This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here is my hijack this log file.

Logfile of HijackThis v1.99.1
Scan saved at 2:42:28 PM, on 03/08/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - _{5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - (no file)
R3 - URLSearchHook: (no name) - _{8277E983-5647-01B0-4517-5A50D4513193} - (no file)
R3 - URLSearchHook: (no name) - {C1255F66-E4A1-BF55-A6A9-E13B82077695} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: (no name) - {130405B1-F11C-B7BF-00C1-E4D5BDA3E2FA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)
O2 - BHO: (no name) - {262935B1-DC2F-828B-2DF1-D4F88D93CFCA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)
O2 - BHO: (no name) - {44880B16-FFE5-B646-AE2B-EA3563C3BDFE} - C:\WINDOWS\System32\skzh.dll (file missing)
O2 - BHO: (no name) - {4C69C042-32EB-2349-A2AB-72FCDF53E9F8} - C:\WINDOWS\System32\qact.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - C:\WINDOWS\System32\ozzslemr.dll (file missing)
O2 - BHO: (no name) - {5C2567E6-9949-88EB-0721-DAC69C76F9AC} - C:\WINDOWS\System32\aixpz.dll (file missing)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {690857E6-B47A-BDDF-2A11-EAEBAC46D49C} - C:\WINDOWS\System32\aixpz.dll (file missing)
O2 - BHO: (no name) - {71A53B16-D2D6-8372-831B-DA1853F390CE} - C:\WINDOWS\System32\skzh.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {80AF48D5-E074-ABD0-6ED7-F5F41FBC77AD} - C:\WINDOWS\System32\qwbfyi.dll (file missing)
O2 - BHO: (no name) - {8277E983-5647-01B0-4517-5A50D4513193} - C:\WINDOWS\System32\rearx.dll (file missing)
O2 - BHO: (no name) - {8EE82CB3-CF70-95D5-7804-CB891A086496} - C:\WINDOWS\System32\cfkshs.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {C58BCA75-3782-2A73-9FB8-234934BE61F5} - C:\WINDOWS\System32\svglcyf.dll (file missing)
O2 - BHO: (no name) - {D22CADD0-0978-1388-3782-105A95F627FB} - C:\WINDOWS\System32\retns.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ZICORN] C:\WINDOWS\System32\ZICORN
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [dmatd.exe] C:\WINDOWS\System32\dmatd.exe
O4 - HKLM\..\Run: [htzqt.exe] C:\WINDOWS\System32\htzqt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Richmond Academy web link] "C:\Program Files\Richmond Academy\screen saver\FWLink.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Raoa] "C:\DOCUME~1\RAYMON~1\MYDOCU~1\MCROSO~1.NET\wuauclt.exe" -vt ndrv
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O4 - Global Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O4 - Global Startup: MSWin.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\DOWNLO~1\INCRED~1\INCRED~1\bin\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O12 - Plugin for .wma: C:\Program Files\Sympatico\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://j-bot1.spaces.msn.com/PhotoUpload/M….cab?10,0,912,0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab34246.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101
O17 - HKLM\System\CS2\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
Welcome to the forum :wavey:

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - URLSearchHook: (no name) - _{5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - (no file)

R3 - URLSearchHook: (no name) - _{8277E983-5647-01B0-4517-5A50D4513193} - (no file)

R3 - URLSearchHook: (no name) - {C1255F66-E4A1-BF55-A6A9-E13B82077695} - (no file)

O1 - Hosts: localhost 127.0.0.1

O2 - BHO: (no name) - {130405B1-F11C-B7BF-00C1-E4D5BDA3E2FA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)

O2 - BHO: (no name) - {262935B1-DC2F-828B-2DF1-D4F88D93CFCA} - C:\WINDOWS\System32\ynbwgike.dll (file missing)

O2 - BHO: (no name) - {44880B16-FFE5-B646-AE2B-EA3563C3BDFE} - C:\WINDOWS\System32\skzh.dll (file missing)

O2 - BHO: (no name) - {4C69C042-32EB-2349-A2AB-72FCDF53E9F8} - C:\WINDOWS\System32\qact.dll (file missing)

O2 - BHO: (no name) - {5A2DE536-0BF1-0F04-A1E9-05D58C25E39F} - C:\WINDOWS\System32\ozzslemr.dll (file missing)

O2 - BHO: (no name) - {5C2567E6-9949-88EB-0721-DAC69C76F9AC} - C:\WINDOWS\System32\aixpz.dll (file missing)

O2 - BHO: (no name) - {690857E6-B47A-BDDF-2A11-EAEBAC46D49C} - C:\WINDOWS\System32\aixpz.dll (file missing)

O2 - BHO: (no name) - {71A53B16-D2D6-8372-831B-DA1853F390CE} - C:\WINDOWS\System32\skzh.dll (file missing)

O2 - BHO: (no name) - {80AF48D5-E074-ABD0-6ED7-F5F41FBC77AD} - C:\WINDOWS\System32\qwbfyi.dll (file missing)

O2 - BHO: (no name) - {8277E983-5647-01B0-4517-5A50D4513193} - C:\WINDOWS\System32\rearx.dll (file missing)

O2 - BHO: (no name) - {8EE82CB3-CF70-95D5-7804-CB891A086496} - C:\WINDOWS\System32\cfkshs.dll (file missing)

O2 - BHO: (no name) - {C58BCA75-3782-2A73-9FB8-234934BE61F5} - C:\WINDOWS\System32\svglcyf.dll (file missing)

O2 - BHO: (no name) - {D22CADD0-0978-1388-3782-105A95F627FB} - C:\WINDOWS\System32\retns.dll (file missing)

O4 - HKLM\..\Run: [dmatd.exe] C:\WINDOWS\System32\dmatd.exe

O4 - HKLM\..\Run: [htzqt.exe] C:\WINDOWS\System32\htzqt.exe

O4 - HKCU\..\Run: [Raoa] "C:\DOCUME~1\RAYMON~1\MYDOCU~1\MCROSO~1.NET\wuauclt.exe" -vt ndrv

O4 - Global Startup: MSWin.exe

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101

O17 - HKLM\System\CS2\Services\Tcpip\..\{63E9BA26-3749-4A06-8022-78E155A92AE6}: NameServer = 85.255.115.22 85.255.112.101


Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Close the program.

Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds.

Save the logfile from the scan.

Boot in normal mode.

Post:

1. The log from Ewido

2. A new HijackThis! log

Into this thread.
:)
Thank you for responding so quickly.

Logfile of HijackThis v1.99.1
Scan saved at 10:35:30 PM, on 03/08/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Call Manager\ICM.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Documents and Settings\Raymond White\Desktop\HijackThis(spyware remover)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ZICORN] C:\WINDOWS\System32\ZICORN
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Richmond Academy web link] "C:\Program Files\Richmond Academy\screen saver\FWLink.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O4 - Global Startup: Internet Call Manager.LNK = C:\Program Files\Internet Call Manager\ICM.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\DOWNLO~1\INCRED~1\INCRED~1\bin\WebMenuImg.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O12 - Plugin for .wma: C:\Program Files\Sympatico\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://j-bot1.spaces.msn.com/PhotoUpload/M….cab?10,0,912,0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136658589914
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab34246.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe



———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 10:22:12 PM 03/08/2006

+ Scan result:



C:\WINDOWS\mtuninst.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\{EB61D295-C32A-4800-B3B6-95F19A61DFDC}.exe -> Adware.Raze : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\csigc.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\Documents and Settings\Raymond White\Local Settings\Temp\a.exe -> Downloader.Tiny.ax : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.6:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.7:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
:mozilla.8:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Raymond White\Application Data\Mozilla\Profiles\default\r2cdilcw.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\htzqt.exe -> Trojan.DNSChanger.ef : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\{812016BF-D8F7-4C55-BAC9-1813C74A9551}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\{E007D8A5-10DB-4B64-920E-F8C174DA02FC}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dmatd.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).


::Report end
Just one noticable item left.

How's it running now?
:unsure:

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [ZICORN] C:\WINDOWS\System32\ZICORN

Then click "Fix checked" and close Hijack This!.

Reboot.
Done! Seems to be running normal, although it wasn't too bad at times before; hopefully it's fixed *knock on wood*. Thank you very much.
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI