This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

this is my log after I ran vundofix

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 10:06:37 PM, on 8/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SmileyDistrict\plugin.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\LYDIAG~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - Default URLSearchHook is missing
O1 - Hosts: 202.67.220.232 win.mail.ru
O2 - BHO: (no name) - {05F4AAEA-7CFA-4768-8978-76B601D83075} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {17B9662A-07EE-4035-BC5B-C2D4171C9CCC} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {1E910EB7-22BD-4C18-826C-54C55E93C0E7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\system32\mllji.dll
O2 - BHO: (no name) - {24646168-30A5-463A-B54B-D0D22EFF8CB4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {3619FCC7-26A5-4CC2-88AC-BDA29ED15F77} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4119C436-6FFF-45EF-BEBB-2A4487CDDEA4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4F2E1265-8C29-46A5-8CE4-E007B5597906} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {52410B9E-3B38-4624-9BC6-9351B2FD1785} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5380E79C-F79F-4745-A153-9BC2FD4366FE} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {587596F6-79C9-49BB-AB29-1E5849785D29} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {5992A728-DA27-4B25-9BA1-47C1C67333B5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {61F9D8E7-CD4D-471C-B83F-B8D3D6E12B36} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {68CABCDA-1318-4C84-B368-4AE10E9E86EF} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {690770E4-0FF0-4BCE-B462-57DBC2FA0ED7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CB90B47-DCB0-4C6A-87E2-7D5ABE3296FA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CD4E24C-43F8-4724-92BE-A19C583296D5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {7893A24B-3331-4316-9FDD-C928E3959740} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system\vga.dll
O2 - BHO: (no name) - {8C3B7860-062B-4CFA-8534-8181ABB9B427} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9ACC1661-966F-4AC0-95BE-4D5FDABD4B34} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9B0F1A6D-5004-402F-98C4-2C2407C3334E} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {A6DAB8D0-954D-4192-AF3C-8195352273E9} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {A91D33B1-4B85-4B36-A395-DFDBB116C91D} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {AF3A2994-00A3-4EB9-9A2F-3BC60011CF31} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B14A34D7-DEB2-4D7F-A610-EB9BA8D572FB} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B2C5B9AD-9B42-4048-8818-D184C15EA374} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B8E4AD23-1B90-404E-9970-1BDFD7BAB378} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {C5EF780D-4AC4-4072-BDBB-98A7950E6742} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {DCAD8EFC-F483-498B-9A6A-A148D6345DCA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {E893B8F6-5E76-4579-9548-B6CF303AD521} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FA60696B-051D-42F1-B600-3EA8B4CEF531} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FEE9A69E-C489-46CB-B278-5D503A89767B} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smiley District] C:\Program Files\SmileyDistrict\plugin.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll
O20 - Winlogon Notify: khhgg - khhgg.dll (file missing)
O20 - Winlogon Notify: mllji - C:\WINDOWS\SYSTEM32\mllji.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\DGMRTP.DLL (file missing)
O20 - Winlogon Notify: vga - C:\WINDOWS\system\vga.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

What is safe to remove from my computer?
Welcome to the forum :wavey:

Download VundoFix.exe to your desktop from here:

VundoFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. If it doesn't find anything, in the main program window, choose "Add more files?". Type this in the box EXACTLY AS SHOWN:

C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\system\vga.dll

(Add 2 files, if they aren't detected by the program)

Click Close Window, then Remove Vundo.

4. You will receive a prompt asking if you want to remove the files, click YES.
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will shutdown your computer, click OK.
7. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
Logfile of HijackThis v1.99.1
Scan saved at 5:18:47 AM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SmileyDistrict\plugin.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\LYDIAG~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - Default URLSearchHook is missing
O1 - Hosts: 202.67.220.232 win.mail.ru
O2 - BHO: (no name) - {05F4AAEA-7CFA-4768-8978-76B601D83075} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {17B9662A-07EE-4035-BC5B-C2D4171C9CCC} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {1E910EB7-22BD-4C18-826C-54C55E93C0E7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\system32\mllji.dll
O2 - BHO: (no name) - {24646168-30A5-463A-B54B-D0D22EFF8CB4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {3619FCC7-26A5-4CC2-88AC-BDA29ED15F77} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4119C436-6FFF-45EF-BEBB-2A4487CDDEA4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4F2E1265-8C29-46A5-8CE4-E007B5597906} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {52410B9E-3B38-4624-9BC6-9351B2FD1785} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5380E79C-F79F-4745-A153-9BC2FD4366FE} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {587596F6-79C9-49BB-AB29-1E5849785D29} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {5992A728-DA27-4B25-9BA1-47C1C67333B5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {61F9D8E7-CD4D-471C-B83F-B8D3D6E12B36} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {68CABCDA-1318-4C84-B368-4AE10E9E86EF} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {690770E4-0FF0-4BCE-B462-57DBC2FA0ED7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CB90B47-DCB0-4C6A-87E2-7D5ABE3296FA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CD4E24C-43F8-4724-92BE-A19C583296D5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {7893A24B-3331-4316-9FDD-C928E3959740} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system\vga.dll (file missing)
O2 - BHO: (no name) - {8C3B7860-062B-4CFA-8534-8181ABB9B427} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9ACC1661-966F-4AC0-95BE-4D5FDABD4B34} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9B0F1A6D-5004-402F-98C4-2C2407C3334E} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {A6DAB8D0-954D-4192-AF3C-8195352273E9} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {A91D33B1-4B85-4B36-A395-DFDBB116C91D} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {AF3A2994-00A3-4EB9-9A2F-3BC60011CF31} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B14A34D7-DEB2-4D7F-A610-EB9BA8D572FB} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B2C5B9AD-9B42-4048-8818-D184C15EA374} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B8E4AD23-1B90-404E-9970-1BDFD7BAB378} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {C5EF780D-4AC4-4072-BDBB-98A7950E6742} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {DCAD8EFC-F483-498B-9A6A-A148D6345DCA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {E893B8F6-5E76-4579-9548-B6CF303AD521} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FA60696B-051D-42F1-B600-3EA8B4CEF531} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FEE9A69E-C489-46CB-B278-5D503A89767B} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smiley District] C:\Program Files\SmileyDistrict\plugin.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll
O20 - Winlogon Notify: khhgg - khhgg.dll (file missing)
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\DGMRTP.DLL (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

This was on the C:\vundofix.txt file:

VundoFix V5.1.7

Checking Java version…

Java version is 1.4.2.3

Scan started at 8:20:24 PM 8/11/2006

Listing files found while scanning….

C:\WINDOWS\system32\Drivers\DP.sys

Beginning removal…

The process smss.exe was successfully stopped

The process winlogon.exe was successfully stopped

The process explorer.exe was successfully stopped

The process iexplore.exe was successfully stopped

The process rundll32.exe was successfully stopped

Attempting to delete C:\WINDOWS\system32\Drivers\DP.sys
C:\WINDOWS\system32\Drivers\DP.sys Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V5.1.7

Checking Java version…

Java version is 1.4.2.3

Scan started at 8:55:23 PM 8/11/2006

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V5.1.7

Checking Java version…

Java version is 1.4.2.3

Scan started at 12:31:41 AM 8/12/2006

Listing files found while scanning….


VundoFix V5.1.7

Checking Java version…

Java version is 1.4.2.3

Scan started at 4:43:31 AM 8/12/2006

Listing files found while scanning….

No infected files were found.


Beginning removal…

The process smss.exe was successfully stopped

The process winlogon.exe was successfully stopped

The process explorer.exe was successfully stopped

The process iexplore.exe was successfully stopped

The process rundll32.exe was successfully stopped

Attempting to delete C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\mllji.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system\vga.dll
C:\WINDOWS\system\vga.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\mllji.dll Could not be deleted.

Attempting to delete C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\mllji.dll Could not be deleted.

Attempting to delete C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\mllji.dll Could not be deleted.

Attempting to delete C:\WINDOWS\SYSTEM32\mllji.dll
C:\WINDOWS\SYSTEM32\mllji.dll Could not be deleted.

Performing Repairs to the registry.
Done!
Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory

MSWINSCK.OCX
Here is the Look2Me-Destroyer log

Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 8/13/2006 3:16:06 PM

Infected! C:\WINDOWS\system32\DGMRTP.DLL

Attempting to delete infected files…

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Run

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{BB2A5A2F-53A8-4BF2-829E-54863E46D273}"
HKCR\Clsid\{BB2A5A2F-53A8-4BF2-829E-54863E46D273}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

Here is my new HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 5:15:46 PM, on 8/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SmileyDistrict\plugin.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\LYDIAG~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {05F4AAEA-7CFA-4768-8978-76B601D83075} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {17B9662A-07EE-4035-BC5B-C2D4171C9CCC} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {1E910EB7-22BD-4C18-826C-54C55E93C0E7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\system32\mllji.dll
O2 - BHO: (no name) - {24646168-30A5-463A-B54B-D0D22EFF8CB4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {3619FCC7-26A5-4CC2-88AC-BDA29ED15F77} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4119C436-6FFF-45EF-BEBB-2A4487CDDEA4} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {4F2E1265-8C29-46A5-8CE4-E007B5597906} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {52410B9E-3B38-4624-9BC6-9351B2FD1785} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5380E79C-F79F-4745-A153-9BC2FD4366FE} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {587596F6-79C9-49BB-AB29-1E5849785D29} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {5992A728-DA27-4B25-9BA1-47C1C67333B5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {61F9D8E7-CD4D-471C-B83F-B8D3D6E12B36} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {68CABCDA-1318-4C84-B368-4AE10E9E86EF} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {690770E4-0FF0-4BCE-B462-57DBC2FA0ED7} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CB90B47-DCB0-4C6A-87E2-7D5ABE3296FA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {6CD4E24C-43F8-4724-92BE-A19C583296D5} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {7893A24B-3331-4316-9FDD-C928E3959740} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system\vga.dll (file missing)
O2 - BHO: (no name) - {8C3B7860-062B-4CFA-8534-8181ABB9B427} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9ACC1661-966F-4AC0-95BE-4D5FDABD4B34} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {9B0F1A6D-5004-402F-98C4-2C2407C3334E} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {A6DAB8D0-954D-4192-AF3C-8195352273E9} - C:\Program Files\CSBB\CSBB.dll (file missing)
O2 - BHO: (no name) - {A91D33B1-4B85-4B36-A395-DFDBB116C91D} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {AF3A2994-00A3-4EB9-9A2F-3BC60011CF31} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B14A34D7-DEB2-4D7F-A610-EB9BA8D572FB} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B2C5B9AD-9B42-4048-8818-D184C15EA374} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {B8E4AD23-1B90-404E-9970-1BDFD7BAB378} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {C5EF780D-4AC4-4072-BDBB-98A7950E6742} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {DCAD8EFC-F483-498B-9A6A-A148D6345DCA} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {E893B8F6-5E76-4579-9548-B6CF303AD521} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FA60696B-051D-42F1-B600-3EA8B4CEF531} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O2 - BHO: (no name) - {FEE9A69E-C489-46CB-B278-5D503A89767B} - C:\Program Files\y4uzj29l\y4uzj29l.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smiley District] C:\Program Files\SmileyDistrict\plugin.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll
O20 - Winlogon Notify: khhgg - khhgg.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {05F4AAEA-7CFA-4768-8978-76B601D83075} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {17B9662A-07EE-4035-BC5B-C2D4171C9CCC} - C:\Program Files\CSBB\CSBB.dll (file missing)

O2 - BHO: (no name) - {1E910EB7-22BD-4C18-826C-54C55E93C0E7} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINDOWS\system32\mllji.dll

O2 - BHO: (no name) - {24646168-30A5-463A-B54B-D0D22EFF8CB4} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {3619FCC7-26A5-4CC2-88AC-BDA29ED15F77} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {4119C436-6FFF-45EF-BEBB-2A4487CDDEA4} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {4F2E1265-8C29-46A5-8CE4-E007B5597906} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {52410B9E-3B38-4624-9BC6-9351B2FD1785} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {5380E79C-F79F-4745-A153-9BC2FD4366FE} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {587596F6-79C9-49BB-AB29-1E5849785D29} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {5992A728-DA27-4B25-9BA1-47C1C67333B5} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {61F9D8E7-CD4D-471C-B83F-B8D3D6E12B36} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {68CABCDA-1318-4C84-B368-4AE10E9E86EF} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {690770E4-0FF0-4BCE-B462-57DBC2FA0ED7} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {6CB90B47-DCB0-4C6A-87E2-7D5ABE3296FA} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {6CD4E24C-43F8-4724-92BE-A19C583296D5} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {7893A24B-3331-4316-9FDD-C928E3959740} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system\vga.dll (file missing)

O2 - BHO: (no name) - {8C3B7860-062B-4CFA-8534-8181ABB9B427} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {9ACC1661-966F-4AC0-95BE-4D5FDABD4B34} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {9B0F1A6D-5004-402F-98C4-2C2407C3334E} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {A6DAB8D0-954D-4192-AF3C-8195352273E9} - C:\Program Files\CSBB\CSBB.dll (file missing)

O2 - BHO: (no name) - {A91D33B1-4B85-4B36-A395-DFDBB116C91D} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {AF3A2994-00A3-4EB9-9A2F-3BC60011CF31} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {B14A34D7-DEB2-4D7F-A610-EB9BA8D572FB} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {B2C5B9AD-9B42-4048-8818-D184C15EA374} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {B8E4AD23-1B90-404E-9970-1BDFD7BAB378} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {C5EF780D-4AC4-4072-BDBB-98A7950E6742} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {DCAD8EFC-F483-498B-9A6A-A148D6345DCA} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {E893B8F6-5E76-4579-9548-B6CF303AD521} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {FA60696B-051D-42F1-B600-3EA8B4CEF531} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O2 - BHO: (no name) - {FEE9A69E-C489-46CB-B278-5D503A89767B} - C:\Program Files\y4uzj29l\y4uzj29l.dll

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll

O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll

O20 - Winlogon Notify: khhgg - khhgg.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\y4uzj29l <— FOLDER

c:\windows\system32\euuqmjpr.dll <— file

c:\windows\system32\inetsvc.dll <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread.

Please keep your replies to this thread by using the "Add Reply" button, located at the bottom, right of this page.

:)
Due to lack of feedback:

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI