2315-3EFD358C640E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {59B82052-3204-0AC2-5799-7B5823CAE8B1} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5BE2A300-DF41-1D2A-22D2-7A5C53FB22C1} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5D5669A2-F461-128D-9991-54276785FFEB} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5D70026B-DD76-3535-1BEA-512A5762961B} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5E505850-4B99-080C-4E5C-164E354365A1} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5F0E6EA7-14FB-1958-03FB-2600054647CC} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {5F40142C-2CCE-42D0-23F1-451520215980} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6014FF2C-36E7-56A0-B275-51FE53A73458} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {60425173-3F19-48C7-8D5A-3E175A38B29D} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {610A27B5-2D83-374C-BC74-1BEE2CDE858D} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {623EDD4A-43D0-6B12-DFC5-32B028FDAAA2} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {63F86A80-378F-7655-9CA2-33E80872E6AD} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {643D69F8-9D90-3522-F6F5-366531BD29D3} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {652ED793-0511-315F-4B28-7F6138CAF058} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {67655300-26CE-4DDF-66AF-2B6D45306665} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {67E63341-FF70-39EF-B23C-3B10617D0580} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {67E88C76-07B2-6395-9541-1BAC435E9861} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {68030900-E4B8-5E69-684D-547034187986} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6A9C616C-7A4A-2643-292A-1D3450450ADC} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6CFF3F88-2403-08C3-5914-53E91016B28D} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6D24DAB0-0CE7-5219-5580-637A6B33EE80} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6DD4C7A8-F828-493C-99F4-24416CAF7CF4} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143237812389
O16 - DPF: {6FAA4848-3907-3F8E-36FC-01160FAFF800} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {6FDD2158-8DCC-3845-26BA-4F8B09002A4A} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {7038E9DD-B88C-7DE3-FC99-1A2C65C5506B} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {708A3662-F2F4-5DD8-6B95-7F767E1071C0} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {7099B82E-6E2A-5C83-5E8C-7E656BE46FAE} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {71E98712-6E4F-6860-782C-56440A265B12} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {728D970E-DD42-062E-0275-07E3177743F9} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {78103A2E-6D9C-6B9D-B1B9-208F5AD02C77} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {787BEA65-2F7F-7FF4-5290-6A6D41CBE94E} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {791E477C-3119-510D-9A88-28796CB1BC72} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {79C0112F-9223-07ED-2485-4BD10BCFAADF} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {7ADC75FC-A6AA-1470-1A73-36CE612D2775} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {7CC35187-19E6-282E-FF5D-6F6C79254C57} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {7FC7BB51-BCD2-1C5E-1B68-22573BEBAC38} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…r/goldfever.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popzuma/…aploader_v7.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: jkhhf - C:\WINDOWS\system32\jkhhf.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe







Thanks!
Welcome to the forum :wavey:

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)

O4 - HKLM\..\Run: [43dca191.exe] C:\WINDOWS\system32\43dca191.exe

O4 - HKCU\..\Run: [43dca191.exe] C:\Documents and Settings\Frank Springstead\Local Settings\Application Data\43dca191.exe

O16 - DPF: {015D37C5-514D-116E-2607-08794883D6A2} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {028DE2C3-80FB-0612-827B-65F0684997FF} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {03339E88-5048-6A27-061E-59DD480D58F1} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {04FB317B-9C10-2337-D12B-006E39DDDC76} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {064BBBC3-0A9A-0344-79A6-4FBC37C838A9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0702C1A0-1FA4-5F80-625B-4D04560D898C} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0834AA16-95B8-03C7-D775-79682C18A685} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {08FE0B1B-A8C8-30E0-17C8-1F17226C3DD1} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0A992EF3-A332-7F7F-605D-28697FFCE10D} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0AE19F10-6879-1986-B617-637D66CA3034} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0CB5AB5C-CB1D-0DA8-4665-213A3FAEF5F9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0D60DC7B-5826-6A9F-DEE9-532376E7FA97} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {0EB72432-83A9-20A1-4703-01703CD7B2CF} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1023F96F-20B8-6A31-3804-5A9D013FF77B} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {12CDC8B4-14BC-4BC1-1963-30636EC6C624} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {166D0B85-7AFB-21EA-510C-03164AF7ED9F} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {17663A6C-D671-34A5-F060-0E5277AFAB71} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {185ED802-E290-45D4-C394-7F0C47322F58} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {19760675-FCAF-51F4-1CE0-210817EF96F2} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1B8A7583-68F4-105C-3EF8-061F05357175} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1C81B16F-6CDD-3AB1-7B6C-5A2974A39BEC} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1D0758E0-B04B-7D2F-2C16-064A3A6C2C5F} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab

O16 - DPF: {1D7F59A2-752C-3CD9-2D85-393C6BB3B9CE} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1EFA2C3B-AB27-040E-D26B-64380515D1E3} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {1F365E9A-D21E-3040-B4E1-6F2D009E00D9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {22B8FC63-BE18-6D56-1AAB-7D9B570F7053} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {232FD6D1-68F1-4844-916E-7997581DA882} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {2569DA4C-8A5A-2499-5D30-362346CB7625} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {28AF6BFB-6E33-7343-240B-24AA59B8014C} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {2A2F6945-6DD5-7703-B910-38A36B02A92E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {2B57DB4E-B7E8-24EA-88CE-15F6508C0EF9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {2B766AD7-7CBA-1D7A-038F-7118568AA229} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {2E0D8895-0244-47F0-3E41-52F91BEE0D33} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {300932C4-A69D-182F-104E-0B072278FA97} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {3059ABEC-A4AB-00B8-D94D-05930C7932C8} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {31DF68DC-E042-3918-0677-1ADC59AF3539} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {329209AA-9EBE-464A-2B74-435E739CAF99} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {34A43C4F-5A1F-3145-B3DB-0AA77EF0A0D6} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {36ECD040-7BFF-1BC3-DC23-542C2E6A533A} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {3762A596-9F6E-3547-6700-594274DBA453} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {39F10DCE-00F4-75CC-54A6-55F967D2462E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {3B573430-7481-74AA-7FAD-1B5B51D720CE} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {3C61304A-FAE1-096B-1720-28913D94653D} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {3FFB1EFC-402F-793B-6163-429B29474407} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {41C2D936-4FDE-67FB-4926-75430ACAC344} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4213EC12-C178-1F0B-790F-2AA75EA0D6B9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4358757D-7693-470A-7CBB-1E1D7C05DFD7} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4463C6F2-AB48-4391-A256-69FF2C3097B6} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {45939973-E09E-48E4-02B5-6FD14EF06F9E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4687F0DC-7CF7-6DD5-C3F4-5D832FECA701} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4750F67C-4568-2FD6-CABF-3DC064FE25A7} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {479EBC74-BAA6-4559-7DDB-77B512614FCB} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {48F525D5-DC24-300C-F4AD-50117D19EA6F} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4A09DDC0-19EF-303C-398C-5734733C82E2} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4C05D031-4445-6F8C-E0FF-2E5F68A83716} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4C1AFF27-8E56-2C88-7A9A-672B5492E69C} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4D99C551-1F43-5FEA-8F83-299D6E83A3B4} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4E34CF81-9714-4387-772F-207B57F66123} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4ECCA825-2049-5422-F10D-4E3F18A430C2} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4F72ACD0-F4CA-3D0C-6E98-134B53E5E36E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {4FB83B04-CD2C-2E5D-3483-34FD236798C7} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {509CB429-2433-52C4-677C-381343EE5B57} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {52A4DDB8-F4C7-290F-6DFA-1A77108A9DCD} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {532515F2-D655-05A8-E103-00CE1C703AE6} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {542C111B-3A46-0172-130D-4CB81275C6BC} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {54BB1D5F-361C-1487-57CD-04F848F2D565} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {57C148F3-24CC-7E3F-2315-3EFD358C640E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {59B82052-3204-0AC2-5799-7B5823CAE8B1} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5BE2A300-DF41-1D2A-22D2-7A5C53FB22C1} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5D5669A2-F461-128D-9991-54276785FFEB} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5D70026B-DD76-3535-1BEA-512A5762961B} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5E505850-4B99-080C-4E5C-164E354365A1} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5F0E6EA7-14FB-1958-03FB-2600054647CC} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {5F40142C-2CCE-42D0-23F1-451520215980} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6014FF2C-36E7-56A0-B275-51FE53A73458} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {60425173-3F19-48C7-8D5A-3E175A38B29D} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {610A27B5-2D83-374C-BC74-1BEE2CDE858D} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {623EDD4A-43D0-6B12-DFC5-32B028FDAAA2} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {63F86A80-378F-7655-9CA2-33E80872E6AD} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {643D69F8-9D90-3522-F6F5-366531BD29D3} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {652ED793-0511-315F-4B28-7F6138CAF058} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {67655300-26CE-4DDF-66AF-2B6D45306665} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {67E63341-FF70-39EF-B23C-3B10617D0580} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {67E88C76-07B2-6395-9541-1BAC435E9861} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {68030900-E4B8-5E69-684D-547034187986} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6A9C616C-7A4A-2643-292A-1D3450450ADC} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6CFF3F88-2403-08C3-5914-53E91016B28D} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6D24DAB0-0CE7-5219-5580-637A6B33EE80} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6DD4C7A8-F828-493C-99F4-24416CAF7CF4} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6FAA4848-3907-3F8E-36FC-01160FAFF800} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {6FDD2158-8DCC-3845-26BA-4F8B09002A4A} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {7038E9DD-B88C-7DE3-FC99-1A2C65C5506B} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {708A3662-F2F4-5DD8-6B95-7F767E1071C0} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {7099B82E-6E2A-5C83-5E8C-7E656BE46FAE} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {71E98712-6E4F-6860-782C-56440A265B12} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {728D970E-DD42-062E-0275-07E3177743F9} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {78103A2E-6D9C-6B9D-B1B9-208F5AD02C77} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {787BEA65-2F7F-7FF4-5290-6A6D41CBE94E} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {791E477C-3119-510D-9A88-28796CB1BC72} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {79C0112F-9223-07ED-2485-4BD10BCFAADF} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {7ADC75FC-A6AA-1470-1A73-36CE612D2775} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {7CC35187-19E6-282E-FF5D-6F6C79254C57} - http://85.255.113.214/1/gdnUS2218.exe

O16 - DPF: {7FC7BB51-BCD2-1C5E-1B68-22573BEBAC38} - http://85.255.113.214/1/gdnUS2218.exe

O20 - Winlogon Notify: jkhhf - C:\WINDOWS\system32\jkhhf.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\frank springstead\local settings\application data\43dca191.exe <— file

c:\windows\system32\43dca191.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Found both the files and deleted. Here's the new log…




Logfile of HijackThis v1.99.1
Scan saved at 4:17:03 PM, on 6/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLServiceHost.exe
c:\program files\common files\aol\1131672637\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1131672637\ee\AOLServiceHost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Frank Springstead\My Documents\My Pictures\site\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1131672637\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2E0D8895-0244-47F0-3E41-52F91BEE0D33} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://aolsvc.aol.com/onlinegames/trytriji…nx.1.0.0.58.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143237812389
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…r/goldfever.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popzuma/…aploader_v7.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktank…ownloadCtrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe









Thanks so very much! Hopefully this takes care of everything. If I come across something else, I'll let you know.
You missed one:

O16 - DPF: {2E0D8895-0244-47F0-3E41-52F91BEE0D33} - http://85.255.113.214/1/gdnUS2218.exe

If you have further problems, please try this first to see if your problems go away:

Please download and run Spybot-Search&Destroy and Ad-Aware; they are the standard programs for finding and cleaning malware off your system. Here are links to both programs, and instructions for their use.


Get Spybot - Search & Destroy from Spybot Search and Destroy
(This is the NEW Version 1.4)
Get AdAware SE Personal from Lavasoft
(This is the NEW Build 1.6)

Download and install these programs if you don't already have them. If you do have them, make sure they are UPDATED AND CONFIGURED AS DESCRIBED here:

Configure Adaware

Configure Spybot

Reboot after running each program.

M68 :)

Post Infection Items To Ponder
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI