This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

baseline

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:38:45 PM, on 10/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\PRINTV~1\pvmodule.exe
C:\windows\system32\okdsregr.exe
C:\Program Files\QuickTime\qttask.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\kybrdff_e35.exe
C:\nwnmff_e35.exe
C:\WINDOWS\v1201.exe
C:\WINDOWS\gkywyddA.exe
C:\WINDOWS\system32\twinlpes.exe
C:\WINDOWS\win3208432-1338768.exe
C:\WINDOWS\cfg32.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\cmd\command.exe
C:\PROGRA~1\COMMON~1\SCURIT~1\wowexec.exe
C:\WINDOWS\system32\S?mantec\msiexec.exe
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\gkywydd.exe
C:\Program Files\Batty2\Batty2.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\system32\wscntfy.exe
c:\kybrdff_e36.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\PSCastor\PSCastor.exe
c:\dfndrff_e36.exe
C:\Program Files\Common Files\{B03403D0-04B2-1033-0226-020504130001}\Update.exe
c:\nwnmff_e36.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
R3 - URLSearchHook: (no name) - {5ED8E64F-7E83-242B-D3B8-2EA7795FE3C2} - C:\WINDOWS\system32\rqvh.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKLM\..\Run: [{40-03-3D-D0-ZN}] C:\windows\system32\okdsregr.exe ELT001
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e36.exe
O4 - HKLM\..\Run: [keyboard] c:\\kybrdff_e36.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_e36.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [gkywyddA] C:\WINDOWS\gkywyddA.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinlpem.exe ELT001
O4 - HKLM\..\Run: [win3208432-1338768] C:\WINDOWS\win3208432-1338768.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - HKCU\..\Run: [Tart] "C:\PROGRA~1\COMMON~1\SCURIT~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Vqeez] C:\WINDOWS\system32\S?mantec\msiexec.exe
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinlpem.exe
O4 - Global Startup: svchost.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O20 - AppInit_DLLs: BattyRun2.dll
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\c800lidm180a.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\cmd\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\gkywydd.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Howard Anderson - Tue 10/24/2006 19:43:09.81 Service Pack 2 ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop" ((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log )))))))))))))))))))))))))))))))))))))))))))))))))) REGISTRY ENTRIES REMOVED: [HKEY_CLASSES_ROOT\clsid\{AF2F09E7-F1C1-4751-B62E-52B622DE941B}] @="" [HKEY_CLASSES_ROOT\clsid\{AF2F09E7-F1C1-4751-B62E-52B622DE941B}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\clsid\{AF2F09E7-F1C1-4751-B62E-52B622DE941B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\clsid\{AF2F09E7-F1C1-4751-B62E-52B622DE941B}\InprocServer32] @="C:\\WINDOWS\\system32\\nztlogon.dll" "ThreadingModel"="Apartment" * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * FILES REMOVED: C:\WINDOWS\system32\c800lidm180a.dll C:\WINDOWS\system32\nztlogon.dll C:\WINDOWS\system32\s288lclu1fq8.dll Granting sedebugprivilege to Administrators … successful ((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))) Qoologic uninstaller found and executed. Registry entries fixed. (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\cfg32.exe C:\WINDOWS\cfg32a.exe C:\WINDOWS\Duce6.exe C:\dfndrff_e36.exe C:\kybrdff_e35.exe C:\kybrdff_e36.exe C:\nwnmff_e35.exe C:\nwnmff_e36.exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\78RSTLMN\dfndrff_e[2].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\78RSTLMN\dfndrff_e_uit[1].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\0S2UDEXY\drsmartload44a[1].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\6YQ9ATC4\deskbar_e[1].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\78RSTLMN\kybrdff_e[1].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\78RSTLMN\MTE3NDI6ODoxNg[1].exe C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\H9STU4WO\nwnmff_e[1].exe C:\WINDOWS\offun.exe C:\WINDOWS\wallpap.exe C:\WINDOWS\system32\aaa00000.sys C:\WINDOWS\system32\cmd.com C:\WINDOWS\system32\dwdsregt.exe C:\WINDOWS\system32\ping.com C:\WINDOWS\system32\regedit.com C:\WINDOWS\system32\tasklist.com C:\WINDOWS\system32\tracert.com C:\WINDOWS\system32\WinNB58.dll C:\WINDOWS\uninstall_nmon.vbs C:\WINDOWS\system32\atmtd.dll C:\WINDOWS\system32\atmtd.dll._ C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\NetMon C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\NetMon C:\Program Files\cmfibula C:\Program Files\Deskbar C:\Program Files\outlook C:\Program Files\winsupdater C:\Program Files\winupdate C:\Program Files\winupdates C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001} C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\svchost.exe C:\Program Files\batty2 C:\Program Files\network monitor C:\Program Files\PrintView C:\Program Files\Common Files\{B03403D0-04B2-1033-0226-020504130001} C:\WINDOWS\cmd ((((((((((((((((((((((((((((((( Files Created from 2010-23-06 to 2010/24/2006 )))))))))))))))))))))))))))))))))) No new files created in this timespan (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2012/29/2005 05:04 PM 24064 –a—— C:\WINDOWS\system32\drivers\ATITool.sys 2012/18/2004 08:32 PM 38229 ——— C:\WINDOWS\system32\drivers\StMp3Rec.sys 2011/10/2003 12:31 PM 36232 ——— C:\WINDOWS\system32\drivers\NETMD033.sys (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Tart"="\"C:\\PROGRA~1\\COMMON~1\\SCURIT~1\\wowexec.exe\" -vt yazb" "Vqeez"="C:\\WINDOWS\\system32\\S?mantec\\msiexec.exe" "CMIntex"="\"C:\\Program Files\\CMIntex\\CMIntex.exe\"" "PSCastor"="\"C:\\Program Files\\PSCastor\\PSCastor.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "csr"="csrrs.exe" "{40-03-3D-D0-ZN}"="C:\\windows\\system32\\okdsregr.exe ELT001" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "BDNewsAgent"="\"c:\\program files\\softwin\\bitdefender8\\bdnagent.exe\"" "ACTX1"="C:\\WINDOWS\\v1201.exe" "gkywyddA"="C:\\WINDOWS\\gkywyddA.exe" "win3208432-1338768"="C:\\WINDOWS\\win3208432-1338768.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] "csr"="csrrs.exe" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="C:\\Program Files\\Messenger\\kyzerekoj.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] "Source"="C:\\Program Files\\Common Files\\howyp.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "NoDispSettingsPage"=dword:00000000 "NoDispScrSavPage"=dword:00000000 "NoDispAppearancePage"=dword:00000000 "NoVisualStyleChoice"=dword:00000000 "NoColorChoice"=dword:00000000 "NoSizeChoice"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000000 "NoLowDiskSpaceChecks"=dword:00000001 "NoInstrumentation"=dword:00000001 "MemCheckBoxInRunDlg"=dword:00000000 "NoStrCmpLogical"=dword:00000000 "NoControlPanel"=dword:00000000 "NoAddPrinter"=dword:00000000 "NoDeletePrinter"=dword:00000000 "NoThemesTab"=dword:00000000 "NoChangeKeyboardNavigationIndicators"=dword:00000000 "NoChangeAnimation"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 "RunStartupScriptSync"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\MP Scheduled Scan.job Completion time: Tue 10/24/2006 19:47:58.06 C:\ComboFix.txt … 10/24/2006 07:47 PM
Welcome to the forum :wavey:

You started out with the right fix.

We'll probably need to do more.

Please "copy/paste" a new HijackThis! log file into this thread. :)
Logfile of HijackThis v1.99.1
Scan saved at 10:05:55 PM, on 10/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system32\okdsregr.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\v1201.exe
C:\WINDOWS\gkywyddA.exe
C:\WINDOWS\win3208432-1338768.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\PSCastor\PSCastor.exe
C:\WINDOWS\gkywydd.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\{B03403D0-04B2-1033-0226-020504130001}\Update.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
c:\dfndrff_e37.exe
c:\kybrdff_e37.exe
c:\nwnmff_e37.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\cmd\command.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [{40-03-3D-D0-ZN}] C:\windows\system32\okdsregr.exe ELT001
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [gkywyddA] C:\WINDOWS\gkywyddA.exe
O4 - HKLM\..\Run: [win3208432-1338768] C:\WINDOWS\win3208432-1338768.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinlpem.exe ELT001
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e37.exe
O4 - HKLM\..\Run: [keyboard] c:\\kybrdff_e37.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_e37.exe
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinlpem.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
O20 - AppInit_DLLs: BattyRun2.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\djtrans.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\cmd\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\gkywydd.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)


Evilware Emancipator thank you for your help Howard Anderson
Howard Anderson - 06-10-25 22:31:38.37 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{829E24CF-1E38-4562-ABA5-E9C723386478}]
@=""

[HKEY_CLASSES_ROOT\clsid\{829E24CF-1E38-4562-ABA5-E9C723386478}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{829E24CF-1E38-4562-ABA5-E9C723386478}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{829E24CF-1E38-4562-ABA5-E9C723386478}\InprocServer32]
@="C:\\WINDOWS\\system32\\djtrans.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\system32\djtrans.dll
C:\WINDOWS\system32\dtip32.dll


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\Duce6.exe
C:\dfndrff_e37.exe
C:\drsmartload.exe
C:\deskbar.exe
C:\deskbar_e37.exe
C:\kybrdff_e37.exe
C:\MTE3NDI6ODoxNg.exe
C:\nwnmff_e37.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\KXQ70XU7\dfndrff_e_uit[1].exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\K5QFCTUB\drsmartload44a[1].exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\SPUR0HEB\deskbar_e[1].exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\SPUR0HEB\kybrdff_e[1].exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\WL2BW5AB\MTE3NDI6ODoxNg[1].exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Local Settings\Temporary Internet Files\Content.IE5\KXQ70XU7\nwnmff_e[1].exe
C:\mte3ndi6odoxng.exe
C:\Installer4.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\NetMon
C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\NetMon
C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}
C:\Program Files\Deskbar
C:\Program Files\network monitor
C:\Program Files\Common Files\{B03403D0-04B2-1033-0226-020504130001}
C:\WINDOWS\cmd

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Application Data\FNTS~1
C:\QooBox\Purity\Program Files\CROSOF~1.NET
C:\QooBox\Purity\Program Files\Common Files\SCURIT~1
C:\QooBox\Purity\WINDOWS\system32\FNTS~1
C:\QooBox\Purity\WINDOWS\system32\SMANTE~1


((((((((((((((((((((((((((((((( Files Created from 2006-09-25 to 2006-10-25 ))))))))))))))))))))))))))))))))))


2006-10-25 22:33 106,496 –a—— C:\WINDOWS\Duce6.exe
2006-10-25 21:46 16,384 –a—— C:\mc44a37.exe
2006-10-24 18:17 172,148 –a—— C:\WINDOWS\system32\twinlpem.exe
2006-10-24 10:09 45,082 –a—— C:\WINDOWS\system32\okdsregr.exe
2006-10-23 00:01 45,056 –a—— C:\WINDOWS\cfg32s.dll
2006-10-23 00:01 397,312 –a—— C:\WINDOWS\cfg32p.dll
2006-10-23 00:01 168,033 –a—— C:\WINDOWS\system32\twinlpes.exe
2006-10-23 00:01 163,840 –a—— C:\WINDOWS\win3208432-1338768.exe
2006-10-23 00:01 110,592 –a—— C:\WINDOWS\cfg32o.dll
2006-10-23 00:01 102,400 –a—— C:\WINDOWS\cfg32r.dll
2006-10-23 00:00 45,056 –a—— C:\WINDOWS\gkywydd.exe
2006-10-23 00:00 29,696 –a—— C:\WINDOWS\system32\w0dceb1d.dll
2006-10-23 00:00 183,478 –a—— C:\WINDOWS\srvqiwtufy.exe
2006-10-23 00:00 110,592 –a—— C:\WINDOWS\v1201.exe
2006-10-23 00:00 1,147,824 -r-hs—- C:\WINDOWS\gkywyddA.exe
2006-10-22 20:01 234,272 -r–s—- C:\WINDOWS\system32\fpsres.dll
2006-10-22 12:19 155,648 –a—— C:\WINDOWS\b.exe
2006-10-20 13:46 918 –a—— C:\WINDOWS\system32\winpfg32.sys
2006-10-20 13:46 32,768 –a—— C:\WINDOWS\unstall.exe
2006-10-20 13:46 25,105 –a—— C:\WINDOWS\idlemg.exe
2006-10-20 13:45 2,560 –a—— C:\WINDOWS\ac3_0002.exe
2006-10-20 13:45 139,264 –a—— C:\WINDOWS\MirarSetup_876057.exe
2006-10-20 10:32 192 –a—— C:\WINDOWS\system32\ggg.bat
2006-10-20 10:31 24,576 –a—— C:\WINDOWS\system32\dr.exe
2006-10-20 10:31 20,480 –a—— C:\WINDOWS\system32\setup9X.exe
2006-10-16 11:36 0 –a—— C:\WINDOWS\system32\taskkill.exe
2006-10-15 03:19 53,248 –a—— C:\WINDOWS\system32\DrvTrNTm.dll
2006-10-15 03:19 122,880 –a—— C:\WINDOWS\system32\DrvTrNTl.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-25 22:35 ——– d-a—— C:\Program Files\Common Files
2006-10-25 22:01 ——– d——– C:\Program Files\Mozilla Firefox
2006-10-24 18:18 ——– d——– C:\Program Files\PSDream
2006-10-24 18:18 ——– d——– C:\Program Files\PSCastor
2006-10-24 18:18 ——– d——– C:\Program Files\CMIntex
2006-10-23 00:01 2 –a—— C:\WINDOWS\system32\wnscpsv.exe
2006-10-23 00:00 ——– d——– C:\Program Files\NetMeeting
2006-10-23 00:00 ——– d——– C:\Program Files\Messenger
2006-10-22 20:08 ——– d——– C:\Program Files\Calnique
2006-10-21 22:14 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-21 21:30 ——– d——– C:\Program Files\Sony
2006-10-21 19:27 ——– d——– C:\Program Files\Lavasoft
2006-10-21 17:44 ——– d——– C:\Program Files\Common Files\àppPatch
2006-10-21 00:47 ——– d——– C:\Program Files\Real Alternative
2006-10-21 00:47 ——– d——– C:\Program Files\QuickTime
2006-10-21 00:47 ——– d——– C:\Program Files\Media Player Classic
2006-10-20 15:07 ——– d——– C:\Program Files\Common Files\zzuq
2006-10-20 15:07 ——– d——– C:\Program Files\Common Files\AOL
2006-10-20 13:45 ——– d——– C:\Program Files\em
2006-10-19 21:42 ——– d——– C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Application Data\LimeWire
2006-10-19 21:16 ——– d——– C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Application Data\acccore
2006-10-19 21:15 ——– d——– C:\Program Files\Common Files\Nullsoft
2006-10-19 21:15 ——– d——– C:\Program Files\AOD
2006-10-19 19:29 ——– d——– C:\Program Files\RegScrubXP
2006-10-17 18:20 ——– d——– C:\Program Files\Nstorm
2006-10-15 03:19 ——– d——– C:\Program Files\HighCriteria
2006-10-14 18:47 ——– d——– C:\Program Files\InterActual
2006-10-13 03:10 ——– d——– C:\Program Files\MSXML 4.0
2006-10-11 18:57 ——– d——– C:\Program Files\GameHouse
2006-10-11 18:43 ——– d——– C:\Program Files\Microsoft Plus! Dancer LE
2006-10-09 17:43 ——– d——– C:\Program Files\GameSpy Arcade
2006-10-09 17:42 ——– d——– C:\Program Files\Microsoft Games
2006-10-06 09:56 ——– d——– C:\Program Files\Microsoft Plus! Digital Media Edition
2006-10-05 18:26 ——– d——– C:\Program Files\Internet Explorer
2006-09-22 08:38 53248 –a—— C:\WINDOWS\109uninst.exe
2006-09-22 08:36 53248 –a—— C:\WINDOWS\uni_7eh.exe
2006-09-12 23:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-12 17:51 1245184 –a—— C:\WINDOWS\system32\msxml4.dll
2006-09-05 22:12 ——– d——– C:\Program Files\iTunes
2006-08-30 09:43 ——– d——– C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Application Data\Apple Computer
2006-08-30 09:41 ——– d——– C:\Program Files\iPod
2006-08-27 02:04 ——– d——– C:\Program Files\ResumeMaker
2006-08-27 02:04 ——– d——– C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Application Data\Individual Software
2006-08-26 19:59 ——– d——– C:\Program Files\FaxTools
2006-08-25 09:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-21 06:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-16 05:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll
2006-08-10 08:00 737280 –a—— C:\WINDOWS\iun6002.exe
2006-08-07 09:17 61440 –a—— C:\WINDOWS\system32\BattyRun2.dll
2006-07-27 07:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CMIntex"="\"C:\\Program Files\\CMIntex\\CMIntex.exe\""
"PSCastor"="\"C:\\Program Files\\PSCastor\\PSCastor.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"csr"="csrrs.exe"
"{40-03-3D-D0-ZN}"="C:\\windows\\system32\\okdsregr.exe ELT001"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"BDNewsAgent"="\"c:\\program files\\softwin\\bitdefender8\\bdnagent.exe\""
"ACTX1"="C:\\WINDOWS\\v1201.exe"
"gkywyddA"="C:\\WINDOWS\\gkywyddA.exe"
"win3208432-1338768"="C:\\WINDOWS\\win3208432-1338768.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"csr"="csrrs.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\Messenger\\kyzerekoj.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Common Files\\howyp.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,ea,00,00,00,00,00,00,00,16,03,00,00,e4,02,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispSettingsPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispAppearancePage"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000
"NoLowDiskSpaceChecks"=dword:00000001
"NoInstrumentation"=dword:00000001
"MemCheckBoxInRunDlg"=dword:00000000
"NoStrCmpLogical"=dword:00000000
"NoControlPanel"=dword:00000000
"NoAddPrinter"=dword:00000000
"NoDeletePrinter"=dword:00000000
"NoThemesTab"=dword:00000000
"NoChangeKeyboardNavigationIndicators"=dword:00000000
"NoChangeAnimation"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"RunStartupScriptSync"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 06-10-25 22:35:49.76
C:\ComboFix.txt … 06-10-25 22:35
C:\ComboFix2.txt … 06-10-24 19:47



Logfile of HijackThis v1.99.1
Scan saved at 10:41:45 PM, on 10/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\gkywydd.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\system32\wscntfy.exe
C:\windows\system32\okdsregr.exe
C:\Program Files\QuickTime\qttask.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\v1201.exe
C:\WINDOWS\gkywyddA.exe
C:\WINDOWS\win3208432-1338768.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\PSCastor\PSCastor.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [{40-03-3D-D0-ZN}] C:\windows\system32\okdsregr.exe ELT001
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [gkywyddA] C:\WINDOWS\gkywyddA.exe
O4 - HKLM\..\Run: [win3208432-1338768] C:\WINDOWS\win3208432-1338768.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinlpem.exe ELT001
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinlpem.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
O20 - AppInit_DLLs: BattyRun2.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\gkywydd.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0

O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)

O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll

O4 - HKLM\..\Run: [csr] csrrs.exe

O4 - HKLM\..\Run: [{40-03-3D-D0-ZN}] C:\windows\system32\okdsregr.exe ELT001

O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe

O4 - HKLM\..\Run: [gkywyddA] C:\WINDOWS\gkywyddA.exe

O4 - HKLM\..\Run: [win3208432-1338768] C:\WINDOWS\win3208432-1338768.exe

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinlpem.exe ELT001

O4 - HKLM\..\RunServices: [csr] csrrs.exe

O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
(If you recognize this as "friendly", leave it alone!!!)

O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
(If you recognize this as "friendly", leave it alone!!!)

O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe

O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinlpem.exe

O15 - Trusted Zone: *.elitemediagroup.net

O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)

O20 - AppInit_DLLs: BattyRun2.dll

O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\gkywydd.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column look for:

Windows Overlay Components

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\gkywydd.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\program files\cmintex <— FOLDER
(If you recognize this as "friendly", leave it alone!!!)

c:\program files\pscastor <— FOLDER
(If you recognize this as "friendly", leave it alone!!!)

c:\windows\cfg32s.dll <— file

c:\windows\gkywydd.exe <— file

c:\windows\gkywydda.exe <— file

c:\windows\system32\dwdsregt.exe <— file

c:\windows\system32\okdsregr.exe <— file

c:\windows\system32\twinlpem.exe <— file

c:\windows\v1201.exe <— file

c:\windows\win3208432-1338768.exe <— file

c:\windows\system32\csrrs.exe <— file

c:\windows\system32\battyrun2.dll <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Logfile of HijackThis v1.99.1
Scan saved at 1:33:34 AM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\Duce6.exe
C:\Program Files\webHancer\Programs\whagent.exe
C:\dfndrff_e38.exe
C:\kybrdff_e38.exe
C:\nwnmff_e38.exe
C:\Program Files\Common Files\{B03403D0-04B2-1033-0226-020504130001}\Update.exe
C:\WINDOWS\cmd\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ms05768432-1338.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_e38.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e38.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e38.exe
O4 - HKLM\..\Run: [ms05768432-1338] C:\WINDOWS\ms05768432-1338.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\h2j40c1qef.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\cmd\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)



Evilware Emancipator Thanks again could not even begin to do this without your help. I will definetly donate to site. asap Howard Anderson
You're infected once more.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

Run combofix once more.

Boot in "safe" mode

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Close the program.

Boot normally, and post a new HijackThis! log file.

DO NOT REBOOT AGAIN UNTIL ASKED TO DO SO.
Logfile of HijackThis v1.99.1
Scan saved at 8:24:38 AM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [ms05768432-1338] C:\WINDOWS\ms05768432-1338.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Download LSPFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Run LSPFix.exe
2. Check 'I know what I'm doing'.
3. Select 'webhdll.dll'.
4. Click the right-pointing arrow.
5. Click 'Finished'.

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)

O4 - HKLM\..\Run: [ms05768432-1338] C:\WINDOWS\ms05768432-1338.exe

Then click "Fix checked" and close HijackThis!

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All.
Click the Empty Selected button.
Close the program.

Find and delete:

C:\WINDOWS\ms05768432-1338.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Logfile of HijackThis v1.99.1
Scan saved at 12:00:10 PM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\sys0338768432-13.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [sys0338768432-13] C:\WINDOWS\sys0338768432-13.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)

O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe

O4 - HKLM\..\Run: [sys0338768432-13] C:\WINDOWS\sys0338768432-13.exe

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

C:\WINDOWS\Duce6.exe <— file

C:\WINDOWS\sys0338768432-13.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Logfile of HijackThis v1.99.1
Scan saved at 1:21:49 PM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\program files\softwin\bitdefender8\bdnagent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Howard Anderson.N-E6E49B5669FB4\Desktop\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Howard's Browser
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{303403D0-04B2-1033-0226-020504130001}\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BDNewsAgent] "c:\program files\softwin\bitdefender8\bdnagent.exe"
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI