This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Taken Over! Help Please!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello -

My computer has recently become unusable due to malware. I regularly run AntiVir antivirus scans, and AdAware and Spybot scans. Since this computer is also used by my wife and kids, I always find something minor. But major problems have arisen in the last week or two.

These include: automatic reboots whether the computer is in use or not (sometimes multiple times within a few minutes), and not being able to run programs from the Start Menu (e.g. Control Panel, My Computer, etc.). When I try the latter the screen refreshes and deletes toolbars, shortcuts, etc.

Attached is a HiJackThis log I had to create in Safe Mode because of the above mentioned screen refresh issue. I cannot run the program within regular mode.

Any help is greatly appreciated!!! :rant2:

Thanks!

Jim

—————————————–

Logfile of HijackThis v1.99.1
Scan saved at 9:13:59 PM, on 9/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0B90AA1B-F649-44C3-9FD3-736C332CBBCF} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {51FFBE57-CEF4-4E80-8355-BBEA484A3B93} - C:\WINDOWS\SERVIC~1\vddnds.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {79581D8D-337E-452A-8075-C21A8946A78B} - C:\WINDOWS\ServicePackFiles\vddnds.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\System32\mljgf.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Smiley District] C:\Program Files\SmileyDistrict\plugin.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C…/bridge-c10.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\System32\hardsys.dll
O20 - Winlogon Notify: htproc - htproc32.dll (file missing)
O20 - Winlogon Notify: mljgf - C:\WINDOWS\System32\mljgf.dll
O20 - Winlogon Notify: mljgg - C:\WINDOWS\System32\mljgg.dll
O20 - Winlogon Notify: mllji - C:\WINDOWS\System32\mllji.dll
O20 - Winlogon Notify: mllmm - C:\WINDOWS\System32\mllmm.dll
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\SYSTEM32\nmvwylcx.dll
O20 - Winlogon Notify: paafx - C:\WINDOWS\system32\3com_dmi\paafx.dll
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\System32\pmkhg.dll
O20 - Winlogon Notify: pmkjg - C:\WINDOWS\System32\pmkjg.dll
O20 - Winlogon Notify: pmnlk - C:\WINDOWS\System32\pmnlk.dll
O20 - Winlogon Notify: ssqpp - C:\WINDOWS\System32\ssqpp.dll
O20 - Winlogon Notify: ssqro - C:\WINDOWS\System32\ssqro.dll
O20 - Winlogon Notify: ssqrq - C:\WINDOWS\System32\ssqrq.dll
O20 - Winlogon Notify: vddnds - C:\WINDOWS\SERVIC~1\vddnds.dll
O20 - Winlogon Notify: vtutq - C:\WINDOWS\System32\vtutq.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\System32\xmlcom.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Download VundoFix.exe by Atribune from here and save it to your desktop.to your desktop.
  • Close all open programs and windows as this may require a reboot.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HiJackThis log.
Also, run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thanks for your reply Noviciate! :)

I downloaded and ran VundoFix.exe in regular Windows mode. However, I could only view the text file in Safe Mode because of the problem I mentioned earlier where I cannot access My Computer via Start Menu in regular mode. I also ran HJT in Safe Mode. Attached are the requested log files.

——————————-

VundoFix V6.1.2

Checking Java version…

Java version is 1.5.0.8

Scan started at 6:56:40 PM 9/5/2006

Listing files found while scanning….

C:\WINDOWS\system32\rqdbsnxd.exe
C:\WINDOWS\system32\wmmjatwm.exe
C:\WINDOWS\system32\yidnghjw.exe

Beginning removal…

Attempting to delete C:\WINDOWS\system32\rqdbsnxd.exe
C:\WINDOWS\system32\rqdbsnxd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wmmjatwm.exe
C:\WINDOWS\system32\wmmjatwm.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\yidnghjw.exe
C:\WINDOWS\system32\yidnghjw.exe Has been deleted!

Performing Repairs to the registry.
Done!

————————-

Logfile of HijackThis v1.99.1
Scan saved at 7:22:52 PM, on 9/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0B90AA1B-F649-44C3-9FD3-736C332CBBCF} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {51FFBE57-CEF4-4E80-8355-BBEA484A3B93} - C:\WINDOWS\SERVIC~1\vddnds.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {79581D8D-337E-452A-8075-C21A8946A78B} - C:\WINDOWS\ServicePackFiles\vddnds.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\System32\mljgf.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Smiley District] C:\Program Files\SmileyDistrict\plugin.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/6247971C…/bridge-c10.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} (Java Plug-in 1.3.1) -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.3.1_02) -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\System32\hardsys.dll
O20 - Winlogon Notify: htproc - htproc32.dll (file missing)
O20 - Winlogon Notify: mljgf - C:\WINDOWS\System32\mljgf.dll
O20 - Winlogon Notify: mljgg - C:\WINDOWS\System32\mljgg.dll
O20 - Winlogon Notify: mllji - C:\WINDOWS\System32\mllji.dll
O20 - Winlogon Notify: mllmm - C:\WINDOWS\System32\mllmm.dll
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\SYSTEM32\nmvwylcx.dll
O20 - Winlogon Notify: paafx - C:\WINDOWS\system32\3com_dmi\paafx.dll
O20 - Winlogon Notify: pmkhg - C:\WINDOWS\System32\pmkhg.dll
O20 - Winlogon Notify: pmkjg - C:\WINDOWS\System32\pmkjg.dll
O20 - Winlogon Notify: pmnlk - C:\WINDOWS\System32\pmnlk.dll
O20 - Winlogon Notify: ssqpp - C:\WINDOWS\System32\ssqpp.dll
O20 - Winlogon Notify: ssqro - C:\WINDOWS\System32\ssqro.dll
O20 - Winlogon Notify: ssqrq - C:\WINDOWS\System32\ssqrq.dll
O20 - Winlogon Notify: vddnds - C:\WINDOWS\SERVIC~1\vddnds.dll
O20 - Winlogon Notify: vtutq - C:\WINDOWS\System32\vtutq.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\System32\xmlcom.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

——————————–
(uninstall_list.txt contents)

3D Groove Playback Engine
ACD PhotoStitcher
ACDSee 3.1 (SR-1)
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Shockwave Player
Avira AntiVir PersonalEdition Classic
BitTorrent 3.4.2 (Neurox SecureBT 1.32)
Conexant SoftK56 Modem(M)
DC++ (remove only)
HijackThis 1.99.1
HyperLoad
Intel® Extreme Graphics Driver
iTunes
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment Standard Edition v1.3.1_02
Learn2 Player (Uninstall Only)
LimeWire 4.12.6
MaxSpeed
Microsoft Data Access Components KB870669
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Office Standard Edition 2003
Microsoft Works 6.0
Mozilla Firefox (1.5.0.6)
Netscape 6 (6.2.1)
Netscape Browser (remove only)
PopUpCop
PowerDVD
QuickTime
RealArcade
RealPlayer
Realtek AC'97 Audio
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Shockwave
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Viewpoint Media Player
Winamp (remove only)
Windows Backup Utility
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
XviD MPEG-4 Video Codec
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Toolbar
Download the 14 day trial of Webroot's Spy Sweeper from here.
Once the download has completed, double click the file to begin installation.
During the installation you will be given the option to check for updates - click the button to allow it to do so.
Once the installation has completed, your PC will need to be rebooted.

Once your PC has rebooted, open Spy Sweeper:
  • Click the Options button.
  • Select the Update Tab.
  • Click Update Spy Sweeper.
  • I.E. will open displaying a page from the Spy Sweeper website - you can close this as Spy Sweeper will continue to update regardless.
Once the updates have all been downloaded:
  • Select the Sweep Tab.
  • Check all the boxes under "Items to Sweep" and "Other Options".
  • Now click the Start Sweep button.
Once the scan has completed, Spy Sweeper will display the results of the scan. If anything has been found, click Quarantine Selected.
If you are asked to allow a reboot, do so - if not, manually reboot your PC anyway.

Once the PC has rebooted, open Spy Sweeper:
  • Click the Options button on the left.
  • Select the Sweep Tab again.
  • Click the "View Session Log link in the bottom right hand corner.
  • Click the Save to File button - by default the log will be saved as Spy Sweeper Sessions Log.txt in My Documents.
Copy and paste this into your next reply along with a fresh HJT log AND a description of how your PC is behaving.
Hi Noviciate -

My PC is working much better. I've been on it for at least 2 hours following your instructions, etc. and it has not automatically reboot. Also, I can now execute programs from the Start Menu and in regular Windows mode (no longer using Safe Mode). However, SpywareGuard is still picking up on an attempt to add a BHO to the registry each time I log into my account. Also, I had to perform a hard reboot after the first time I ran Spy Sweeper because the screen froze for almost an hour. So I ran it again following the reboot and followed your instructions from there.


Is the better performance a result of Spy Sweeper? If so, is this a program I'll need to run beyond the free 14 day trial? I ask because I noticed it creates shields that I'm guessing block dll's from re-appearing.

Attached are the log files you requested.

Thanks again,

Jim

——————————

Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:15 PM: Shield States
9:15 PM: Spyware Definitions: 755
9:15 PM: Spy Sweeper 5.0.5.1286 started
8:45 PM: | End of Session, Wednesday, September 06, 2006 |
8:44 PM: Your definitions are up to date.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
8:43 PM: Shield States
8:43 PM: Spyware Definitions: 755
8:42 PM: Spy Sweeper 5.0.5.1286 started
7:29 PM: | End of Session, Wednesday, September 06, 2006 |
7:26 PM: Your definitions are up to date.
7:26 PM: Your spyware definitions have been updated.
Operation: File Access
Target:
Source: C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
7:25 PM: Tamper Detection
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
7:23 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST5C.tmp". Reason: The process cannot access the file because it is being used by another process
7:23 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST5C.tmp.log". Reason: The process cannot access the file because it is being used by another process
ActiveX Shield: On
Windows Messenger Service Shield: On
7:23 PM: Warning: S-1-5-21-982823239-2492322576-3337251515-500 could not be unmapped. Error Code 87
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
7:23 PM: Shield States
7:23 PM: Spyware Definitions: 691
7:23 PM: Spy Sweeper 5.0.5.1286 started
7:23 PM: Spy Sweeper 5.0.5.1286 started
7:23 PM: | Start of Session, Wednesday, September 06, 2006 |
********
8:39 PM: Warning: Failed to quarantine registry items for: S-1-5-21-982823239-2492322576-3337251515-1007
8:39 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The process cannot access the file because it is being used by another process
8:39 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp.log". Reason: The process cannot access the file because it is being used by another process
8:39 PM: Warning: TAllUserItem.Unmap().FlushChanges().UnLoadKey
8:36 PM: Warning: A required privilege is not held by the client
8:35 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The system cannot find the file specified
8:35 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:33 PM: Warning: A required privilege is not held by the client
8:31 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The system cannot find the file specified
8:30 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:28 PM: Warning: A required privilege is not held by the client
8:27 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The system cannot find the file specified
8:27 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:25 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The system cannot find the file specified
8:25 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:21 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C7.tmp". Reason: The system cannot find the file specified
8:21 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:16 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C8.tmp". Reason: The system cannot find the file specified
8:16 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C8.tmp". Reason: The system cannot find the file specified
8:06 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:06 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SST2C8.tmp". Reason: The system cannot find the file specified
8:06 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
8:06 PM: Warning: Quarantine process could not restart Explorer.
8:06 PM: Warning: Launched explorer.exe
8:05 PM: Quarantining All Traces: whenu savenow
8:05 PM: Quarantining All Traces: whenu
8:05 PM: Quarantining All Traces: overture cookie
8:05 PM: Quarantining All Traces: apmebf cookie
8:05 PM: Quarantining All Traces: 180search assistant/zango
8:05 PM: Quarantining All Traces: exact software
8:05 PM: Quarantining All Traces: dialerplatform
8:05 PM: Quarantining All Traces: bho_sep
8:05 PM: Quarantining All Traces: clocksync
8:05 PM: Quarantining All Traces: browseraid
8:05 PM: Quarantining All Traces: websearch.com hijack
8:05 PM: Quarantining All Traces: twain-tech
8:05 PM: Quarantining All Traces: searchbar.html hijack
8:05 PM: Quarantining All Traces: wild media - minigolf
8:05 PM: Quarantining All Traces: shopathomeselect
8:05 PM: Quarantining All Traces: internetoptimizer
8:05 PM: Quarantining All Traces: sidesearch
8:05 PM: Quarantining All Traces: winad
8:05 PM: Quarantining All Traces: popnav hijacker
8:05 PM: Quarantining All Traces: delfin
8:05 PM: Quarantining All Traces: trojan-keylogger lineage
8:05 PM: Quarantining All Traces: directrevenue-abetterinternet
8:05 PM: Quarantining All Traces: clearsearch
8:05 PM: Quarantining All Traces: websearch toolbar
8:05 PM: Quarantining All Traces: ie driver
8:05 PM: Quarantining All Traces: adlogix
8:05 PM: C:\WINDOWS\system32\vtutq.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\ssqrq.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\ssqro.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\ssqpp.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\pmnlk.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\pmkjg.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\pmkhg.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\3com_dmi\paafx.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mllmm.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mllji.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mljgg.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mljgf.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\ServicePackFiles\vddnds.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\ServicePackFiles\vddnds.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mllmm.dll is in use. It will be removed on reboot.
8:05 PM: C:\WINDOWS\system32\mljgf.dll is in use. It will be removed on reboot.
8:05 PM: virtumonde is in use. It will be removed on reboot.
8:05 PM: Quarantining All Traces: virtumonde
8:04 PM: Removal process initiated
8:01 PM: Traces Found: 94
8:01 PM: Full Sweep has completed. Elapsed time 00:32:06
8:01 PM: File Sweep Complete, Elapsed Time: 00:29:10
8:00 PM: Access to Hosts file blocked for C:\WINDOWS\EXPLORER.EXE
8:00 PM: Access to Hosts file blocked for C:\WINDOWS\EXPLORER.EXE
7:54 PM: Warning: Failed to access drive D:
7:54 PM: C:\Program Files\Netscape\Netscape 6\components\npclntax.xpt (ID = 146238)
7:54 PM: C:\WINDOWS\system32\bln02nqv.ini (ID = 75683)
7:54 PM: C:\WINDOWS\inf\Belt.inf (ID = 83154)
7:54 PM: C:\WINDOWS\inf\biini.inf (ID = 83199)
7:54 PM: C:\WINDOWS\sepsd.bin (ID = 75367)
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.fr2741 (ID = 87854)
7:54 PM: C:\WINDOWS\inf\alchem.inf (ID = 83109)
7:54 PM: Found Adware: directrevenue-abetterinternet
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.fr5597 (ID = 84923)
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.fr0BDA (ID = 84894)
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.frF5E0 (ID = 86338)
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.fr1090 (ID = 84894)
7:54 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.fr43D6 (ID = 87862)
7:52 PM: C:\Documents and Settings\Jim\Local Settings\Temp\temp.fr941C\MediaAccC.dll (ID = 90374)
7:52 PM: C:\WINDOWS\system32\gah95on6.ini (ID = 75741)
7:52 PM: Found Adware: shopathomeselect
7:48 PM: C:\Program Files\Mozilla Firefox\plugins\npclntax.dll (ID = 292514)
7:48 PM: C:\Program Files\Netscape\Netscape 6\Plugins\npclntax.dll (ID = 292514)
7:47 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\ZangoInstaller.exe (ID = 240743)
7:47 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\VVSNInst.exe (ID = 127141)
7:47 PM: Found Adware: whenu savenow
7:46 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\temp.frAD16 (ID = 84910)
7:40 PM: C:\WINDOWS\system32\exdl1.exe (ID = 50597)
7:40 PM: Found Adware: exact software
7:36 PM: C:\Documents and Settings\Cheryl\Local Settings\Temp\WSMIcon2.ico (ID = 58328)
7:36 PM: Found Adware: dialerplatform
7:32 PM: C:\WINDOWS\temp\ClrSch (ID = 2147486048)
7:32 PM: Found Adware: clearsearch
7:32 PM: C:\Documents and Settings\Cheryl\Application Data\{2CF0B992-5EEB-4143-99C0-5297EF71F444} (ID = 2147485986)
7:32 PM: C:\Documents and Settings\All Users\Application Data\Dpi (ID = 2147486159)
7:32 PM: C:\Documents and Settings\Cheryl\Start Menu\Programs\WhenU (3 subtraces) (ID = 2147486913)
7:32 PM: Found Adware: whenu
7:32 PM: Starting File Sweep
7:32 PM: Warning: Failed to access drive A:
7:32 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
7:32 PM: c:\documents and settings\matt\cookies\matt@overture[1].txt (ID = 3105)
7:32 PM: Found Spy Cookie: overture cookie
7:32 PM: c:\documents and settings\matt\cookies\matt@apmebf[1].txt (ID = 2229)
7:32 PM: Found Spy Cookie: apmebf cookie
7:32 PM: Starting Cookie Sweep
7:32 PM: Registry Sweep Complete, Elapsed Time:00:00:49
7:32 PM: HKU\S-1-5-21-982823239-2492322576-3337251515-1005\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
7:32 PM: HKU\S-1-5-21-982823239-2492322576-3337251515-1005\software\zango\ (ID = 147919)
7:32 PM: HKU\S-1-5-21-982823239-2492322576-3337251515-1005\software\sep\ (ID = 141642)
7:32 PM: HKU\S-1-5-21-982823239-2492322576-3337251515-1005\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
7:32 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1006\software\sep\ (ID = 141642)
7:32 PM: Found Adware: bho_sep
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1006\software\microsoft\windows\currentversion\run\ || clocksync (ID = 106141)
7:31 PM: Found Adware: clocksync
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1006\software\microsoft\windows\currentversion\updt\ (ID = 105189)
7:31 PM: Found Adware: browseraid
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\toolbar\ (ID = 646239)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {339bb23f-a864-48c0-a59f-29ea915965ec} (ID = 392934)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\microsoft\internet explorer\main\ || search bar (ID = 146561)
7:31 PM: Found Adware: websearch.com hijack
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\toolbar\ (ID = 146513)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\microsoft\internet explorer\toolbar\webbrowser\ || {339bb23f-a864-48c0-a59f-29ea915965ec} (ID = 146464)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\180solutions\ (ID = 135617)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\avenue media\ (ID = 128887)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1008\software\avenue media\ (ID = 128887)
7:31 PM: Found Adware: internetoptimizer
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1008\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
7:31 PM: Found Adware: sidesearch
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\zango\ (ID = 147919)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\mxtarget\ (ID = 145343)
7:31 PM: Found Adware: twain-tech
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\main\ || search bar (ID = 140818)
7:31 PM: Found Adware: searchbar.html hijack
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
7:31 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-500\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
7:31 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrq\ (ID = 1617260)
7:31 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk\ (ID = 1589784)
7:31 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\mllmm\ (ID = 1229701)
7:31 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\htproc\ (ID = 1109596)
7:31 PM: HKLM\software\classes\clsid\{827dc836-dd9f-4a68-a602-5812eb50a834}\progid\ (ID = 749172)
7:31 PM: HKLM\software\classes\clsid\{827dc836-dd9f-4a68-a602-5812eb50a834}\ (ID = 749166)
7:31 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{827dc836-dd9f-4a68-a602-5812eb50a834}\ (ID = 749160)
7:31 PM: HKCR\clsid\{827dc836-dd9f-4a68-a602-5812eb50a834}\ (ID = 749140)
7:31 PM: HKLM\software\classes\imside1egate.application.1\ (ID = 711277)
7:31 PM: HKCR\imside1egate.application.1\ (ID = 710985)
7:31 PM: Found Adware: 180search assistant/zango
7:31 PM: HKLM\software\microsoft\windows\currentversion\run\ || media access (ID = 147202)
7:31 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediaaccx.dll\ (ID = 147191)
7:31 PM: HKLM\software\microsoft\code store database\distribution units\{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}\ (ID = 147185)
7:31 PM: Found Adware: winad
7:31 PM: HKLM\system\currentcontrolset\enum\root\legacy_wintoolssvc\ (ID = 146518)
7:31 PM: Found Adware: websearch toolbar
7:31 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\iefeatures.ocx (ID = 136774)
7:31 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/iefeatures.ocx\ (ID = 136770)
7:31 PM: Found Adware: popnav hijacker
7:31 PM: HKLM\software\minigolf\ (ID = 135062)
7:31 PM: Found Adware: wild media - minigolf
7:31 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{120e090d-9136-4b78-8258-f0b44b4bd2ac}\ (ID = 128065)
7:31 PM: HKLM\software\maxspeed\ (ID = 127929)
7:31 PM: Found Adware: ie driver
7:31 PM: HKLM\software\dsi\ (ID = 124852)
7:31 PM: Found Adware: delfin
7:31 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{0b90aa1b-f649-44c3-9fd3-736c332cbbcf}\ (ID = 103015)
7:31 PM: HKLM\software\adlogix\ (ID = 102896)
7:31 PM: Found Adware: adlogix
7:31 PM: Starting Registry Sweep
7:31 PM: Memory Sweep Complete, Elapsed Time: 00:01:46
7:30 PM: Detected running threat: C:\WINDOWS\system32\vtutq.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\ssqrq.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\ssqro.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\ssqpp.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\pmnlk.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\pmkjg.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\pmkhg.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\3com_dmi\paafx.dll (ID = 486)
7:30 PM: Detected running threat: C:\WINDOWS\system32\mllmm.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\mllji.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\mljgg.dll (ID = 77)
7:30 PM: Detected running threat: C:\WINDOWS\system32\mljgf.dll (ID = 77)
7:29 PM: Detected running threat: C:\WINDOWS\ServicePackFiles\vddnds.dll (ID = 486)
7:29 PM: Detected running threat: C:\WINDOWS\ServicePackFiles\vddnds.dll (ID = 486)
7:29 PM: Starting Memory Sweep
7:29 PM: C:\WINDOWS\system32\mllmm.dll (ID = 1232682)
7:29 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\mllmm\ || dllname (ID = 1232682)
7:29 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\htproc\ || dllname (ID = 1187683)
7:29 PM: Found Trojan Horse: trojan-keylogger lineage
7:29 PM: C:\WINDOWS\system32\mljgf.dll (ID = 1142187)
7:29 PM: HKCR\clsid\{827dc836-dd9f-4a68-a602-5812eb50a834}\inprocserver32\ (ID = 1142187)
7:29 PM: Found Adware: virtumonde
7:29 PM: Sweep initiated using definitions version 755
7:29 PM: Spy Sweeper 5.0.5.1286 started
7:29 PM: | Start of Session, Wednesday, September 06, 2006 |
********
8:46 PM: | End of Session, Wednesday, September 06, 2006 |
8:46 PM: None
8:46 PM: Traces Found: 0
8:46 PM: Memory Sweep Complete, Elapsed Time: 00:00:57
8:46 PM: Sweep Canceled
8:45 PM: Starting Memory Sweep
8:45 PM: Sweep initiated using definitions version 755
8:45 PM: Spy Sweeper 5.0.5.1286 started
8:45 PM: | Start of Session, Wednesday, September 06, 2006 |
********
9:11 PM: Removal process completed. Elapsed time 00:01:01
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDB.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDC.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDC.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDC.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDC.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDC.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDD.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDD.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file "C:\WINDOWS\temp\SSTDE.tmp". Reason: The system cannot find the file specified
9:10 PM: Warning: Failed to delete profile shadow file ".log". Reason: The system cannot find the file specified
9:10 PM: Quarantining All Traces: 180search assistant/zango
9:10 PM: Quarantining All Traces: twain-tech
9:10 PM: Quarantining All Traces: searchbar.html hijack
9:10 PM: Quarantining All Traces: internetoptimizer
9:10 PM: Quarantining All Traces: sidesearch
9:10 PM: Quarantining All Traces: websearch toolbar
9:10 PM: Quarantining All Traces: ie driver
9:10 PM: Removal process initiated
9:09 PM: Traces Found: 10
9:09 PM: Full Sweep has completed. Elapsed time 00:22:56
9:09 PM: File Sweep Complete, Elapsed Time: 00:20:31
9:08 PM: Warning: Failed to access drive D:
8:49 PM: Starting File Sweep
8:49 PM: Warning: Failed to access drive A:
8:49 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:49 PM: Starting Cookie Sweep
8:49 PM: Registry Sweep Complete, Elapsed Time:00:00:44
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\toolbar\ (ID = 646239)
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1007\software\toolbar\ (ID = 146513)
8:48 PM: Found Adware: websearch toolbar
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1008\software\avenue media\ (ID = 128887)
8:48 PM: Found Adware: internetoptimizer
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1008\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
8:48 PM: Found Adware: sidesearch
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\zango\ (ID = 147919)
8:48 PM: Found Adware: 180search assistant/zango
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\mxtarget\ (ID = 145343)
8:48 PM: Found Adware: twain-tech
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\main\ || search bar (ID = 140818)
8:48 PM: Found Adware: searchbar.html hijack
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-1009\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
8:48 PM: HKU\WRSS_Profile_S-1-5-21-982823239-2492322576-3337251515-500\software\microsoft\internet explorer\extensions\cmdmapping\ || {120e090d-9136-4b78-8258-f0b44b4bd2ac} (ID = 127930)
8:48 PM: Found Adware: ie driver
8:48 PM: Starting Registry Sweep
8:48 PM: Memory Sweep Complete, Elapsed Time: 00:01:28
8:46 PM: Starting Memory Sweep
8:46 PM: Sweep initiated using definitions version 755
8:46 PM: Spy Sweeper 5.0.5.1286 started
8:46 PM: | Start of Session, Wednesday, September 06, 2006 |
********

——————————–
Logfile of HijackThis v1.99.1
Scan saved at 9:20:20 PM, on 9/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\SmileyDistrict\plugin.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] "C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" -autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Smiley District] "C:\Program Files\SmileyDistrict\plugin.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} (Java Plug-in 1.3.1) -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.3.1_02) -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\System32\hardsys.dll
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\SYSTEM32\nmvwylcx.dll
O20 - Winlogon Notify: vddnds - C:\WINDOWS\SERVIC~1\vddnds.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\System32\xmlcom.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Spy Sweeper has cleaned a lot of slime from your hard drive which has obviously improved things. With a little more work, hopefully you won't have to purchase a full license - if you like the program and want to upgrade, that's fine, it's having to that we want to avoid.

There is one item in your log that you may wish to keep, but it is a little slimy - SmileyDistrict.

I'll list all of the entries for the above in green, and you can include them in the fix if you wish.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

2) You will also need to know how to boot into Safe Mode.
Instructions can be found here.

3) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Run HJT and click on Open the Misc Tools section.
Click on delete a file on reboot…
Copy and paste the following into the "File name:" text box and then click Open:

C:\WINDOWS\System32\dnssrv.dll

When you are asked "Do you want to restart your computer now?", click NO.
Repeat these steps for the following file(s) and this time, when you reach the end, click OK:

C:\WINDOWS\System32\hardsys.dll
C:\WINDOWS\SYSTEM32\nmvwylcx.dll
C:\WINDOWS\System32\xmlcom.dll


Your PC MUST reboot to delete the files!

2) End Running Processes through Task Manager.
To do this:
Press and hold CTRL and Alt and tap Delete. This will open Task Manager.
If it is not selected, click on the 'Processes' Tab.
Scroll down and locate any/all of the following (if you cannot find one or more, don't worry):

plugin.exe

Click on each one you can find to highlight it, and then click on 'End Process'
There may be more than one entry in Task Manager for a particular file, so be sure to check.

2) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - C:\WINDOWS\system32\slqpsruq.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [Smiley District] "C:\Program Files\SmileyDistrict\plugin.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

O9 - Extra button: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)
O9 - Extra 'Tools' menuitem: Smiley District - {0418F3E3-C763-4e02-9EC5-F0AE13B54B0F} - C:\Program Files\SmileyDistrict\insmile.dll (file missing)


O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} (Java Plug-in 1.3.1) -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.3.1_02) -

O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\System32\hardsys.dll
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\SYSTEM32\nmvwylcx.dll
O20 - Winlogon Notify: vddnds - C:\WINDOWS\SERVIC~1\vddnds.dll (file missing)l
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\System32\xmlcom.dll


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

3) Boot into Safe Mode.

4) Remove any/all of the following files/folders that you can find:

Folders

C:\Program Files\SmileyDistrict

As an example:
To delete C:\WINDOWS\system32\foldertogo
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on foldertogo and from the menu that appears, click on 'Delete'


5) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

6) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

7) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

8) Boot into Normal Mode.

Will you then run HJT and post a new log AND a description of how your PC is running.
Hi again Noviciate!

I've followed all your instructions and my PC is running so much better! :thumbup:

There are no more automatic reboots, and all programs seem to run fine in Normal Mode. The machine even seems a little faster.

The only thing I noticed is after following all your instructions (deleting files, fixing checked HJT entries, etc.), the file C:\WINDOWS\System32\dnssrv.dll remains. I tried getting rid of it a few times but to no avail.

Here is my latest HJT log.

Thanks again,

Jim

—————————————–

Logfile of HijackThis v1.99.1
Scan saved at 9:01:44 PM, on 9/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - (no file)
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - (no file)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] "C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" -autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\
O20 - Winlogon Notify: vddnds - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
1) Download KillBox.zip by Option^Explicit from here and save it to your Desktop.
You will need to extract the file(s) from the zipped folder.

To do this: Right-click on the zipped folder and from the menu that appears, click on Extract All…
In the Extraction Wizard window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see the contents of the KillBox folder - close it for now.

2) You will need to disable SpywareGuard as it may interfere with this fix.
To do this:
Right click the 'SG' icon in the system tray (to the left of the clock)
Click on Options.
Under 'General Protection Options' uncheck the following:
'Enable Real-Time Scanning'
'Enable Download Protection'
'Enable Browser Hijack Protection'
Click on Save Settings
In the SpywareGuard confirmation window, click on OK.

3) You will need to disable Spybot's Tea Timer function as it may interfere with this fix. To do this:
Open Spybot S&D.
Click on Mode > Advanced Mode and click on Yes in the 'Warning' window.
In the left-hand pane, click on Tools > Resident
Uncheck the box to the left of Resident "Tea Timer" (Protection of over-all system settings) active
Close Spybot S&D.

4) You will need to disable SpySweeper's real-time protection as it may interfere with the fix. To do this:
Open SpySweeper and go to Options > Program Options.
Uncheck "load at windows startup".
Over to the left, click "Shields".
Uncheck "Home page shield" and "Automatically restore default without notifiction".

5) Reboot your PC.

6) IMPORTANT
Close all other open windows and programs because this will require a reboot.

Double click KillBox.exe to run it.
Click the radio button to the left of 'Delete on Reboot', then 'copy and paste' the following line into the 'Full Path of File to Delete' textbox:

C:\WINDOWS\System32\dnssrv.dll

Click on the red and white 'X' button.
First you will be asked to confirm that 'All listed Files will be Deleted on Next Reboot' - click on Yes.
Next you will be asked to 'Files will be Removed on Reboot, Do you want to reboot now?' - click Yes

If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message, just restart manually.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and then run missingfilesetup.exe - then try Killbox again.

7) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - (no file)
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} -

O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\
O20 - Winlogon Notify: vddnds - C:\WINDOWS\
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

Let me know how you get on.
Hi Noviciate!

In a word - STUBBORN! :scratch:

After following your instructions nothing seems to have changed this time. The PC is running the same, but the dnssrv.dll file is still there, and all the HJT entries you had me mark for deletion are still there.

Here is the latest log.

Thanks again,

Jim

—————————————–

Logfile of HijackThis v1.99.1
Scan saved at 9:05:50 AM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - (no file)
O2 - BHO: (no name) - {320dbc2a-a81c-435b-810e-e4d1fe1400da} - (no file)
O2 - BHO: (no name) - {392009DE-5DFB-4CCC-9F10-F59AE04178B4} - (no file)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
O2 - BHO: (no name) - {B3942E19-CD56-4701-B8D8-1973D9338F9C} - (no file)
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: (no name) - {E2FCA6B4-FDF7-4E5A-B9DD-F3A2155D1460} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] "C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" -autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O16 - DPF: {B3B8E157-3752-4070-AF84-89880D365362} -
O16 - DPF: {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: hardsys - C:\WINDOWS\
O20 - Winlogon Notify: nmvwylcx - C:\WINDOWS\
O20 - Winlogon Notify: vddnds - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: xmlcom - C:\WINDOWS\
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
On the occassions that this happens, its usually down to Spybot - try the following:
  • Download ResetTeaTimer.bat from here and save it to your Desktop.
    You will then need to extract the file.

    To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
    In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
    In the final window, click on Finish


    Close the folder, you will need it later.
  • Disable the real-time protection as before.
  • Reboot your PC.
  • Open the ResetTeaTimer folder and double click ResetTeaTimer.bat to run it.
  • Reboot your PC again.
  • Run the rest of the fix again.
  • Let me have a fresh HJT log and description of how the PC is behaving.
I think we're almost there Noviciate! :)

After running ResetTeaTimer.bat per your instructions, and running all of the previous fix (including KillBox.exe) it looks like all the HJT entries are now gone EXCEPT dnssrv.dll.

The PC is running very well - all of the original "noticeable" problems are gone. I'm just concerned as to what dnssrv.dll is doing (or might do).

Attached is the latest HJT log.

Thanks again,

Jim

————————————–

Logfile of HijackThis v1.99.1
Scan saved at 6:27:48 PM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\HijackThis\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.netscape.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Camera Detector] "C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" -autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.onlinebank.com
O15 - Trusted Zone: *.theremyreport.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.weather.com
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX28.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: dnssrv - C:\WINDOWS\System32\dnssrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Go to Jotti's and click on the Browse… button at the top and navigate to the following file and then click on Submit:

C:\WINDOWS\System32\dnssrv.dll

When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button at the top, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*
Hi Noviciate - Jotti's site was busy, so I used VirusTotal. These are very neat services I was not aware of before. Attached are the results from VirusTotal. It looks like Vundo/Virtumonde is still a problem. Thanks, Jim ————————————- STATUS: FINISHEDComplete scanning result of "dnssrv.dll", received in VirusTotal at 09.09.2006, 05:58:15 (CET). Antivirus Version Update Result AntiVir 7.1.1.16 09.08.2006 ADSPY/Virtumonde.368660 Authentium 4.93.8 09.09.2006 no virus found Avast 4.7.844.0 09.08.2006 Win32:Adware-gen. AVG 386 09.08.2006 Adware Generic.PBE BitDefender 7.2 09.09.2006 Adware.Virtumonde.BI CAT-QuickHeal 8.00 09.07.2006 no virus found ClamAV devel-20060426 09.09.2006 no virus found DrWeb 4.33 09.09.2006 no virus found eTrust-InoculateIT 23.72.120 09.08.2006 no virus found eTrust-Vet 30.3.3068 09.08.2006 no virus found Ewido 4.0 09.05.2006 Adware.Virtumonde Fortinet 2.77.0.0 09.09.2006 suspicious F-Prot 3.16f 09.09.2006 no virus found F-Prot4 4.2.1.29 09.08.2006 no virus found Ikarus 0.2.65.0 09.08.2006 no virus found Kaspersky 4.0.2.24 09.09.2006 not-a-virus:AdWare.Win32.Virtumonde.gen McAfee 4848 09.08.2006 Vundo Microsoft 1.1560 09.09.2006 no virus found NOD32v2 1.1746 09.08.2006 no virus found Norman 5.90.23 09.08.2006 W32/Virtumonde.KQ Panda 9.0.0.4 09.08.2006 Suspicious file Sophos 4.09.0 09.09.2006 no virus found Symantec 8.0 09.09.2006 no virus found TheHacker 5.9.8.208 09.08.2006 Adware/Virtumonde.gen UNA 1.83 09.08.2006 Adware.Virtumonde.BA37 VBA32 3.11.1 09.07.2006 no virus found VirusBuster 4.3.7:9 09.08.2006 Trojan.Vundo.B Aditional Information File size: 368660 bytes MD5: f8ebfd1d5e8f7ee308f73f4eb6ef273a SHA1: 770e5b481d1659e7c6234fd81dac1c7f7cc1a804 packers: embedded
Download a fresh copy of VundoFix, disable all the real-time protection and see if it will delete now. It's possible that this is a new file that the removal tool didn't recognize before. If it still doesn't work, we'll need to send a copy of the file off for inclusion.
Good morning Noviciate - I reloaded VundoFix, disabled realtime protection, and the new scan did not find any infected files. So I guess VundoFix does not search for dnssrv.dll. What next? Should I be using the PC? (I haven't been until it gets completely clean) What does Vundo do anyway? Thanks, Jim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI