This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijack this --- pop ups, pop ups

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I need some help with eliminating the pop ads from my pc. The come up constantly and although I think I remove them they always return. Usually something to do with downloading antivirus and spy software.
I have run Adaware, Spybot and Ewido to no avail.
Any help would be greatly appreciated.

Thanks
Tim


Logfile of HijackThis v1.99.1
Scan saved at 8:04:10 PM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\dGltIGh1bnNpY2tlcg\command.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Browser Mouse\mouse32a.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
C:\nwnmff_14.exe
C:\dfndrff_14.exe
C:\kybrdff_14.exe
C:\WINDOWS\xload.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\win3209284269201.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\sys01842692012.exe
C:\WINDOWS\bijvseeA.exe
C:\WINDOWS\system32\czuehf.exe
C:\WINDOWS\system32\kcnzrop6.exe
C:\WINDOWS\win3208128426920.exe
C:\WINDOWS\sys02426920128.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\windows\system32\rlvknlg.exe
C:\Program Files\Common Files\{10F19A91-069E-1033-0314-021220010001}\Update.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\Program Files\System Files\System.exe
C:\PROGRA~1\COMMON~1\irfw\irfwm.exe
C:\Program Files\PSLister\PSLister.exe
C:\Program Files\CMFibula\CMFibula.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\ha3f.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ewxcksr.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\fufudc.exe
C:\Documents and Settings\tim hunsicker\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,gpqfbot.exe
O2 - BHO: Bucket Class - {00000001-C003-4A2F-9142-7CB1D78DE6C1} - C:\WINDOWS\tct101.dll
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [newname] C:\\nwnmff_14.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_14.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_14.exe
O4 - HKLM\..\Run: [xload] "C:\WINDOWS\xload.exe"
O4 - HKLM\..\Run: [w0016711.dll] RUNDLL32.EXE w0016711.dll,I2 002a930a00016711
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\qwinlpex.exe CORN003
O4 - HKLM\..\Run: [win3209284269201] C:\WINDOWS\win3209284269201.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [sys01842692012] C:\WINDOWS\sys01842692012.exe
O4 - HKLM\..\Run: [bijvseeA] C:\WINDOWS\bijvseeA.exe
O4 - HKLM\..\Run: [RreN4HW] C:\WINDOWS\system32\czuehf.exe
O4 - HKLM\..\Run: [FQQERQ] "C:\WINDOWS\system32\kcnzrop6.exe"
O4 - HKLM\..\Run: [win3208128426920] C:\WINDOWS\win3208128426920.exe
O4 - HKLM\..\Run: [loaddr] C:\topaff.exe
O4 - HKLM\..\Run: [sys02426920128] C:\WINDOWS\sys02426920128.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [RelevantKnowledge] c:\windows\system32\rlvknlg.exe -boot
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [irfw] C:\PROGRA~1\COMMON~1\irfw\irfwm.exe
O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\qwinlpex.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.com
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/pro…138302D2D2D.exe
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.media-motor.net/cabs/joysavsht.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1142785441109
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O18 - Filter: text/html - {65BD126C-9E4B-4371-911F-EE85CA17D52B} - C:\WINDOWS\system32\OTPDDP~1.DLL
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\fp0003dme.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\dGltIGh1bnNpY2tlcg\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\bijvsee.exe
timboxcviii :D

Welcome to the forum, sorry for the delay in responding. Let me tell ya, you have quite a nice array of malware and trojans on your system :thumbdown:


Some of the infections that you have act as magnets to download other malware, some of what you have can also compromise your online security. I would strongly suggest that except for posting here that you stay off the internet until we have you all cleaned up.



Let do this first.


Please download ComboFix from either of these two locations

BleepingComputerComboFix
TechSupportForumComboFix
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Post back with the log from ComboFix and a new HJT log please.
Sorry for the delay in responding. I was not around my pc for a while. It seems to be better, but would still like your apinion and assistance.
Here are the logs:

tim hunsicker - 06-09-14 18:11:16.09 Service Pack 2
ComboFix 06.09.14 - Running from: C:\Documents and Settings\[removed]\Desktop

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\SYSTEM32\dkvmgr.dll
C:\WINDOWS\SYSTEM32\gpr8l39u1.dll
C:\WINDOWS\SYSTEM32\h0j4la1q1d.dll
C:\WINDOWS\SYSTEM32\guard.tmp


Granting sedebugprivilege to Administrators … successful


((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-08-26 14:51 28672 ra8pv.exe.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\tim hunsicker\Application Data\Sskknwrd.dll
C:\Documents and Settings\tim hunsicker\Application Data\Sskuknwrd.dll
C:\WINDOWS\system32\bk.exe
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\drsmartload2.dat
C:\WINDOWS\Duce6.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\teller2.chk
C:\dfndref_7.exe
C:\dfndrff_11.exe
C:\dfndrff_11a.exe
C:\dfndrff_12.exe
C:\dfndrff_13.exe
C:\dfndrff_8.exe
C:\dfndrff_9.exe
C:\dfndrfg_8.exe
C:\dfndrfh_10.exe
C:\drsmartload.exe
C:\drsmartload1.exe
C:\drsmartload45a1001.exe
C:\drsmartload45a2002.exe
C:\drsmartload45a2002a.exe
C:\drsmartload45a3344a.exe
C:\drsmartload45a45f.exe
C:\drsmartload45a7h.exe
C:\drsmartload45a8b.exe
C:\drsmartload45a8b9abc.exe
C:\drsmartload45a99.exe
C:\drsmartload45a9999a.exe
C:\drsmartload46a1001.exe
C:\drsmartload46a2002.exe
C:\drsmartload46a2002a.exe
C:\drsmartload46a3344a.exe
C:\drsmartload46a46f.exe
C:\drsmartload46a7h.exe
C:\drsmartload46a8b.exe
C:\drsmartload46a8b9abc.exe
C:\drsmartload46a99.exe
C:\drsmartload46a9999a.exe
C:\drsmartload849a1001.exe
C:\drsmartload849a2002.exe
C:\drsmartload849a2002a.exe
C:\drsmartload849a3344a.exe
C:\drsmartload849a7h.exe
C:\drsmartload849a849f.exe
C:\drsmartload849a8b.exe
C:\drsmartload849a8b9abc.exe
C:\drsmartload849a99.exe
C:\drsmartload849a9999a.exe
C:\deskbar.exe
C:\kybrdef_7.exe
C:\kybrdff_11.exe
C:\kybrdff_11a.exe
C:\kybrdff_12.exe
C:\kybrdff_13.exe
C:\kybrdff_8.exe
C:\kybrdff_9.exe
C:\kybrdfg_8.exe
C:\kybrdfh_10.exe
C:\MTE3NDI6ODoxNgnew.exe
C:\nwnmef_7.exe
C:\nwnmff_11.exe
C:\nwnmff_12.exe
C:\nwnmff_13.exe
C:\nwnmff_8.exe
C:\nwnmff_9.exe
C:\nwnmfg_8.exe
C:\nwnmfh_10.exe
C:\stub_113_4_0_4_0newer.exe
C:\warebundlenewer.exe
C:\Documents and Settings\tim hunsicker\Application Data\Install.dat
C:\WINDOWS\system32\BattyRun.dll
C:\WINDOWS\system32\bez6n4r21.exe
C:\WINDOWS\system32\ftuninst.exe
C:\WINDOWS\system32\icon_mediamotor.exe
C:\WINDOWS\system32\javaw.dll
C:\WINDOWS\system32\mptft.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\redist.dll
C:\WINDOWS\system32\redistributor.exe
C:\WINDOWS\system32\smss.dll
C:\WINDOWS\system32\ssec.exe
C:\WINDOWS\system32\tfthot.exe
C:\WINDOWS\system32\tpuninstall.exe
C:\WINDOWS\system32\ts_mediamotor.exe
C:\WINDOWS\system32\tsuninst.exe
C:\WINDOWS\system32\v199.dll
C:\WINDOWS\system32\vm7cmapox.dll
C:\WINDOWS\system32\VSL05.exe
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\system32\xeymi.dll
C:\RDFX4.exe
C:\visfx500new.exe
C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
C:\WINDOWS\media_motor_bundle.exe
C:\WINDOWS\offun.exe
C:\WINDOWS\pf78.exe
C:\WINDOWS\ssqbn.exe
C:\WINDOWS\system32bez6n4r21.exe
C:\WINDOWS\system32ftuninst.exe
C:\WINDOWS\system32ghynf.exe
C:\WINDOWS\system32n9nyb.exe
C:\WINDOWS\System32ssec.exe
C:\WINDOWS\System32tfthot.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\uni_eh.exe
C:\WINDOWS\uni_ehhh.exe
C:\WINDOWS\unin101.exe
C:\WINDOWS\uninst104.exe
C:\WINDOWS\RDFX4.exe
C:\WINDOWS\MirarSetup_876075.exe
C:\WINDOWS\uni_ehhhh.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\w0014c56.dll
C:\WINDOWS\system32\w0016711.dll
C:\WINDOWS\system32\w0028705.dll
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Program Files\batty2
C:\Program Files\Cas2Stub
C:\Program Files\cmfibula
C:\Program Files\Cowabanga
C:\Program Files\Deskbar
C:\Program Files\Inetget2
C:\Program Files\Ipwins
C:\Program Files\network monitor
C:\Program Files\PSLister
C:\Program Files\System Files
C:\Program Files\System Icons
C:\Program Files\windows
C:\WINDOWS\system32\crunner
C:\Program Files\Common Files\{10F19A91-069E-1033-0314-021220010001}

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\tim hunsicker\Application Data\ICROSO~1
C:\QooBox\Purity\Documents and Settings\tim hunsicker\My Documents\ECURIT~1
C:\QooBox\Purity\Documents and Settings\tim hunsicker\My Documents\ECURIT~1\scanregw.exe
C:\QooBox\Purity\Documents and Settings\tim hunsicker\My Documents\ECURIT~1\?ecurity
C:\QooBox\Purity\WINDOWS\SYSTEM32\SEMBLY~1


((((((((((((((((((((((((((((((( Files Created from 2006-08-14 to 2006-09-14 ))))))))))))))))))))))))))))))))))


2006-08-29 10:55 307,200 –a—— C:\WINDOWS\SYSTEM32\rlls(2).dll
2006-08-28 00:00 30,208 –a—— C:\SS1001newer.exe
2006-08-28 00:00 234,272 -r–s—- C:\WINDOWS\SYSTEM32\CZDetres.dll
2006-08-27 10:08 290,816 –a—— C:\installerwnusnewer.exe
2006-08-26 14:51 45,056 –a—— C:\WINDOWS\system32fufudc.exe
2006-08-26 14:51 45,056 –a—— C:\WINDOWS\SYSTEM32\fufudc.exe
2006-08-26 14:51 28,672 –a—— C:\WINDOWS\system32ra8pv.exe
2006-08-26 14:51 28,672 –a—— C:\WINDOWS\SYSTEM32\mnopdb.exe
2006-08-26 14:51 24,576 –a—— C:\WINDOWS\system32ha3f.exe
2006-08-26 14:51 24,576 –a—— C:\WINDOWS\SYSTEM32\ha3f.exe
2006-08-26 14:51 208,896 –a—— C:\WINDOWS\SYSTEM32\otpddpea5.dll
2006-08-16 13:08 53,120 –a—— C:\WINDOWS\srvzyimvqd.exe
2006-08-16 13:08 507,904 –a—— C:\814.exe
2006-08-16 13:08 353,280 –a—— C:\803_104.exe
2006-08-16 13:08 214,749 –a—— C:\WINDOWS\srvwnfhcpl.exe
2006-08-16 13:08 186,223 –a—— C:\WINDOWS\srvmneweij.exe
2006-08-16 13:08 1,043,728 –a—— C:\WINDOWS\__delete_on_reboot__bijvsee.exe
2006-08-16 00:00 214,752 –a—— C:\Setup100.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-14 18:12 ——– d——– C:\Program Files\Common Files
2006-09-05 22:18 ——– d——– C:\Program Files\Viewpoint
2006-09-05 22:18 ——– d——– C:\Program Files\AOD
2006-09-05 22:18 ——– d——– C:\Program Files\AIM
2006-09-05 22:18 ——– d——– C:\Documents and Settings\tim hunsicker\Application Data\Aim
2006-09-05 20:47 ——– d——– C:\Program Files\PartyPoker
2006-09-05 20:47 ——– d——– C:\Program Files\PartyGaming
2006-09-05 19:44 ——– d——– C:\Program Files\Napster
2006-09-05 19:39 ——– d——– C:\Program Files\Common Files\Napster Shared
2006-09-03 09:41 ——– d——– C:\Program Files\TheSearchAccelerator(2)
2006-09-03 09:41 ——– d——– C:\Program Files\Common Files\irfw
2006-09-03 09:20 ——– d——– C:\Program Files\Modem Helper
2006-08-31 19:21 ——– d——– C:\Program Files\Microsoft Works
2006-08-30 21:11 ——– d——– C:\Program Files\Microsoft Picture It! 2002
2006-08-26 14:51 ——– d——– C:\Program Files\SEARCHESSISTANT Toolbar
2006-08-21 00:01 ——– d——– C:\Program Files\Online Services
2006-08-21 00:01 ——– d——– C:\Program Files\MSN Gaming Zone
2006-08-21 00:01 ——– d——– C:\Program Files\ComPlus Applications
2006-08-19 08:03 ——– d——– C:\Program Files\ewido anti-malware
2006-08-13 03:03 ——– d——– C:\Program Files\Internet Explorer
2006-08-13 03:01 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-08-11 12:05 155648 –a—— C:\WINDOWS\win3209284269201.exe
2006-08-11 12:05 155648 –a—— C:\WINDOWS\sys01842692012.exe
2006-08-07 20:54 ——– d——– C:\Program Files\Messenger
2006-08-07 20:50 ——– d——– C:\Program Files\Outlook Express
2006-08-07 20:50 ——– d——– C:\Program Files\Common Files\System
2006-08-07 11:17 61440 –a—— C:\WINDOWS\SYSTEM32\BattyRun2.dll
2006-08-06 12:12 931 –a—— C:\WINDOWS\SYSTEM32\winpfg32.sys
2006-08-06 12:12 168063 –a—— C:\WINDOWS\SYSTEM32\qwinlpex.exe
2006-08-06 11:12 2 –a—— C:\WINDOWS\SYSTEM32\wcpsvcc.exe
2006-08-06 11:11 57344 –a—— C:\WINDOWS\cs2m6f.exe
2006-08-06 11:11 45056 –a—— C:\WINDOWS\system32zkdmg.exe
2006-08-06 11:11 36864 –a—— C:\WINDOWS\system32uvzgi.exe
2006-08-06 11:11 36864 –a—— C:\WINDOWS\SYSTEM32\uvzgi.exe
2006-08-06 11:11 32768 –a—— C:\WINDOWS\unstall.exe
2006-08-06 11:11 28672 –a—— C:\WINDOWS\system32tpsd.exe
2006-08-06 11:11 28672 –a—— C:\WINDOWS\SYSTEM32\tpsd.exe
2006-08-06 11:11 28672 –a—— C:\WINDOWS\SYSTEM32\poznfsqy.exe
2006-08-04 22:53 ——– d——– C:\Program Files\webHancer(2)
2006-08-04 22:22 ——– d—s—- C:\Documents and Settings\tim hunsicker\Application Data\Microsoft
2006-08-04 22:19 159744 –a—— C:\WINDOWS\SYSTEM32\redist(2).dll
2006-07-31 12:10 1142784 –a—— C:\WINDOWS\SYSTEM32\kcnzrop6.exe
2006-07-31 12:09 24576 –a—— C:\WINDOWS\SYSTEM32\ewxcksr.exe
2006-07-31 12:08 135168 –a—— C:\WINDOWS\SYSTEM32\czuehf.exe
2006-07-27 09:24 679424 –a—— C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-07-26 08:42 ——– d——– C:\Program Files\Windows Media Player
2006-07-26 08:42 ——– d——– C:\Program Files\Movie Maker
2006-07-26 08:39 ——– d——– C:\Program Files\Windows NT
2006-07-26 08:39 ——– d——– C:\Program Files\NetMeeting
2006-07-26 08:18 ——– d——– C:\Program Files\TClock
2006-07-25 21:49 37376 –a—— C:\WINDOWS\SYSTEM32\aspi257037(2).exe
2006-07-25 20:25 93664 –ahs—- C:\Program Files\Common Files\Y1304OU.exe
2006-07-25 20:24 183887 –a—— C:\WINDOWS\YazzleBundle-1304.exe
2006-07-25 20:24 143360 –a—— C:\WINDOWS\win32092842692012006.exe
2006-07-25 20:24 143360 –a—— C:\WINDOWS\win3208128426920.exe
2006-07-25 20:23 45056 –a—— C:\WINDOWS\zuckdha.exe
2006-07-25 20:23 290816 –a—— C:\WINDOWS\installer_2512.exe
2006-07-25 20:23 28672 –a—— C:\WINDOWS\SYSTEM32\hvzead7v.exe
2006-07-25 20:23 234248 –a—— C:\WINDOWS\Tagasuarus2.exe
2006-07-25 20:11 2560 –a—— C:\WINDOWS\_MSRSTRT.EXE
2006-07-25 20:10 ——– d——– C:\Program Files\Screensavers.com
2006-07-25 20:05 14617 –a—— C:\WINDOWS\xload.exe
2006-07-25 20:03 69632 –a—— C:\WINDOWS\SYSTEM32\hjcienjm.dll
2006-07-25 20:03 69632 –a—— C:\WINDOWS\SYSTEM32\fhoijali.dll
2006-07-25 20:03 61440 –a—— C:\WINDOWS\SYSTEM32\fnnf7da6.dll
2006-07-25 20:03 587776 –a—— C:\626_101newer.exe
2006-07-25 20:03 29696 –a—— C:\WINDOWS\SYSTEM32\w1002497f.dll
2006-07-25 20:03 2560 –a—— C:\ac3_0003.exe
2006-07-25 20:03 235134 –a—— C:\WINDOWS\srvpyranjr.exe
2006-07-25 20:03 184829 –a—— C:\WINDOWS\srvwtnsqlc.exe
2006-07-25 20:03 1063 –a—— C:\WINDOWS\SYSTEM32\fnnf7da6.sys
2006-07-25 20:03 ——– d——– C:\Program Files\PSHope
2006-07-25 20:02 143360 –a—— C:\WINDOWS\ms04692012842.exe
2006-07-25 20:01 57344 –a—— C:\fym9bvo.exe
2006-07-25 20:01 53120 –a—— C:\WINDOWS\optimize.exe
2006-07-25 20:01 42944 –a—— C:\WINDOWS\pop06ap2.exe
2006-07-25 20:01 28672 –a—— C:\WINDOWS\SYSTEM32\iqqr.exe
2006-07-25 20:01 102400 –a—— C:\WINDOWS\mirar.exe
2006-07-25 20:01 0 –a—— C:\Documents and Settings\tim hunsicker\Application Data\internaldb41.dat
2006-07-21 04:24 72704 –a—— C:\WINDOWS\SYSTEM32\hlink.dll
2006-07-03 10:53 24576 –a—— C:\WINDOWS\SYSTEM32\xd7ehbkw.exe
2006-07-03 10:53 1142784 –a—— C:\WINDOWS\SYSTEM32\bdpn.exe
2006-06-29 05:24 83456 –a—— C:\WINDOWS\SYSTEM32\nse16F.dll
2006-06-16 11:41 155648 —hs—- C:\Program Files\Common Files\Y1304OA.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\Money Express.exe\""
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet"
"PopUpStopperFreeEdition"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~2\\PSFree.exe\""
"MSMSGS"="\"C:\\Program Files\\Messenger\\MSMSGS.EXE\" /background"
"RealPlayer"="\"C:\\Program Files\\Real\\RealPlayer\\realplay.exe\" /RunUPGToolCommandReBoot"
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"
"AIM"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"DellTouch"="C:\\WINDOWS\\DELLMMKB.EXE"
"AHQInit"="C:\\Program Files\\Creative\\SBLive\\Program\\AHQInit.exe"
"DIAGENT"="C:\\Program Files\\Creative\\SBLive\\Creative Diagnostics 2.0\\DIAGENT.EXE startup"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb05.exe"
"nwiz"="nwiz.exe /install"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Browser Mouse\\mouse32a.exe"
"FLMK08KB"="C:\\Program Files\\Muiltmedia keyboard utility\\1.1\\MMKEYBD.EXE"
"NapsterShell"="C:\\Program Files\\Napster\\napster.exe /systray"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ea,00,00,00,00,00,00,00,16,03,00,00,e4,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,ea,00,00,00,00,00,00,00,16,03,00,00,e4,02,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=hex:5f,00,00,00
@=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job




HIJACKTHIS LOG:


Logfile of HijackThis v1.99.1
Scan saved at 6:19:07 PM, on 9/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Browser Mouse\mouse32a.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\tim hunsicker\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\qwinlpex.exe CORN003
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\qwinlpex.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1142785441109
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


Please let me know what to do next.


Thanks again for all your help
Tim
timboxcviii :D

Just wanted to mention that the ComboFix tool was written by one of the wonderful people in the malware removal community by the name of sUbs over at Bleeping Computer. It really cleaned about 99% of the bad stuff off of your system. Some of the things that it did not clean where infections that the tool was not designed for, we are going to remove them manually.




C:\Program Files\Napster
These file and song sharing sites are one of the biggest reasons people get infected, I would strongly urge you to remove this program form the Add-Remove Programs in the Control Panel.


Open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked

Remove this one only if you removed Napster
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\qwinlpex.exe CORN003
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\qwinlpex.exe



More bad sites that bring nothing but trouble
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.


Boot into Safemode and delete this file
C:\WINDOWS\SYSTEM32\qwinlpex.exe

Boot into Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard



Boot normally and run this system cleaner.

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.


Post a new HJT log and let me know how your system is running now.
Okay,
Here is the new log. I kept the Napster for now because I use it with my pionner inno to manage my music. If you still think it is a problem I can get rid of it.

the system is running 100% better. I continue to appreciate you assistance.

Tim

Logfile of HijackThis v1.99.1
Scan saved at 6:16:15 PM, on 9/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Browser Mouse\mouse32a.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Microsoft Money\System\Money Express.exe
C:\Program Files\Muiltmedia keyboard utility\1.1\KbdAp32A.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Netropa\OSD.exe
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\tim hunsicker\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.1\MMKEYBD.EXE
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1142785441109
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Tim :D

Clean log. :thumbup: Napster itself is not a malicious program, but you just have to be real careful what you download.

Tim, with all the bad infections you had on this system, I would dive in and clean out all the temp files and such as i have them listed, also your system restore, all that garbage is backed up in that program and you can take the chance of reinfecting your self if you use it to revert your system to an earlier date.


I see Symantec Live Update but do not see the program itself. I have Free AV listed if you need one.




Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

Be sure to follow the instructions for System Restore because everything we removed is backed up in that program and if you ever use it to revert your system to an earlier date, you can reinfect your self all over again.


Download and Install CCleaner

* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.

* Clean out your Temp Files
* This procedure should be run from Safemode for better results.


Boot into Safemode

* Go to Start> Shut off your Computer> Restart
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the Up and Down Arrow Keys to scroll up to Safemode
* Then press the Enter Key on your Keyboard




* Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer Local Settings and delete all the contents of the Temp Folder and the Temporary Internet Files Folder <–Just the contents, not the folder itself.

* Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <– But not the temp folder itself.

* Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. <–But not the Prefetch folder itself.



Reboot your system normally


Close any instance of Internet Explorer and Windows Explorer.
  • Go to Start> Control Panel> Internet Options . You shoud be on the General Tab
  • Delete Cookies
  • Delete Files > and offline content as well

Now Empty your Recycle Bin


System Restore makes regular backups of all your settings, if you ever had to use this program to restore your
system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this


Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

Here are Free Anti-Virus Programs if you need one. Just install one because with AV software…MORE IS NOT BETTER.
* AVG Free Edition
* AntVir Personal Edition


* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.

* Spyware Blaster It will prevent most spyware from ever being installed.

* Spyware Guard It offers realtime protection from spyware installation attempts.

* Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.

* IE- Spyad IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

* Firefox Browser It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

* Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.

* Windows Updates Go to Start> Control Panel> Security Center> Windows Updates and check the radio button that says " Notify me but don't automatically download and install them "

* Go to Start> All Programs> Assessories > System Tools> Disk Defragmenter. This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.



Thanks for stopping by Tom Coyote , I'm glad I was able to help you.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI