This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Several Problems (I think)

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I posted this over at another forum, but have had no help, so I'll just copy and paste it here.

Hello folks, new to your forum here. Well it seems as if I picked up that Vundo.Trojan. I've run McAfee, AdAWare, and Spybot S&D, and they all come back clean now, but there still seems to be something wrong, as my browsing is a tad slower than it was in thepast few days, and I also noticed something odd in my Hijack This log.
"O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll"

Now I did a quick Google on "ddayxxu.dll", and I got -nothing- back on it, which seems odd to me. I figured if it was legitimate or not, I would have gotten SOMETHING back on it, but I get no results.

There's also this entry that I am not too sure what it is.
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - "http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab"

I wasn't sure if I should just cut and paste the whole log, or if I needed to attach the log itself or what. I'm also a tad hesitant to attach it, as I don't want to include any 'sensitive' data. But if need be, I shall post both my log and startup log file, as I would like someone experienced to tell me if my system is in okay shape. Thanks very much for your time. [/end of pasted post]

Now I have also discovered something else. Occasionally, I have something called "wmiprvse.exe" running, and it says it's a network service. Now I've read that it's a normal function of Windows and it's safe. BUT…I have ALSO read, and I quote…

"Normally, wmipvrse.exe is a valid windows/system32 file, and with SP1, it stays in the WDEM directory at about 199KB, and has the SP1 distribution date of 8/29/2002. But when you get the virus, you will find another file, of 38KB size in the Windows/Prefetch directory, with the same name, but a more recent date. Deleting that file and rebooting seems to fix the problem, the original MS file seems unharmed."

Well, I DO have one in my Preftech folder, with a date of 10/05/2006. Something else odd, I had deleted it and when it was in the Recyle Bin it was 88.0 KB. Not being sure if I SHOULD have deleted it, I restored it, and it's back in the Preftech folder, but now the size is 85.2 kb.

Also, while that IS running, (WMIPRVSE.EXE) my Yahoo! Messenger won't connect. I launch it and it SAYS it's running in Task Manager, but nothing happens. It doesn't even attempt to open. One last thing about this, I've read that it's simialr to 'svchost.exe', and is a critical function and ending it could adversely effect my system. Well when I kill it via the Task Manager, the only thing that seems to happen is I can once again connect on Yahoo!.

Well, I'll brave it and just go ahead and post my full log for you guys.

Logfile of HijackThis v1.99.1
Scan saved at 11:24:22 PM, on 10/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\sony\giga pocket\usbsircs.exe
D:\Logitech\SetPoint\KEM.exe
D:\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\mcafee\msc\mcupdui.exe
D:\Yahoo!\Messenger\YPager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\unzipped\hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Giga Pocket Remocon Driver.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\KEM.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/support/pops/mdldetect/VaioInfo.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\giga pocket\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (Application) (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Here is my Startup List

StartupList report, 10/5/2006, 11:25:37 PM
StartupList version: 1.52.2
Started from : C:\unzipped\hijackthis\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\sony\giga pocket\usbsircs.exe
D:\Logitech\SetPoint\KEM.exe
D:\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\mcafee\msc\mcupdui.exe
D:\Yahoo!\Messenger\YPager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\unzipped\hijackthis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = ?
Giga Pocket Remocon Driver.lnk = ?
Logitech Desktop Messenger.lnk.disabled
Logitech SetPoint.lnk = D:\Logitech\SetPoint\KEM.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ezShieldProtector for Px = C:\WINDOWS\System32\ezSP_Px.exe
UpdReg = C:\WINDOWS\Updreg.exe
HPDJ Taskbar Utility = C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
HTpatch = C:\WINDOWS\htpatch.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
Logitech Hardware Abstraction Layer = KHALMNPR.EXE
VSOCheckTask = "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
VirusScan Online = C:\Program Files\McAfee.com\VSO\mcvsshld.exe
OASClnt = C:\Program Files\McAfee.com\VSO\oasclnt.exe
CleanUp = C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=c:\windows\system32\ddayxxu.dll

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

McDefragTask.job
McQcTask.job
Registration reminder 2.job

————————————————–

Enumerating Download Program Files:

[ActiveGS.cab]
CODEBASE = http://www.virtualapple.com/activegs.cab
OSD = C:\WINDOWS\Downloaded Program Files\OSDA56.OSD

[{0000000A-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/d/4…0367/wmavax.CAB

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[VaioInfo.CMClass]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\VaioInfo.dll
CODEBASE = http://esupport.sony.com/support/pops/mdldetect/VaioInfo.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[Yahoo! Audio Conferencing]
InProcServer32 = C:\WINDOWS\DOWNLO~1\yacscom.dll
CODEBASE = http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab

[YInstStarter Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[McAfee.com Operating System Class]
InProcServer32 = C:\WINDOWS\system32\mcinsctl.dll
CODEBASE = http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab

[McAfee Virtual Technician Control Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MVT.dll
CODEBASE = http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab

[Yahoo! Webcam Upload Wrapper]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yuplapp.dll
CODEBASE = http://chat.yahoo.com/cab/yuplapp.cab

[DwnldGroupMgr Class]
InProcServer32 = C:\WINDOWS\system32\mcgdmgr.dll
CODEBASE = http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

[Virtools WebPlayer Class]
InProcServer32 = C:\Program Files\Virtools Web Player 3.5\WebPlayer.ocx
CODEBASE = http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe

[{D719897A-B07A-4C0C-AEA9-9B663A28DFCB}]
CODEBASE = http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab

[CTAdjust Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\clearadjust.dll
CODEBASE = http://download.microsoft.com/download/7/E…04/clearadj.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\shell32.dll
CDBurn: C:\WINDOWS\system32\shell32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 8,661 bytes
Report generated in 0.047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


Now I ran a startup log earlier, and it reported this was in it.
"C:\WINDOWS\System32\wuauclt.exe"
But it doesn't seem to be there now. Which as I understand it, "wuauclt.exe" has to do with Windows Updates, but I have them disabled, so why it EVER runs is beyond me.

Well, I think I covered it all, thanks a lot for your time in reading this ungodly-long post. :)
wired :D

Welcome to Tom Coyote

Lets do a couple of things…

Run this free online virus scanner from Panda, it won't clean anything but I need to see the report.
Panda ActiveScan <—-Accept default settings



Then go to where you have HJT currently installed and right click on the HJT Icon and rename it to Analyze.exe and post a new log along with the log from Panda.

wired :D

Welcome to Tom Coyote

Lets do a couple of things…

Run this free online virus scanner from Panda, it won't clean anything but I need to see the report.
Panda ActiveScan <—-Accept default settings



Then go to where you have HJT currently installed and right click on the HJT Icon and rename it to Analyze.exe and post a new log along with the log from Panda.

I don't have HJT installed, per se. It was in a .zip and I simply unzipped it. Will that be a problem? I'm running Panda now. Thanks for the reply.

That's odd. I got a PUP warning from McAfee while running that, and it killed my IE. I'll try again. *sigh*
Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure WordWrap is unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use the [external image: Posted Image] Button and not the New Topic Button
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Sorry for the delayed reply, been doing some research.
HJT Log
*********
Logfile of HijackThis v1.99.1
Scan saved at 8:35:34 PM, on 10/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\sony\giga pocket\usbsircs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Logitech\SetPoint\KEM.exe
D:\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Giga Pocket Remocon Driver.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\KEM.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/support/pops/mdldetect/VaioInfo.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\giga pocket\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (Application) (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Here's the PandaScan Log.
*****************

Incident Status Location

Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Guest\Cookies\guest@atwola[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\y8n3wm13.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\y8n3wm13.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\y8n3wm13.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\John\Cookies\john@112.2o7[2].txt
Spyware:Cookie/66.246.209 Not disinfected C:\Documents and Settings\John\Cookies\john@66.246.209[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\John\Cookies\[removed][2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\John\Cookies\john@adultfriendfinder[2].txt
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\John\Cookies\john@apmebf[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\John\Cookies\john@atwola[2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\John\Cookies\john@banner[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\John\Cookies\john@belnk[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\John\Cookies\john@burstnet[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\John\Cookies\[removed][2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\John\Cookies\john@ccbill[2].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\John\Cookies\john@cdfreaks[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\John\Cookies\john@cgi-bin[6].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\John\Cookies\john@com[1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\John\Cookies\john@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\John\Cookies\[removed][2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\John\Cookies\john@drivecleaner[2].txt
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\John\Cookies\john@entrepreneur[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\John\Cookies\john@go[3].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\John\Cookies\[removed][2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\John\Cookies\john@toplist[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\John\Cookies\john@webpower[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\John\Cookies\[removed][2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\John\Cookies\[removed][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\John\Cookies\john@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\John\Cookies\john@yadro[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Mamie\Cookies\mamie@atwola[1].txt
Adware:Adware/Maxifiles Not disinfected C:\unzipped\hijackthis\backups\backup-20061007-221520-791.dll
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\icon_mediamotor.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\system32\ts_mediamotor.exe
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom.zip[[removed][1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom1.zip[john@advertising[1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom10.zip[[removed][1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom11.zip[john@advertising[1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom2.zip[[removed][1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom3.zip[john@advertising[1].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom4.zip[[removed][2].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom5.zip[john@advertising[2].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom6.zip[[removed][2].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom7.zip[john@advertising[2].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom8.zip[[removed][2].txt]
Spyware:Cookie/Advertising Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom9.zip[john@advertising[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc.zip[john@atdmt[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc1.zip[john@atdmt[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc2.zip[john@atdmt[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc3.zip[john@atdmt[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc4.zip[john@atdmt[2].txt]
Spyware:Cookie/Atlas DMT Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc5.zip[john@atdmt[2].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast.zip[john@bfast[1].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast1.zip[john@bfast[2].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast2.zip[john@bfast[2].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast3.zip[john@bfast[2].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast4.zip[john@bfast[2].txt]
Spyware:Cookie/Bfast Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\BFast5.zip[john@bfast[1].txt]
Spyware:Cookie/Coremetrics Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\CoreMetrics.zip[[removed][2].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick.zip[john@doubleclick[1].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick1.zip[john@doubleclick[1].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick2.zip[john@doubleclick[1].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick3.zip[john@doubleclick[2].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick4.zip[john@doubleclick[2].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick5.zip[john@doubleclick[1].txt]
Spyware:Cookie/Doubleclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\DoubleClick6.zip[john@doubleclick[2].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick.zip[john@fastclick[2].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick1.zip[john@fastclick[3].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick2.zip[john@fastclick[1].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick3.zip[john@fastclick[3].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick4.zip[john@fastclick[2].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick5.zip[john@fastclick[2].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick6.zip[john@fastclick[1].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick7.zip[john@fastclick[1].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick8.zip[john@fastclick[3].txt]
Spyware:Cookie/FastClick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\FastClick9.zip[john@fastclick[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox1.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox11.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox12.zip[[removed][2].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox14.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox15.zip[[removed][2].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox18.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox19.zip[[removed][2].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox2.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox21.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox22.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox23.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox3.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox4.zip[[removed][2].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox5.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox6.zip[john@hitbox[2].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitBox8.zip[john@hitbox[1].txt]
Spyware:Cookie/Hitslink Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\HitsLink.zip[[removed][1].txt]
Spyware:Cookie/Hitbox Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer11.zip[john@hitbox[1].txt]
Spyware:Cookie/Mysearch Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer11.zip[john@mysearch[2].txt]
Spyware:Cookie/Tribalfusion Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer11.zip[john@tribalfusion[1].txt]
Spyware:Cookie/Adserver Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer11.zip[[removed][1].txt]
Spyware:Cookie/2o7 Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@2o7[1].txt]
Spyware:Cookie/bravenetA Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@bravenet[2].txt]
Spyware:Cookie/Ccbill Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@ccbill[2].txt]
Spyware:Cookie/CentrPort Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@centrport[2].txt]
Spyware:Cookie/Cgi-bin Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@cgi-bin[2].txt]
Spyware:Cookie/Com.com Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@com[2].txt]
Spyware:Cookie/Powerscan Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@gammae[1].txt]
Spyware:Cookie/Gator Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@gator[2].txt]
Spyware:Cookie/HotLog Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@hotlog[1].txt]
Spyware:Cookie/LinkExchange Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@linkexchange[1].txt]
Spyware:Cookie/Mysearch Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@mysearch[1].txt]
Spyware:Cookie/Overture Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@overture[2].txt]
Spyware:Cookie/PayCounter Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@paycounter[1].txt]
Spyware:Cookie/Mircx Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[[removed][1].txt]
Spyware:Cookie/QuestionMarket Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@questionmarket[1].txt]
Spyware:Cookie/RealMedia Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@realmedia[1].txt]
Spyware:Cookie/SpyLog Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@spylog[1].txt]
Spyware:Cookie/WebtrendsLive Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[[removed][1].txt]
Spyware:Cookie/Mammamediasolutions Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@targetnet[2].txt]
Spyware:Cookie/Toplist Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@toplist[1].txt]
Spyware:Cookie/Traffic Marketplace Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@trafficmp[1].txt]
Spyware:Cookie/WebPower Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@webpower[2].txt]
Spyware:Cookie/X10 Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@x10[2].txt]
Spyware:Cookie/XXXCounter Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[john@xxxcounter[2].txt]
Spyware:Cookie/Adserver Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer14.zip[[removed][1].txt]
Spyware:Cookie/2o7 Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@2o7[2].txt]
Spyware:Cookie/Bilbo.counted Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[[removed][2].txt]
Spyware:Cookie/Bluestreak Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@bluestreak[2].txt]
Spyware:Cookie/bravenetA Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@bravenet[2].txt]
Spyware:Cookie/CentrPort Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@centrport[1].txt]
Spyware:Cookie/Cgi-bin Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@cgi-bin[1].txt]
Spyware:Cookie/Comclick Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[[removed][2].txt]
Spyware:Cookie/Gator Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@gator[1].txt]
Spyware:Cookie/Go Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@go[1].txt]
Spyware:Cookie/Mysearch Not disinfected D:\Spybot - Search & Destroy 1.1\Recovery\InternetExplorer18.zip[john@mysearch[1].txt]
Wired :D

If your not receiving help in another fourm, then proceed with the fix, all the forums are swamped and we really can't afford two people helping you with the same problem.


Please start by downloading VirtumondoBegone to your desktop.
  • Reboot your computer into Safemode
  • Go to START/ SHUT OF YOUR COMPUTER/ RESTART
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
  • Then press the ENTER KEY ON YOUR KEYBOARD
  • Doubleclick on VirtumundoBeGone.exe and follow the instructions.
  • Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.
  • When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply along with a new HJT log.
VBG Log..
*************

[10/08/2006, 21:29:35] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\John\Desktop\VirtumundoBeGone.exe" )
[10/08/2006, 21:29:41] - Detected System Information:
[10/08/2006, 21:29:41] - Windows Version: 5.1.2600, Service Pack 1
[10/08/2006, 21:29:41] - Current Username: John (Admin)
[10/08/2006, 21:29:41] - Windows is in SAFE mode with Networking.
[10/08/2006, 21:29:41] - Searching for Browser Helper Objects:
[10/08/2006, 21:29:41] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[10/08/2006, 21:29:41] - BHO 2: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
[10/08/2006, 21:29:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:41] - Checking for HKLM\…\Winlogon\Notify\mnyside
[10/08/2006, 21:29:41] - Key not found: HKLM\…\Winlogon\Notify\mnyside, continuing.
[10/08/2006, 21:29:41] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[10/08/2006, 21:29:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:41] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[10/08/2006, 21:29:41] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[10/08/2006, 21:29:41] - BHO 4: {B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859} ()
[10/08/2006, 21:29:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:41] - Checking for HKLM\…\Winlogon\Notify\awtss
[10/08/2006, 21:29:41] - Found: HKLM\…\Winlogon\Notify\awtss - This is probably Virtumundo.
[10/08/2006, 21:29:41] - Assigning {B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859} MSEvents Object
[10/08/2006, 21:29:41] - BHO list has been changed! Starting over…
[10/08/2006, 21:29:41] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[10/08/2006, 21:29:41] - BHO 2: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
[10/08/2006, 21:29:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:41] - Checking for HKLM\…\Winlogon\Notify\mnyside
[10/08/2006, 21:29:41] - Key not found: HKLM\…\Winlogon\Notify\mnyside, continuing.
[10/08/2006, 21:29:41] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[10/08/2006, 21:29:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:41] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[10/08/2006, 21:29:41] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[10/08/2006, 21:29:41] - BHO 4: {B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859} (MSEvents Object)
[10/08/2006, 21:29:41] - ALERT: Found MSEvents Object!
[10/08/2006, 21:29:41] - Finished Searching Browser Helper Objects
[10/08/2006, 21:29:41] - *** Detected MSEvents Object
[10/08/2006, 21:29:41] - Trying to remove MSEvents Object…
[10/08/2006, 21:29:42] - Terminating Process: IEXPLORE.EXE
[10/08/2006, 21:29:42] - Terminating Process: RUNDLL32.EXE
[10/08/2006, 21:29:42] - Disabling Automatic Shell Restart
[10/08/2006, 21:29:42] - Terminating Process: EXPLORER.EXE
[10/08/2006, 21:29:42] - Suspending the NT Session Manager System Service
[10/08/2006, 21:29:43] - Terminating Windows NT Logon/Logoff Manager
[10/08/2006, 21:29:43] - Re-enabling Automatic Shell Restart
[10/08/2006, 21:29:43] - File to disable: C:\WINDOWS\System32\awtss.dll
[10/08/2006, 21:29:43] - Renaming C:\WINDOWS\System32\awtss.dll -> C:\WINDOWS\System32\awtss.dll.vir
[10/08/2006, 21:29:43] - File successfully renamed!
[10/08/2006, 21:29:43] - Removing HKLM\…\Browser Helper Objects\{B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859}
[10/08/2006, 21:29:43] - Removing HKCR\CLSID\{B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859}
[10/08/2006, 21:29:43] - Adding Kill Bit for ActiveX for GUID: {B89DE1CB-A3B3-41BE-9AE9-5CB5A52D0859}
[10/08/2006, 21:29:43] - Deleting ATLEvents/MSEvents Registry entries
[10/08/2006, 21:29:43] - Removing HKLM\…\Winlogon\Notify\awtss
[10/08/2006, 21:29:43] - Searching for Browser Helper Objects:
[10/08/2006, 21:29:43] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[10/08/2006, 21:29:43] - BHO 2: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
[10/08/2006, 21:29:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:43] - Checking for HKLM\…\Winlogon\Notify\mnyside
[10/08/2006, 21:29:43] - Key not found: HKLM\…\Winlogon\Notify\mnyside, continuing.
[10/08/2006, 21:29:43] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[10/08/2006, 21:29:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:29:43] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[10/08/2006, 21:29:43] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[10/08/2006, 21:29:43] - Finished Searching Browser Helper Objects
[10/08/2006, 21:29:43] - Finishing up…
[10/08/2006, 21:29:43] - A restart is needed.
[10/08/2006, 21:30:55] - Attempting to Restart via STOP error (Blue Screen!)

[10/08/2006, 21:33:12] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\John\Desktop\VirtumundoBeGone.exe" )
[10/08/2006, 21:33:14] - Detected System Information:
[10/08/2006, 21:33:14] - Windows Version: 5.1.2600, Service Pack 1
[10/08/2006, 21:33:14] - Current Username: John (Admin)
[10/08/2006, 21:33:14] - Windows is in SAFE mode with Networking.
[10/08/2006, 21:33:14] - Searching for Browser Helper Objects:
[10/08/2006, 21:33:14] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[10/08/2006, 21:33:14] - BHO 2: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
[10/08/2006, 21:33:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:33:14] - Checking for HKLM\…\Winlogon\Notify\mnyside
[10/08/2006, 21:33:14] - Key not found: HKLM\…\Winlogon\Notify\mnyside, continuing.
[10/08/2006, 21:33:14] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[10/08/2006, 21:33:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:33:14] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[10/08/2006, 21:33:14] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[10/08/2006, 21:33:14] - Finished Searching Browser Helper Objects
[10/08/2006, 21:33:14] - Finishing up…
[10/08/2006, 21:33:14] - Nothing found! Exiting…

[10/08/2006, 21:33:41] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\John\Desktop\VirtumundoBeGone.exe" )
[10/08/2006, 21:33:42] - Detected System Information:
[10/08/2006, 21:33:42] - Windows Version: 5.1.2600, Service Pack 1
[10/08/2006, 21:33:42] - Current Username: John (Admin)
[10/08/2006, 21:33:42] - Windows is in SAFE mode with Networking.
[10/08/2006, 21:33:42] - Searching for Browser Helper Objects:
[10/08/2006, 21:33:42] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[10/08/2006, 21:33:42] - BHO 2: {243B17DE-77C7-46BF-B94B-0B5F309A0E64} ()
[10/08/2006, 21:33:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:33:42] - Checking for HKLM\…\Winlogon\Notify\mnyside
[10/08/2006, 21:33:42] - Key not found: HKLM\…\Winlogon\Notify\mnyside, continuing.
[10/08/2006, 21:33:42] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[10/08/2006, 21:33:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/08/2006, 21:33:42] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[10/08/2006, 21:33:42] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[10/08/2006, 21:33:42] - Finished Searching Browser Helper Objects
[10/08/2006, 21:33:42] - Finishing up…
[10/08/2006, 21:33:42] - Nothing found! Exiting…

HJT Log..
********
Logfile of HijackThis v1.99.1
Scan saved at 9:37:54 PM, on 10/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\avgcc.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\sony\giga pocket\usbsircs.exe
D:\Logitech\SetPoint\KEM.exe
D:\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1.4\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Giga Pocket Remocon Driver.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\KEM.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/support/pops/mdldetect/VaioInfo.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\giga pocket\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (Application) (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Wired :D

Open HJT Scan Only, close your browser and all open windows, check these entries and click on Fix Checked

O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe

O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll





Download Pocket Killbox to your desktop, unzip it to a folder that you can find

Highlight the file with the complete path inside the Quote Box and press Ctrl C on your keyboard.

c:\windows\system32\ddayxxu.dll

  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure Single File is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes



Run this system cleaner.

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.


Go to where you have HJT currently , right click on the HJT Icon and rename it to Analyze.exe and post a new log. There are some malware programs that are being written to hide from HJT.

Wired :D

Open HJT Scan Only, close your browser and all open windows, check these entries and click on Fix Checked

O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe

O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll





Download Pocket Killbox to your desktop, unzip it to a folder that you can find

Highlight the file with the complete path inside the Quote Box and press Ctrl C on your keyboard.

c:\windows\system32\ddayxxu.dll

  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure Single File is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes
Run this system cleaner.

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Go to where you have HJT currently , right click on the HJT Icon and rename it to Analyze.exe and post a new log. There are some malware programs that are being written to hide from HJT.

Okay, after I clicked "fix checked" I got this message from HJT.
***************
An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: c:\windows\system32\ddayxxu.dll)
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2800.1106
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
***************************
So then I ran Killbox, and clicking on "paste from clipboard" didn't work, so I just pasted it in manually. All the other steps went accordingly, but I got this from Killbox..
[external image: Posted Image]
I am not familiar with that program, so I didn't know if that was normal or not. I also ran ATF with no problems. Here's the new HJT log.
****************
Logfile of HijackThis v1.99.1
Scan saved at 10:13:40 PM, on 10/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\htpatch.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\avgcc.exe
C:\Program Files\sony\giga pocket\usbsircs.exe
D:\Logitech\SetPoint\KEM.exe
D:\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\PackethSvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\avgamsvr.exe
C:\PROGRA~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\giga pocket\GPVSvr.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\Analyze.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1.4\SDHelper.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\avgcc.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Giga Pocket Remocon Driver.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk.disabled
O4 - Global Startup: Logitech SetPoint.lnk = D:\Logitech\SetPoint\KEM.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/support/pops/mdldetect/VaioInfo.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/bin/3,0,1,0/mvt.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: VAIO Media Video Server (Application) (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\giga pocket\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (Application) (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
****************
Any idea what these entries might be?
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
Good Morning wired :D

This was in the Vundobegone log, its a Vundo file ( Vundo is nasty ) The file we removed was part of that also, although it appears you did not have the full blown infection.

Renaming C:\WINDOWS\System32\awtss.dll -> C:\WINDOWS\System32\awtss.dll.vir



Those 016 entries are related to something you downloaded at the Apple site. You can remove any 016 entry from your HJT log, when you revisit the site it will just prompt you to download it again. The 016 entries you have all seem legit, so your call to remove them.


That bad entry is gone :thumbup: Sometimes Killbox chokes on a file. The rest of your log looks fine :thumbup:


The only suggestion I have is that it appears that you are running two anti virus programs, with AV, More is not better They will use up vast amounts of system resources and at time conflict with one another. Your call but you should uninstall one program.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.

System Restore <– Do this first to prevent reinfecting yourself.
TonyKlein CastleCops
Grinler BleepingComputer
Geeks To Go



Any other issues malware related, post back. Glad to be able to help you.

Ken :D
Well, thanks a lot for your help, Ken. My PC is normally pretty clean, but a site I visit frequently has a nasty pop-up. Not even a "bad site", so to speak, but another forum. This particluar pop-up slammed my McAfee, knocking it down, and I wasn't even aware of it. And yeah, I'm going to uninstall AVG, I just wanted to see what it came up with that the other programs might not have gotten. So once, again, thanks for the help! Ciao!
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI