This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

chinese popups

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i keep getting popups from chinese websites on Internet explorer even when im not using it, here is my hijackthis log


Logfile of HijackThis v1.99.1
Scan saved at 5:30:01 PM, on 8/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WF2K.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jielun.HAL04\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pansos.exe
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\RECYCLER\S-1-5-21-823518204-1060284298-839522115-1003\Dc9\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - (no file)
O2 - BHO: (no name) - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinFast_2K] C:\WINDOWS\system32\WF2K.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [1820173] C:\WINDOWS\system32\1820173.exe
O4 - HKLM\..\Run: [7546796] C:\WINDOWS\system32\7546796.exe
O4 - HKLM\..\Run: [SunServer] E:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SPYWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [qquf] C:\PROGRA~1\COMMON~1\qquf\qqufm.exe
O4 - HKCU\..\RunOnce: [CounterSpyCleaner] E:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunASCleaner.exe
O4 - Global Startup: 522097.lnk = C:\WINDOWS\system32\522097.exe
O4 - Global Startup: 538874.lnk = C:\WINDOWS\system32\538874.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Download using FlashGet - E:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4E71E6DD-FB37-4641-A96E-4456399A6DB0} - http://jade.bioware.com/codebaby/codebaby.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Hello and welcome to the forums

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware scan along with a new HijackThis log.
Here is the new HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 9:45:13 AM, on 15/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Jielun.HAL04\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pansos.exe
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\RECYCLER\S-1-5-21-823518204-1060284298-839522115-1003\Dc9\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - (no file)
O2 - BHO: (no name) - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinFast_2K] C:\WINDOWS\system32\WF2K.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [1820173] C:\WINDOWS\system32\1820173.exe
O4 - HKLM\..\Run: [7546796] C:\WINDOWS\system32\7546796.exe
O4 - HKLM\..\Run: [SunServer] E:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SPYWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [qquf] C:\PROGRA~1\COMMON~1\qquf\qqufm.exe
O4 - Global Startup: 522097.lnk = C:\WINDOWS\system32\522097.exe
O4 - Global Startup: 538874.lnk = C:\WINDOWS\system32\538874.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download using FlashGet - E:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4E71E6DD-FB37-4641-A96E-4456399A6DB0} - http://jade.bioware.com/codebaby/codebaby.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
And this is the Anti spyware scan report i had other cookies but i did not include them because they would exceed the post length and i didnt think would be important but if they are i can post them for you ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 9:43:35 AM 15/10/2006 + Scan result: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IHG9IX8V\137[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\All Users.WINDOWS\Application Data\clubmember\Cast\GGS\a2edb5c6cadb67fe5db776cd29937d3d_test.zip/0003.exe -> Downloader.QQHelper.ki : Cleaned with backup (quarantined). :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-137.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-138.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-139.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-140.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-440.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-441.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-442.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-443.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.10:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-444.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-143.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-144.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-59.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-60.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-61.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-62.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.11:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-64.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.12:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-145.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.12:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-146.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.13:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-58.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.16:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-142.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.16:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-67.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.16:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-68.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.17:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-147.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.17:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-148.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.18:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-65.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.18:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-66.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.27:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-69.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.28:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-70.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.35:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-71.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-72.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-73.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-31.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-32.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-33.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.6:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-141.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.6:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-439.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.79:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.79:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-4.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-133.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-134.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-136.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-438.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-51.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.7:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-52.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-2.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-3.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-5.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-6.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-8.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.81:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-7.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.81:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-9.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.86:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-10.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.86:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-11.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.86:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-12.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.86:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-13.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-23.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-24.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-25.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-26.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-27.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-28.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-14.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-15.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-19.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-20.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-21.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-22.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-53.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-54.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-55.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-56.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-16.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-17.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-18.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-29.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.95:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-127.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.99:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-128.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.9:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-30.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.9:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-57.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.9:C:\Documents and Settings\Jielun.HAL04\Application Data\Mozilla\Firefox\Profiles\tf3fawf9.default\cookies-63.txt -> TrackingCookie.2o7 : Cleaned.TrackingCookie.Hitbox : Cleaned. ::Report end
With AVG Anti-Spyware, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All (if all of the items in quarrantine need removing) then Remove Finally Can you reboot in Normal Mode and post a new HJT log please?
Here is the new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 5:21:52 PM, on 15/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WF2K.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jielun.HAL04\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet

Explorer provided by OptusNet
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32

\pansos.exe
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\RECYCLER\S-1-5-21

-823518204-1060284298-839522115-1003\Dc9\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - (no file)
O2 - BHO: (no name) - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32

\IEHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef

/Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinFast_2K] C:\WINDOWS\system32\WF2K.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32

\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [1820173] C:\WINDOWS\system32\1820173.exe
O4 - HKLM\..\Run: [7546796] C:\WINDOWS\system32\7546796.exe
O4 - HKLM\..\Run: [SunServer] E:\Program Files\Sunbelt

Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0

\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5

\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SPYWATCH] C:\Program

Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [qquf] C:\PROGRA~1\COMMON~1\qquf\qqufm.exe
O4 - Global Startup: 522097.lnk = C:\WINDOWS\system32\522097.exe
O4 - Global Startup: 538874.lnk = C:\WINDOWS\system32\538874.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0

\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10

\OSA.EXE
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - E:\Program Files\Kaspersky

Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Download using FlashGet - E:\Program

Files\FlashGet\jc_link.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program

Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4E71E6DD-FB37-4641-A96E-4456399A6DB0} -

http://jade.bioware.com/codebaby/codebaby.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -

http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

http://a840.g.akamai.net/7/840/537/2004061…ecall/xscan53.c

ab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)

- http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -

http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) -

http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1

\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe

Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program

Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program

Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program

Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
In Notepad, please turn Word Wrap Off.

* Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
heres the combofix.txt and HJT log

Jielun - 06-10-15 22:54:52.98 Service Pack 2
ComboFix 06.10.14.1 - Running from: "C:\Documents and Settings\Jielun.HAL04\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-09-15 to 2006-10-15 ))))))))))))))))))))))))))))))))))


2006-10-15 00:18 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-05 21:20 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2006-09-29 00:28 1,660,804 –a—— C:\WINDOWS\edodo_install.exe
2006-09-28 18:28 106,496 –a—— C:\WINDOWS\system32\IEHelper.dll
2006-09-22 18:40 102,400 –ahs—- C:\WINDOWS\system32\ACSs.dll
2006-09-19 18:59 0 –a—— C:\WINDOWS\temp1.exe
2006-09-18 22:41 12,973 –a—— C:\WINDOWS\system32\SCIA.dll
2006-09-17 21:30 72,704 –a—— C:\WINDOWS\system32\IE_Bar.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-15 22:31 ——– d——– C:\Program Files\Mozilla Firefox
2006-10-15 21:16 ——– d——– C:\Documents and Settings\Jielun.HAL04\Application Data\Azureus
2006-10-13 09:57 61072 –a—— C:\WINDOWS\system32\drivers\klick.sys
2006-10-13 09:57 59536 –a—— C:\WINDOWS\system32\drivers\klin.sys
2006-10-08 10:59 ——– d——– C:\Program Files\kuzhan
2006-10-05 23:39 ——– d——– C:\Documents and Settings\Jielun.HAL04\Application Data\Lavasoft
2006-10-05 23:29 ——– d——– C:\Program Files\Windows Media Player
2006-10-05 23:29 ——– d——– C:\Program Files\Internet Explorer
2006-10-03 23:43 ——– d——– C:\Program Files\Common Files\UPDATE2
2006-10-03 21:48 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-03 21:48 ——– d——– C:\Program Files\Common Files\Panda Software
2006-10-03 21:38 ——– d——– C:\Program Files\Trend Micro
2006-10-02 21:42 ——– d——– C:\Program Files\Enigma Software Group
2006-10-02 21:42 ——– d——– C:\Program Files\Common Files
2006-10-02 21:40 ——– d——– C:\Program Files\KooWo
2006-09-29 19:56 ——– d——– C:\Program Files\Winamp
2006-09-21 19:13 ——– d——– C:\Program Files\QuickTime
2006-09-21 19:10 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-09-21 13:53 ——– d——– C:\Program Files\Outlook Express
2006-09-19 19:46 28 –a—— C:\Program Files\autorun.inf
2006-09-14 01:25 94208 –ahs—- C:\WINDOWS\system32\sdmAgent22.dll
2006-09-14 01:25 94208 –ahs—- C:\WINDOWS\system32\sdmAgent20.dll
2006-09-14 00:36 90112 –a—— C:\WINDOWS\system32\SafeHelper12.dll
2006-09-13 15:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-10 02:51 94208 –ahs—- C:\WINDOWS\system32\Nwsapagent.dll
2006-08-26 01:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-21 22:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 19:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-21 19:14 128896 ——— C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-19 14:31 ——– d——– C:\Program Files\Java
2006-08-16 21:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll
2006-08-16 19:37 225664 –a—— C:\WINDOWS\system32\drivers\tcpip6.sys
2006-08-15 17:53 38856 –a—— C:\Documents and Settings\Jielun.HAL04\Application Data\GDIPFONTCACHEV1.DAT
2006-07-27 23:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-21 18:24 72704 –a—— C:\WINDOWS\system32\hlink.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SPYWATCH"="C:\\Program Files\\BulletProofSoft.com\\SpywareRemover\\SpyWatch.exe /STARTUP"
"qquf"="C:\\PROGRA~1\\COMMON~1\\qquf\\qqufm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMJPMIG8.1"="C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"SoundMan"="SOUNDMAN.EXE"
"WinFast_2K"="C:\\WINDOWS\\system32\\WF2K.EXE"
"NeroCheck"="C:\\WINDOWS\\System32\\NeroCheck.exe"
"D-Link AirPlus G"="C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"
"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"E:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"1820173"="C:\\WINDOWS\\system32\\1820173.exe"
"7546796"="C:\\WINDOWS\\system32\\7546796.exe"
"SunServer"="E:\\Program Files\\Sunbelt Software\\CounterSpy\\Consumer\\sunserver.exe"
"kis"="\"E:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 6.0\\avp.exe\""
@=""
"!AVG Anti-Spyware"="\"E:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,3e,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"fairydom"="{5839511e-ec1b-4f91-ace3-fb88e52f5239}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"DTService"="rundll32.exe C:\\WINDOWS\\system32\\soundmix.dll,Load"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Win_Update_Program.job

Completion time: 06-10-15 22:56:41.45
C:\ComboFix.txt … 06-10-15 22:56




Logfile of HijackThis v1.99.1
Scan saved at 10:59:25 PM, on 15/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WF2K.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\rundll32.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Jielun.HAL04\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pansos.exe
O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\RECYCLER\S-1-5-21-823518204-1060284298-839522115-1003\Dc9\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - (no file)
O2 - BHO: (no name) - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: ÐÅÏ¢¼ìË÷ - {CE7C3CF0-98A8-474D-B2B5-1ED7E2E3B004} - C:\WINDOWS\system32\IEHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinFast_2K] C:\WINDOWS\system32\WF2K.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [1820173] C:\WINDOWS\system32\1820173.exe
O4 - HKLM\..\Run: [7546796] C:\WINDOWS\system32\7546796.exe
O4 - HKLM\..\Run: [SunServer] E:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SPYWATCH] C:\Program Files\BulletProofSoft.com\SpywareRemover\SpyWatch.exe /STARTUP
O4 - HKCU\..\Run: [qquf] C:\PROGRA~1\COMMON~1\qquf\qqufm.exe
O4 - Global Startup: 522097.lnk = C:\WINDOWS\system32\522097.exe
O4 - Global Startup: 538874.lnk = C:\WINDOWS\system32\538874.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Download using FlashGet - E:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4E71E6DD-FB37-4641-A96E-4456399A6DB0} - http://jade.bioware.com/codebaby/codebaby.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Download Pocket Killbox
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Then double-click on the killbox.exe program.


Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.

Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.


When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.

C:\WINDOWS\system32\ACSs.dll
C:\WINDOWS\temp1.exe
C:\WINDOWS\system32\SCIA.dll
C:\WINDOWS\system32\IE_Bar.exe
C:\Program Files\kuzhan\kuzhan.dll
C:\WINDOWS\system32\sdmAgent22.dll
C:\WINDOWS\system32\sdmAgent20.dll
C:\WINDOWS\system32\SafeHelper12.dll
C:\WINDOWS\system32\Nwsapagent.dll
C:\WINDOWS\system32\522097.exe
C:\WINDOWS\system32\538874.exe
C:\WINDOWS\system32\1820173.exe
C:\WINDOWS\system32\7546796.exe


Return to Killbox, go to the File menu and select Paste from Clipboard.


Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually

"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI