This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ddayx.dll infection

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

http://forums.tomcoyote.org/index.php?show…50&hl=ddayx - saw this link after looking around and I think this is similar to what I have.

i ran spybot. i ran Ad-aware. i ran ewido in SafeMode.

Here's my ewido and hjt logs.

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 10:03:16 PM 7/24/2006

+ Scan result:



C:\Documents and Settings\Kirk Ortiz\Local Settings\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\Cache\71F545FEd01 -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temporary Internet Files\Content.IE5\CLQNGXAB\drsmartload_js[1].htm -> Downloader.IstBar.j : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ld4C7A.tmp -> Downloader.Zlob.er : Cleaned with backup (quarantined).
C:\WINDOWS\browser.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\xuexngrv.dll -> Logger.VBStat.c : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.110:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.299:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.311:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.359:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.373:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\Cookies\kirk ortiz@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\Cookies\kirk ortiz@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.280:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.281:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.282:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.283:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.616:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.617:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.67:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.571:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.572:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.573:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.72:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.73:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.123:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.596:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.597:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.105:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.106:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.132:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk ortiz@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.177:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.90:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.694:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.206:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.433:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.434:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.641:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.642:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.353:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.354:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.368:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.68:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.69:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.70:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.71:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.377:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.378:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.380:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.381:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.382:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.454:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.455:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.456:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.457:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.458:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.459:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.460:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.461:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.462:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.463:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.464:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.465:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.466:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.467:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.647:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.648:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.649:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.650:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.651:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.652:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.653:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.654:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.655:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.656:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\Cookies\kirk [removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.416:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.165:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.166:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.167:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.104:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.437:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.438:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.439:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.440:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.66:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.446:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.197:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.198:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.199:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.499:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.666:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.449:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.450:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.451:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.452:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.453:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.478:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.479:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.480:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.588:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.486:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.487:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.488:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.489:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.490:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.491:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.492:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.493:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.494:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.495:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.496:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.497:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.505:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.506:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.507:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.508:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.509:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.577:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.578:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.579:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.57:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.580:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.581:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.582:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.58:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.59:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.60:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk [removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk [removed][4].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Cookies\kirk [removed][5].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\Cookies\kirk [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.574:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.575:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.576:C:\Documents and Settings\Kirk Ortiz\Application Data\Mozilla\Firefox\Profiles\st6wp0le.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\drivers\DP.sys -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dwenkmau.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fygvpcih.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gmpxgbpl.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\hgbtacue.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kxleicnq.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nmbdftqy.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\titnbcfj.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ubwnaobw.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ujwceejk.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\xkmrkthw.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ynygiukr.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\fpkchond.exe -> Trojan.Dialer.ay : Cleaned with backup (quarantined).
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\mbdeipmd.exe -> Trojan.Dialer.ay : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld9C79.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Kirk Ortiz\Local Settings\Temp\mdle.exe -> Trojan.Small.gz : Cleaned with backup (quarantined).


::Report end



Logfile of HijackThis v1.99.1
Scan saved at 10:08:06 PM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
D:\tmp\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: DPCUpdater Object - {E291663A-2D6F-4B56-B9DF-AE239AEF6A5B} - C:\WINDOWS\system32\ddayx.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: ddayx - C:\WINDOWS\system32\ddayx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Welcome to the forum :wavey:

Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop. <— VERY IMPORTANT!!!

Go to Start –> Run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /v ddayx

Then hit or click OK

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.
:)
(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\SYSTEM32\DDAYX.DLL
C:\WINDOWS\SYSTEM32\XYADD.INI
C:\WINDOWS\SYSTEM32\XYADD.TMP


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



16:12:04.73
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-26 04:27:40 6338289 ( A…. ) "C:\WINDOWS\THE fOUNTAIN_v4.SCR"
2006-07-26 04:27:28 5339635 ( A…. ) "C:\WINDOWS\THE fOUNTAIN_v2.SCR"
2006-07-26 04:27:16 5818321 ( A…. ) "C:\WINDOWS\THE fOUNTAIN_v1.SCR"
2006-07-26 04:26:52 5835075 ( A…. ) "C:\WINDOWS\THE fOUNTAIN_v3.SCR"
2006-07-26 04:26:44 ( .D… ) "C:\Documents and Settings\Kirk Ortiz\Application Data\iScreensaver"
2006-07-26 04:17:36 65556 ( A…. ) "C:\WINDOWS\system32\ugjhdxtw.exe"
2006-07-26 00:46:48 65556 ( A…. ) "C:\WINDOWS\system32\juxuppft.exe"
2006-07-24 23:08:28 65556 ( A…. ) "C:\WINDOWS\system32\xscnontw.exe"
2006-07-24 21:19:58 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-24 21:00:32 65556 ( A…. ) "C:\WINDOWS\system32\nhgygnit.exe"
2006-07-24 20:16:00 65556 ( A…. ) "C:\WINDOWS\system32\cjgboqcf.exe"
2006-07-24 20:02:24 65556 ( A…. ) "C:\WINDOWS\system32\cdvrqoqa.exe"
2006-07-20 23:55:52 ( .D… ) "C:\Program Files\DVD Shrink"
2006-07-20 23:08:36 ( .D… ) "C:\Documents and Settings\Kirk Ortiz\Application Data\Ahead"
2006-07-20 23:00:26 ( .D… ) "C:\Program Files\Common Files\Ahead"
2006-07-20 23:00:24 ( .D… ) "C:\Program Files\Ahead"
2006-07-20 21:17:34 ( .D… ) "C:\Program Files\QuickTime"
2006-07-20 21:14:48 ( .D… ) "C:\Program Files\iTunes"
2006-06-19 16:20:42 702768 ( A…. ) "C:\WINDOWS\system32\WgaLogon.dll"
2006-05-19 07:59:42 148480 ( A…. ) "C:\WINDOWS\system32\dnsapi.dll"
2006-05-19 07:59:42 111616 ( A…. ) "C:\WINDOWS\system32\dhcpcsvc.dll"
2006-05-19 07:59:42 94720 ( A…. ) "C:\WINDOWS\system32\iphlpapi.dll"
2006-05-12 02:08:58 176167 ( A…. ) "C:\WINDOWS\system32\rmoc3260.dll"
2006-05-12 02:08:36 6656 ( A…. ) "C:\WINDOWS\system32\pndx5016.dll"
2006-05-12 02:08:36 5632 ( A…. ) "C:\WINDOWS\system32\pndx5032.dll"
2006-05-12 02:08:34 278528 ( A…. ) "C:\WINDOWS\system32\pncrt.dll"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-07-26 04:27 6,338,289 C:\WINDOWS\THE
2006-07-26 04:27 5,818,321 C:\WINDOWS\THE
2006-07-26 04:27 5,339,635 C:\WINDOWS\THE
2006-07-26 04:26 5,835,075 C:\WINDOWS\THE
2006-07-26 04:17 65,556 C:\WINDOWS\system32\ugjhdxtw.exe
2006-07-26 00:46 65,556 C:\WINDOWS\system32\juxuppft.exe
2006-07-24 23:08 65,556 C:\WINDOWS\system32\xscnontw.exe
2006-07-24 22:05 1,073,270,784 C:\hiberfil.sys
2006-07-24 21:00 65,556 C:\WINDOWS\system32\nhgygnit.exe
2006-07-24 20:15 65,556 C:\WINDOWS\system32\cjgboqcf.exe
2006-07-24 20:02 65,556 C:\WINDOWS\system32\cdvrqoqa.exe
2006-07-21 01:38 1,916,928 C:\WINDOWS\UNNVEContent.exe
2006-07-20 23:04 3,051,520 C:\WINDOWS\UNNeroVision.exe
2006-07-20 23:04 24,064 C:\WINDOWS\system32\msxml3a.dll
2006-07-20 23:03 38,912 C:\WINDOWS\system32\picn20.dll
2006-07-20 23:00 476,320 C:\WINDOWS\system32\ImagXpr7.dll
2006-07-20 23:00 471,040 C:\WINDOWS\system32\ImagXRA7.dll
2006-07-20 23:00 364,544 C:\WINDOWS\system32\TwnLib4.dll
2006-07-20 23:00 262,144 C:\WINDOWS\system32\ImagXR7.dll
2006-07-20 23:00 155,648 C:\WINDOWS\system32\NeroCheck.exe
2006-07-20 23:00 106,496 C:\WINDOWS\system32\TwnLib20.dll
2006-07-20 23:00 1,568,768 C:\WINDOWS\system32\ImagX7.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"WinampAgent"="\"C:\\Program Files\\Winamp\\winampa.exe\""
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"nForce Tray Options"="sstray.exe /r"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"flags"=dword:00000008

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,00,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system
DisableRegistryTools REG_DWORD 0 (0x0)



Contents of the 'Scheduled Tasks' folder

Completion time: Sat 07/29/2006 16:12:12.81
ComboFix ver 06.07.15/28 - This logfile is located at C:\ComboFix.txt

=================++++++++END OF COMBOFIX.LOG+++++++++==================

Logfile of HijackThis v1.99.1
Scan saved at 4:15:23 PM, on 7/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wuauclt.exe
D:\tmp\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: DPCUpdater Object - {E291663A-2D6F-4B56-B9DF-AE239AEF6A5B} - C:\WINDOWS\system32\ddayx.dll (file missing)
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O20 - Winlogon Notify: ddayx - C:\WINDOWS\system32\ddayx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: DPCUpdater Object - {E291663A-2D6F-4B56-B9DF-AE239AEF6A5B} - C:\WINDOWS\system32\ddayx.dll (file missing)

O20 - Winlogon Notify: ddayx - C:\WINDOWS\system32\ddayx.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot.

From your Combofix log, these don't look like anything "friendly" to me:

2006-07-26 04:17 65,556 C:\WINDOWS\system32\ugjhdxtw.exe
2006-07-26 00:46 65,556 C:\WINDOWS\system32\juxuppft.exe
2006-07-24 23:08 65,556 C:\WINDOWS\system32\xscnontw.exe
2006-07-24 21:00 65,556 C:\WINDOWS\system32\nhgygnit.exe
2006-07-24 20:15 65,556 C:\WINDOWS\system32\cjgboqcf.exe
2006-07-24 20:02 65,556 C:\WINDOWS\system32\cdvrqoqa.exe

Unless you recognize them as useful, I would remove them.

Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Securing Your PC After An Attack
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI