This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yeah, Got me good too. Mad Virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, so i leave my friend alone with my computer for like 10 minutes. He downloads some zip file from a Peer to Peer. you don't even want to know what the title was. anyways, he runs it ( by the way, he's an idiot with computers) and wow, guess what happens. endless pop ups. not mentioning the internet explorer hijacking. whenever i click on a link it directs me to qwiksomething or other. a search tool i guess. it was heck trying to get to post a new topic. anyways i do have a hijack this log. and then hijackthis got deleted by mCAfee as a genericsomething or other. I have to turn off McAfee to run it again. and i ran ewido in Safe Mode. It found 160 something infected files. Some I'll put here.
Downloader.agent.agw
Downloader.Qoologic.bj
Downloader.Small.cyh
Not-A-Virus.Downloader.Win32.PopCap.a
Downloader.PurityScan.cq
Dropper.WinAd.h
Downloader.agent.ala
Downloader.small.buy
Hijacker.small.jf
Dropper.Small
Not-a-Virus.monitor.Win32.Netmon.a
Downloader.VB.ang
Downloader.purityscan.co
Downloader.small.ctp
Dropper.Agent.mu
Downloader.VB.anl
Downloader.Agent.Awb
Downloader.small
Backdoor.rbot.afu
Downloader.purityscan.dr
Trojan.vb.tg
Trojan.Qoologic
Hijacker.small
Downloader.adload.hw
Trojan.KillProc.p

It had errors deleting like the first 10 things. then the computer decided to freeze up and every time i try to delete the viruses from ewido, it freezes up and i have to close out and sometimes I have to shut down. I also have a few new programs on my installed programs list, like
888bar
media by OIN
New.net domains 7.44
OpenMG AAc Add- on Module 1.0.00
Open MG Limited Patch 4.5-06-05-12-01
Open MG Secure Module 4.5.01
Related Page - Sends me to http://remove.getmirar.com
Search Bar - Sends me to http://deskbar.worldtostart.com/deskbar/by…?id=%toolbar_id
Web Nexus Network
windows Overlay components
Yazzle by OIN
Command
Deluxe communications
Microsoft User-Mode Driver Framework Feature Pack 1.0 (Beta 2)
Network Monitor anyways, i would really appreciate some help. pleassseee. Thanks in advance.


Logfile of HijackThis v1.99.1
Scan saved at 3:03:40 PM, on 11/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\mxdin.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,wtklysg.exe
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_44.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O2 - BHO: (no name) - {B7DA7AAE-D553-4D85-8AC7-58E621F09FDA} - C:\Program Files\Online Services\mefo.dll
O2 - BHO: (no name) - {B82B2AEE-EF2C-BB8A-2EE3-B39E8D36579A} - C:\WINDOWS\system32\gyw.dll
O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3826B633-0AE9-1033-1111-040412200001}\888Bar.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3826B633-0AE9-1033-1111-040412200001}\888Bar.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto
O4 - HKLM\..\Run: [virtual-ie] winlogi.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [ms056747517473] C:\WINDOWS\ms056747517473.exe
O4 - HKLM\..\Run: [sys024736747517] C:\WINDOWS\sys024736747517.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [midpqigA] C:\WINDOWS\midpqigA.exe
O4 - HKLM\..\Run: [ToolbarInstall] c:\MirarSetup_876087.exe
O4 - HKLM\..\Run: [alwc6932] RUNDLL32.EXE w053628e.dll,n 006c692c00000003053628e
O4 - HKLM\..\Run: [defender] c:\\dfndrff_e50.exe
O4 - HKLM\..\Run: [keyboard] c:\\kybrdff_e50.exe
O4 - HKLM\..\Run: [newname] c:\\nwnmff_e49.exe
O4 - HKLM\..\RunServices: [virtual-ie] winlogi.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - HKCU\..\Run: [Sen] "C:\WINDOWS\system32\PPATCH~1\wowexec.exe" -vt yazb
O4 - HKCU\..\Run: [Amernp] C:\Documents and Settings\ZelmaE\Application Data\??stem32\s?rvices.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Volume Control.lnk = C:\WINDOWS\system32\sndvol32.exe
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://workplace.raleys.com/postauthI/epi.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.mumbojumbo.com/assets/mjolauncher.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v48/luxor/luxor.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\WmVsbWEgRS4gSm9uZXM\command.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\midpqig.exe


Thanks.
Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run combofix.

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.
:)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Yeah, so, i'm writing this in safe-mode (with networking), every time i try to get to tomcoyote.org my browser is hijacked and redirected to qwickfind.com it never fails. i cannot access tomcoyote in regular OS. anyways, here is the log from combofix and hijackthis. thanks so much for your help!!!!!!!!!!


Combofix-


ZelmaE - 06-11-08 20:24:30.42 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\ZelmaE\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-11-07 09:37 53 vqpqno.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\dxclib303562752.dll
C:\Documents and Settings\Paris\Application Data\Dxccwrd.dll
C:\Documents and Settings\Paris\Application Data\Dxcknwrd.dll
C:\Documents and Settings\ZelmaE\Application Data\Dxccwrd.dll
C:\Documents and Settings\ZelmaE\Application Data\Dxcdmns.dll
C:\Documents and Settings\ZelmaE\Application Data\Dxcknwrd.dll
C:\Documents and Settings\ZelmaE\Application Data\Dxcuknwrd.dll
C:\WINDOWS\system32\bkd.exe
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\DeluxeCommunications\DxcCore.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


C:\WINDOWS\system32\dxclib303562752.dll
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\DeluxeCommunications\DxcCore.dll
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\cfg32.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\drsmartload2.dat
C:\WINDOWS\teller2.chk
C:\WINDOWS\offun.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\netstat.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\taskkill.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tpuninstall.exe
C:\WINDOWS\system32\tracert.com
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\batty2
C:\Program Files\Inetget2
C:\Program Files\msmovies
C:\Program Files\network monitor
C:\Program Files\Common Files\{6826B633-0AE9-1033-1111-040412200001}
C:\WINDOWS\WmVsbWEgRS4gSm9uZXM

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\ZelmaE\Application Data\STEM32~1
C:\QooBox\Purity\WINDOWS\system32\PPATCH~1
C:\QooBox\Purity\WINDOWS\system32\PPATCH~1\PPATCH~1


((((((((((((((((((((((((((((((( Files Created from 2006-10-08 to 2006-11-08 ))))))))))))))))))))))))))))))))))


2006-11-08 00:08 45,056 –a—— C:\WINDOWS\cfg32s.dll
2006-11-08 00:08 110,592 –a—— C:\WINDOWS\cfg32o.dll
2006-11-08 00:08 102,400 –a—— C:\WINDOWS\cfg32r.dll
2006-11-07 15:43 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-07 15:43 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-07 15:43 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-07 15:43 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-07 15:42 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-07 15:42 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-07 10:42 32,768 –a—— C:\WINDOWS\gpneybhv.exe
2006-11-06 16:47 397,312 –a—— C:\WINDOWS\cfg32p.dll
2006-11-06 14:49 69,632 –a—— C:\WINDOWS\system32\pgpggkbj.dll
2006-11-06 14:49 32,768 –a—— C:\WINDOWS\system32\WinDmy.dll
2006-11-06 14:49 2 –a—— C:\WINDOWS\system32\wtstr.exe
2006-11-06 14:49 178,306 –a—— C:\WINDOWS\ac3_0008.exe
2006-11-06 14:49 1,259 –a—— C:\WINDOWS\system32\alwc6932.sys
2006-11-06 14:48 96,768 ——— C:\WINDOWS\system32\dxclib303562752.dll
2006-11-06 14:48 8,464 –a—— C:\WINDOWS\system32\sporder.dll
2006-11-06 14:48 555 –a—— C:\WINDOWS\tjskf.dll
2006-11-06 14:48 217,276 –a—— C:\WINDOWS\srvifvrq.exe
2006-11-02 12:23 8,704 -ra—— C:\WINDOWS\system32\betorder.dll
2006-11-02 12:23 69,183 –a—— C:\WINDOWS\system32\betsp.dll
2006-10-27 19:49 121,856 ——— C:\WINDOWS\system32\xmllite.dll
2006-10-17 12:33 6,049,280 ——— C:\WINDOWS\system32\ieframe.dll
2006-10-17 12:33 50,688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-10-17 12:33 458,752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-10-17 12:33 180,736 ——— C:\WINDOWS\system32\ieui.dll
2006-10-17 12:05 206,336 ——— C:\WINDOWS\system32\WinFXDocObj.exe
2006-10-17 12:01 13,312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-10-17 11:58 61,952 ——— C:\WINDOWS\system32\icardie.dll
2006-10-17 11:58 12,288 ——— C:\WINDOWS\system32\msfeedssync.exe
2006-10-17 11:57 266,752 ——— C:\WINDOWS\system32\iertutil.dll
2006-10-17 11:27 380,928 ——— C:\WINDOWS\system32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-08 20:25 ——– d——– C:\Program Files\Common Files
2006-11-08 18:51 ——– d——– C:\Program Files\Dl_cats
2006-11-08 10:10 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\AVG7
2006-11-07 22:55 ——– d——– C:\Program Files\Online Services
2006-11-07 22:55 ——– d——– C:\Program Files\BFG
2006-11-07 15:42 ——– d——– C:\Program Files\Grisoft
2006-11-07 15:41 ——– d—s—- C:\Documents and Settings\ZelmaE\Application Data\Microsoft
2006-11-07 15:11 ——– d——– C:\Program Files\Windows NT
2006-11-07 14:59 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-11-06 15:55 ——– d——– C:\Program Files\MSN
2006-11-06 14:49 ——– d——– C:\Program Files\PSCastor
2006-11-06 14:48 ——– d——– C:\Program Files\DeluxeCommunications
2006-11-02 12:23 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Aventail
2006-11-01 11:46 ——– d——– C:\Program Files\pogo games
2006-11-01 00:32 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Leadertech
2006-10-31 08:15 ——– d——– C:\Program Files\Diet Analysis Plus 7.0.1
2006-10-29 23:21 ——– d——– C:\Program Files\Oberon Media
2006-10-27 20:49 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\PlayFirst
2006-10-27 19:57 ——– d——– C:\Program Files\Internet Explorer
2006-10-27 19:54 ——– d——– C:\Program Files\Yahoo!
2006-10-27 19:39 ——– d——– C:\Program Files\PlayFirst
2006-10-26 15:46 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Corel
2006-10-25 08:01 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Mind Control Software
2006-10-25 08:00 ——– d——– C:\Program Files\Yahoo! Games
2006-10-17 20:34 ——– d——– C:\Program Files\MumboJumbo
2006-10-17 12:33 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-10-17 12:33 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-10-17 12:33 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-10-17 12:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll
2006-10-17 12:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll
2006-10-17 12:05 105984 –a—— C:\WINDOWS\system32\url.dll
2006-10-17 12:04 101376 –a—— C:\WINDOWS\system32\occache.dll
2006-10-17 12:03 17408 –a—— C:\WINDOWS\system32\corpol.dll
2006-10-17 12:01 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-10-17 12:01 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-10-17 12:01 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-10-17 12:01 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-10-17 12:01 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-10-17 12:00 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-10-17 12:00 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-10-17 12:00 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-10-17 11:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll
2006-10-17 11:56 45568 –a—— C:\WINDOWS\system32\mshta.exe
2006-10-17 11:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll
2006-10-17 11:23 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-10-14 20:14 ——– d——– C:\Program Files\Musicnotes
2006-10-12 16:00 ——– d——– C:\Program Files\Common Files\Oberon Media
2006-10-12 16:00 ——– d——– C:\Program Files\Comcast Play Games
2006-10-11 20:43 ——– d——– C:\Program Files\Luxor 2
2006-10-08 06:36 ——– d——– C:\Program Files\Microsoft.NET
2006-10-08 06:36 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-10-08 06:35 ——– d——– C:\Program Files\Microsoft Office
2006-10-08 06:35 ——– d——– C:\Program Files\Common Files\System
2006-10-04 13:33 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Adobe
2006-10-03 11:44 ——– d——– C:\Program Files\MTV Networks
2006-10-03 10:22 ——– d——– C:\Program Files\Windows Media Player
2006-10-03 10:22 ——– d——– C:\Program Files\Windows Media Connect 2
2006-10-02 20:52 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Sony Corporation
2006-10-01 14:32 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-10-01 14:32 ——– d——– C:\Program Files\Sony
2006-10-01 14:30 ——– d——– C:\Program Files\Common Files\Sony Shared
2006-09-27 19:55 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Ankh
2006-09-24 13:34 ——– d——– C:\Program Files\Watchtower
2006-09-24 13:19 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Watchtower
2006-09-22 14:50 ——– d——– C:\Program Files\Shockwave.com
2006-09-22 14:49 737280 –a—— C:\WINDOWS\iun6002.exe
2006-09-22 14:49 ——– d——– C:\Program Files\Backspin Billiards
2006-09-21 10:09 ——– d——– C:\Program Files\Common Files\Real
2006-09-20 05:19 ——– d——– C:\Program Files\Dell Photo AIO Printer 942
2006-09-19 17:16 ——– d——– C:\Program Files\Common Files\Adobe
2006-09-19 17:15 1561 –a—— C:\Documents and Settings\ZelmaE\Application Data\AdobeDLM.log
2006-09-19 17:15 0 –a—— C:\Documents and Settings\ZelmaE\Application Data\dm.ini
2006-09-19 17:15 ——– d——– C:\Program Files\Adobe
2006-09-19 17:15 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\AdobeUM
2006-09-19 17:15 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\AdobeAUM
2006-09-19 13:41 ——– d——– C:\Program Files\VideoLAN
2006-09-19 13:41 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\vlc
2006-09-19 12:34 ——– d——– C:\Program Files\Atlantis
2006-09-19 06:41 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Help
2006-09-18 23:42 ——– d——– C:\Program Files\Real
2006-09-18 20:47 ——– d——– C:\Program Files\CONEXANT
2006-09-18 16:57 774144 –a—— C:\Program Files\RngInterstitial.dll
2006-09-18 15:23 ——– d——– C:\Program Files\Jasc Software Inc
2006-09-18 15:23 ——– d——– C:\Program Files\Dell Computer
2006-09-18 15:23 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Jasc Software Inc
2006-09-17 18:41 ——– d——– C:\Program Files\WordPerfect Office 12
2006-09-15 14:57 ——– d——– C:\Program Files\Messenger
2006-09-15 14:51 ——– d——– C:\Program Files\Outlook Express
2006-09-15 13:16 53248 –a—— C:\WINDOWS\uni_e6h.exe
2006-09-15 11:26 ——– d——– C:\Program Files\LimeWire
2006-09-15 11:26 ——– d——– C:\Program Files\Java
2006-09-15 11:25 ——– d——– C:\Program Files\Common Files\Java
2006-09-14 11:41 61678 –a—— C:\Documents and Settings\ZelmaE\Application Data\PFP120JPR.{PB
2006-09-14 11:41 12358 –a—— C:\Documents and Settings\ZelmaE\Application Data\PFP120JCM.{PB
2006-09-14 10:53 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Macromedia
2006-09-14 04:11 ——– d——– C:\Program Files\Common Files\DESIGNER
2006-09-14 04:10 ——– d——– C:\Program Files\Microsoft Visual Studio
2006-09-14 04:10 ——– d——– C:\Program Files\Microsoft ActiveSync
2006-09-14 03:38 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Sonic
2006-09-14 03:29 ——– d——– C:\Program Files\McAfee.com
2006-09-14 03:27 ——– d——– C:\Program Files\Common Files\Sonic
2006-09-14 03:26 ——– d——– C:\Program Files\Sonic
2006-09-14 03:24 ——– d——– C:\Program Files\Common Files\Borland Shared
2006-09-14 03:23 ——– d——– C:\Program Files\Common Files\InstallShield
2006-09-14 03:23 ——– d——– C:\Program Files\Common Files\Corel
2006-09-14 03:08 ——– d——– C:\Program Files\ZIM
2006-09-14 03:06 ——– d——– C:\Program Files\CyberLink
2006-09-14 03:03 ——– d——– C:\Program Files\Intel
2006-09-14 03:00 ——– d——– C:\Program Files\Analog Devices
2006-09-14 01:40 ——– d——– C:\Program Files\Broadcom
2006-09-14 01:27 ——– d–h—– C:\Program Files\Uninstall Information
2006-09-14 01:27 ——– d——– C:\Documents and Settings\ZelmaE\Application Data\Identities
2006-09-14 01:04 62 –ahs—- C:\Documents and Settings\ZelmaE\Application Data\desktop.ini
2006-09-14 00:50 ——– d——– C:\Program Files\xerox
2006-09-14 00:50 ——– d——– C:\Program Files\microsoft frontpage
2006-09-14 00:49 0 -rahs—- C:\MSDOS.SYS
2006-09-14 00:49 0 -rahs—- C:\IO.SYS
2006-09-14 00:49 0 –a—— C:\CONFIG.SYS
2006-09-14 00:49 0 –a—— C:\AUTOEXEC.BAT
2006-09-14 00:48 ——– d–h—– C:\Program Files\WindowsUpdate
2006-09-14 00:47 ——– d——– C:\Program Files\NetMeeting
2006-09-14 00:47 ——– d——– C:\Program Files\Movie Maker
2006-09-14 00:47 ——– d——– C:\Program Files\Common Files\Services
2006-09-14 00:47 ——– d——– C:\Program Files\Common Files\MSSoap
2006-09-14 00:46 ——– d——– C:\Program Files\MSN Gaming Zone
2006-09-14 00:46 ——– d——– C:\Program Files\ComPlus Applications
2006-09-13 17:37 ——– d——– C:\Program Files\Common Files\SpeechEngines
2006-09-13 17:37 ——– d——– C:\Program Files\Common Files\ODBC
2006-09-12 21:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-09-06 16:43 22752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2006-08-25 07:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-24 21:42 8704 –a—— C:\WINDOWS\system32\wdfmgr.exe
2006-08-24 21:42 8704 –a—— C:\WINDOWS\system32\uwdf.exe
2006-08-24 21:30 99840 –a—— C:\WINDOWS\system32\wmpshell.dll
2006-08-24 21:30 990208 –a—— C:\WINDOWS\system32\drmv2clt.dll
2006-08-24 21:30 937984 –a—— C:\WINDOWS\system32\WMNetMgr.dll
2006-08-24 21:30 8337920 –a—— C:\WINDOWS\system32\wmploc.dll
2006-08-24 21:30 790016 ——— C:\WINDOWS\system32\WMVSENCD.dll
2006-08-24 21:30 757248 –a—— C:\WINDOWS\system32\WMADMOD.dll
2006-08-24 21:30 7168 –a—— C:\WINDOWS\system32\asferror.dll
2006-08-24 21:30 656896 ——— C:\WINDOWS\system32\WMVXENCD.dll
2006-08-24 21:30 63488 –a—— C:\WINDOWS\system32\wpdmtpus.dll
2006-08-24 21:30 629760 –a—— C:\WINDOWS\system32\wpd_ci.dll
2006-08-24 21:30 611840 ——— C:\WINDOWS\system32\wmpmde.dll
2006-08-24 21:30 603648 –a—— C:\WINDOWS\system32\WMSPDMOD.dll
2006-08-24 21:30 537600 –a—— C:\WINDOWS\system32\blackbox.dll
2006-08-24 21:30 532992 ——— C:\WINDOWS\system32\wmdrmsdk.dll
2006-08-24 21:30 428032 –a—— C:\WINDOWS\system32\wmdrmdev.dll
2006-08-24 21:30 414208 –a—— C:\WINDOWS\system32\msscp.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\wmvdmoe2.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\wmvdmod.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\WMVADVE.DLL
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\WMVADVD.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\wmsdmoe2.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\wmsdmod.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\wdfapi.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\MPG4DMOD.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\MP4SDMOD.dll
2006-08-24 21:30 4096 –a—— C:\WINDOWS\system32\MP43DMOD.dll
2006-08-24 21:30 37376 –a—— C:\WINDOWS\system32\wmdmps.dll
2006-08-24 21:30 35840 –a—— C:\WINDOWS\system32\wpdconns.dll
2006-08-24 21:30 349184 –a—— C:\WINDOWS\system32\wpdsp.dll
2006-08-24 21:30 347648 –a—— C:\WINDOWS\system32\wmdrmnet.dll
2006-08-24 21:30 33792 –a—— C:\WINDOWS\system32\wmdmlog.dll
2006-08-24 21:30 320512 –a—— C:\WINDOWS\system32\mswmdm.dll
2006-08-24 21:30 316928 ——— C:\WINDOWS\system32\MP4SDECD.dll
2006-08-24 21:30 314368 –a—— C:\WINDOWS\system32\wmpdxm.dll
2006-08-24 21:30 305152 ——— C:\WINDOWS\system32\MSDelta.dll
2006-08-24 21:30 295424 ——— C:\WINDOWS\system32\wmpeffects.dll
2006-08-24 21:30 284160 ——— C:\WINDOWS\system32\PortableDeviceApi.dll
2006-08-24 21:30 276480 ——— C:\WINDOWS\system32\audiodev.dll
2006-08-24 21:30 27648 –a—— C:\WINDOWS\system32\mspmsnsv.dll
2006-08-24 21:30 259072 ——— C:\WINDOWS\system32\MPG4DECD.dll
2006-08-24 21:30 2589184 ——— C:\WINDOWS\system32\WpdShext.dll
2006-08-24 21:30 258560 ——— C:\WINDOWS\system32\MP43DECD.dll
2006-08-24 21:30 2450944 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-08-24 21:30 242176 –a—— C:\WINDOWS\system32\wmpasf.dll
2006-08-24 21:30 228352 –a—— C:\WINDOWS\system32\cewmdm.dll
2006-08-24 21:30 227328 –a—— C:\WINDOWS\system32\wmerror.dll
2006-08-24 21:30 222208 –a—— C:\WINDOWS\system32\WMASF.dll
2006-08-24 21:30 211968 ——— C:\WINDOWS\system32\MFPLAT.dll
2006-08-24 21:30 210432 –a—— C:\WINDOWS\system32\qasf.dll
2006-08-24 21:30 204800 ——— C:\WINDOWS\system32\wmpsrcwp.dll
2006-08-24 21:30 198144 ——— C:\WINDOWS\system32\PortableDeviceWMDRM.dll
2006-08-24 21:30 179712 –a—— C:\WINDOWS\system32\msnetobj.dll
2006-08-24 21:30 175104 –a—— C:\WINDOWS\system32\mspmsp.dll
2006-08-24 21:30 166912 ——— C:\WINDOWS\system32\PortableDeviceTypes.dll
2006-08-24 21:30 1660416 ——— C:\WINDOWS\system32\wmpencen.dll
2006-08-24 21:30 157184 –a—— C:\WINDOWS\system32\wmidx.dll
2006-08-24 21:30 154624 –a—— C:\WINDOWS\system32\wpdmtp.dll
2006-08-24 21:30 1539584 ——— C:\WINDOWS\system32\WMVDECOD.dll
2006-08-24 21:30 1532416 ——— C:\WINDOWS\system32\WMVENCOD.dll
2006-08-24 21:30 1392128 ——— C:\WINDOWS\system32\WMVSDECD.dll
2006-08-24 21:30 133120 ——— C:\WINDOWS\system32\WPDShServiceObj.dll
2006-08-24 21:30 1327616 –a—— C:\WINDOWS\system32\WMSPDMOE.dll
2006-08-24 21:30 132096 ——— C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
2006-08-24 21:30 130048 ——— C:\WINDOWS\system32\wmpps.dll
2006-08-24 21:30 11264 –a—— C:\WINDOWS\system32\LAPRXY.dll
2006-08-24 21:30 1118208 –a—— C:\WINDOWS\system32\WMADMOE.dll
2006-08-24 21:30 101888 ——— C:\WINDOWS\system32\PortableDeviceClassExtension.dll
2006-08-24 19:31 100864 –a—— C:\WINDOWS\system32\logagent.exe
2006-08-24 19:27 249344 ——— C:\WINDOWS\system32\drmupgds.exe
2006-08-24 19:26 95288 ——— C:\WINDOWS\system32\WUDFCoinstaller.dll
2006-08-24 19:26 17408 ——— C:\WINDOWS\system32\wpdshextautoplay.exe
2006-08-24 18:19 316416 ——— C:\WINDOWS\system32\WUDFx.dll
2006-08-24 18:19 145920 ——— C:\WINDOWS\system32\WudfHost.exe
2006-08-24 18:18 56320 ——— C:\WINDOWS\system32\WudfSvc.dll
2006-08-24 18:18 168448 ——— C:\WINDOWS\system32\WudfPlatform.dll
2006-08-21 04:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 01:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-16 03:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SsAAD.exe"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
"PSCastor"="\"C:\\Program Files\\PSCastor\\PSCastor.exe\""
"Amernp"="C:\\Documents and Settings\\ZelmaE\\Application Data\\??stem32\\s?rvices.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask"
"VirusScan Online"="c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"UIUCU"="C:\\DOCUME~1\\ZelmaE\\LOCALS~1\\Temp\\UIUCU.EXE -CLEAN_UP -S"
"Dell Photo AIO Printer 942"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\dlbubmgr.exe\""
"DellMCM"="\"C:\\Program Files\\Dell Photo AIO Printer 942\\memcard.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"DLBUCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLBUtime.dll,_RunDLLEntry@16"
"ms056747517473"="C:\\WINDOWS\\ms056747517473.exe"
"alwc6932"="RUNDLL32.EXE w053628e.dll,n 006c692c00000003053628e"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\MSN\\pomogoda.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Common Files\\meke.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (ZELMA-ZelmaE).job
C:\WINDOWS\tasks\McAfee.com Update Check (ZELMA-London).job
C:\WINDOWS\tasks\McAfee.com Update Check (ZELMA-Owner).job
C:\WINDOWS\tasks\McAfee.com Update Check (ZELMA-Paris).job
C:\WINDOWS\tasks\McAfee.com Update Check (ZELMA-ZelmaE).job
C:\WINDOWS\tasks\User_Feed_Synchronization-{B2846612-36BE-46C9-B9A8-34440C3A236B}.job

Completion time: 06-11-08 20:28:20.75
C:\ComboFix.txt … 06-11-08 20:28



and here's hijack this -


Logfile of HijackThis v1.99.1
Scan saved at 8:41:49 PM, on 11/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {B7DA7AAE-D553-4D85-8AC7-58E621F09FDA} - C:\Program Files\Online Services\mefo.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [ms056747517473] C:\WINDOWS\ms056747517473.exe
O4 - HKLM\..\Run: [alwc6932] RUNDLL32.EXE w053628e.dll,n 006c692c00000003053628e
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
O4 - HKCU\..\Run: [Amernp] C:\Documents and Settings\ZelmaE\Application Data\??stem32\s?rvices.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Volume Control.lnk = C:\WINDOWS\system32\sndvol32.exe
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\betsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://workplace.raleys.com/postauthI/epi.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.mumbojumbo.com/assets/mjolauncher.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v48/luxor/luxor.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\midpqig.exe (file missing)

Thank you ver much. thank you thank you thank you.
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll

O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll

O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll

O2 - BHO: (no name) - {B7DA7AAE-D553-4D85-8AC7-58E621F09FDA} - C:\Program Files\Online Services\mefo.dll (file missing)

O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll

O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll

O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)

O4 - HKLM\..\Run: [ms056747517473] C:\WINDOWS\ms056747517473.exe

O4 - HKLM\..\Run: [alwc6932] RUNDLL32.EXE w053628e.dll,n 006c692c00000003053628e

O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe

O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"

O4 - HKCU\..\Run: [Amernp] C:\Documents and Settings\ZelmaE\Application Data\??stem32\s?rvices.exe

O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe

O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)

O20 - AppInit_DLLs: dxclib303562752.dll

O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\midpqig.exe (file missing)

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

C:\WINDOWS\cfg32s.dll <— file

C:\WINDOWS\ms056747517473.exe <— file

C:\Program Files\DeluxeCommunications <— FOLDER

C:\Program Files\PSCastor <— FOLDER

C:\Documents and Settings\ZelmaE\Application Data\??stem32 <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Wow, I only had to delete 4 of those. I had alread fixed the checked yesterday of 20 of them. by prior experience i determined which ones were bad and i got most of them. AVG and Ewido deleted the cfg32s.dll file and the ms….. file. here's the newest log and thanks for all your help.

Logfile of HijackThis v1.99.1
Scan saved at 5:46:22 PM, on 11/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Volume Control.lnk = C:\WINDOWS\system32\sndvol32.exe
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://workplace.raleys.com/postauthI/epi.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.mumbojumbo.com/assets/mjolauncher.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v48/luxor/luxor.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
I know what you mean about the mcAfee and AVG thing. i only downloaded aVG because my subscription to mcafee expired and it wasn't finding anything, i knew i was out of date. so i just disabled but ran a few scans. Other than that my computer is running fine. its pretty good so far. no problems. its a little slower but that's expected. i think its okay to close the thread though. thanks a lot for all your help. thank you thank you thank you!!!!!!!!!
If Mcafee is in add remove programs i should have no problem with it. If there are other components that i need to remove, well, I might need some help. but if not finito it is.
Sometimes uninstall programs leave remnants behind. After removing McAfee, reboot, and post a new HijackThis! log and we'll check it to be sure it's been totally removed. :) :thumbup:
Okay so here's hijack this after mcafee removal.



Logfile of HijackThis v1.99.1
Scan saved at 1:00:33 PM, on 11/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe
C:\Program Files\Dell Photo AIO Printer 942\memcard.exe
C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\Temporary Directory 8 for hijackthis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [UIUCU] C:\DOCUME~1\ZelmaE\LOCALS~1\Temp\UIUCU.EXE -CLEAN_UP -S
O4 - HKLM\..\Run: [Dell Photo AIO Printer 942] "C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe"
O4 - HKLM\..\Run: [DellMCM] "C:\Program Files\Dell Photo AIO Printer 942\memcard.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Volume Control.lnk = C:\WINDOWS\system32\sndvol32.exe
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://workplace.raleys.com/postauthI/epi.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.mumbojumbo.com/assets/mjolauncher.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v48/luxor/luxor.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/zuma/popcaploader_v5.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: dlbu_device - Dell - C:\WINDOWS\system32\dlbucoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe







thanks again
It's all gone.

I have seen times when parts of it were left.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI