This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

lots of popups

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi ashtreysmom, that looks ok. see if you can locate this file webvqr.dll located here: C:\WINDOWS\system32 if so delete just that file, and post a new hjt log please.
okay..i had no luck searching for that file? but here is the log.
Logfile of HijackThis v1.99.1
Scan saved at 10:35:42 PM, on 1/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.0.419.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://clinton.mediacomtoday.com/community
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.0.419.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\webvqr.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
hi,

thanks for the info. lets try this;
lets try this again but please first disable avg guard so it wont interfere with the "fix" you can exit from the icon by the clock, right click>exit.

next launch hjt again:
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked

C:\WINDOWS\system32\webvqr.dll
reboot once. post another hjt log.

shelf life

lets try this also while we are at it:
1. Download this file :

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
alrighty..so i scanned w/HJT and it would not let me "fix" that file and agve me this pop up message

HijackThis window popped up saying:
An unexpected error has occured at procedure: modBackup_MakeBackup(sItem=020-AppInit_DLLs:
C:\WINDOWS\system32\webvqr.dll)

Please email me at [removed], reporting the following:
*What you were trying to fix when the error occured, if applicable
*How you can reproduce the error
*A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.


so i installed the prgram you suggested…here is that log..

"HP_Owner" - 07-01-23 17:39:45 Service Pack 2
ComboFix 07-01-23.2 - Running from: "C:\Documents and Settings\HP_Owner\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\HP_Owner\Application Data\Dxcknwrd.dll
C:\DOCUME~1\HP_Owner\Application Data\Install.dat
C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\emdat.tm
C:\WINDOWS\emdat.tmp
C:\DOCUME~1\LOCALS~1\Application Data\NetMon
C:\DOCUME~1\NETWOR~1\Application Data\NetMon
C:\Program Files\Common Files\{38E99~1
C:\Program Files\Common Files\{38E99~2
C:\Program Files\Common Files\{D8E99~1
C:\Program Files\Common Files\{D8E99~2
C:\Documents and Settings\All Users\Documents\Settings
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\HP_Owner
C:\qoobox\purity\DOCUME~1\HP_Owner\My Documents
C:\qoobox\purity\DOCUME~1\HP_Owner\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\HP_Owner\My Documents\MANTEC~1
C:\qoobox\purity\DOCUME~1\HP_Owner\My Documents\MANTEC~1\l?gonui.exe
C:\qoobox\purity\Program Files\Common Files\ASKS~1
C:\qoobox\purity\Program Files\Common Files\ICROSO~1.NET
C:\qoobox\purity\Program Files\Common Files\ASKS~1\?canregw.exe
C:\qoobox\purity\Program Files\Common Files\ICROSO~1.NET\?icrosoft.NET
C:\qoobox\purity\Program Files\Common Files\ICROSO~1.NET\?icrosoft.NET\ctxad-491.0000
C:\qoobox\purity\WINDOWS\CURITY~1
C:\qoobox\purity\WINDOWS\MCROSO~1
C:\qoobox\purity\WINDOWS\CURITY~1\CURITY~1
C:\qoobox\purity\WINDOWS\MCROSO~1\MCROSO~1
C:\qoobox\purity\WINDOWS\MCROSO~1\wuauboot.exe
C:\qoobox\purity\WINDOWS\system32\YSTEM3~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-23 to 2007-01-23 ))))))))))))))))))))))))))))))))))


2007-01-22 22:15 79,360 –a—— C:\WINDOWS\system32\swxcacls.exe
2007-01-22 22:15 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-01-22 22:15 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-01-22 22:15 40,960 –a—— C:\WINDOWS\system32\swsc.exe
2007-01-22 22:15 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-01-22 22:15 135,168 –a—— C:\WINDOWS\system32\swreg.exe
2007-01-22 20:23 3,346 –a—— C:\WINDOWS\system32\tmp.reg
2007-01-21 19:32 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-21 19:32 d——– C:\Program Files\Grisoft
2007-01-21 18:59 d——– C:\WINDOWS\F8BA8B13856D4DFBA28F7EC868142453.TMP
2007-01-21 18:59 d——– C:\Program Files\Google
2007-01-21 18:59 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-01-21 18:59 d——– C:\Program Files\Common Files\Scanner
2007-01-21 18:58 d——– C:\WINDOWS\system32\àdobe
2007-01-21 14:03 d——– C:\hijackthis
2007-01-21 02:56 0 –a—— C:\WINDOWS\system32\cmmgr32.exe
2007-01-21 02:56 0 –a—— C:\WINDOWS\ORUN32.EXE
2007-01-21 01:58 d——– C:\DOCUME~1\HP_Owner\Application Data\SuperAdBlocker.com
2007-01-21 01:56 d——– C:\Program Files\SuperAdBlocker.com
2007-01-20 13:26 2,112 –a—— C:\69522606.exe
2007-01-20 13:23 2,112 –a—— C:\47989045.exe
2007-01-20 12:23 2,112 –a—— C:\61019375.exe
2007-01-16 02:16 95,760 –a—— C:\WINDOWS\system32\isafeif.dll
2007-01-16 02:16 75,280 –a—— C:\WINDOWS\system32\vetredir.dll
2007-01-16 02:16 75,280 –a—— C:\WINDOWS\system32\isafprod.dll
2007-01-16 02:16 629,216 –a—— C:\WINDOWS\system32\drivers\vetefile.sys
2007-01-16 02:16 108,544 –a—— C:\WINDOWS\system32\drivers\veteboot.sys
2007-01-16 02:16 d——– C:\Program Files\CA
2007-01-16 02:16 d——– C:\DOCUME~1\ALLUSE~1\Application Data\CA
2007-01-15 13:19 119,816 –a—— C:\WINDOWS\system32\drivers\KmxCF.sys
2007-01-14 23:06 d——– C:\DOCUME~1\HP_Owner\Shared
2007-01-14 23:06 d——– C:\DOCUME~1\HP_Owner\Incomplete
2007-01-14 23:03 d——– C:\Program Files\LimeWire
2007-01-14 23:02 d——– C:\DOCUME~1\HP_Owner\.limewire
2007-01-14 00:06 31,616 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-01-14 00:06 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-01-14 00:06 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-01-13 13:25 2,114 –a—— C:\83463934.exe
2007-01-12 19:06 111,624 –a—— C:\WINDOWS\system32\drivers\KmxFw.sys
2007-01-08 17:41 102,408 –a—— C:\WINDOWS\system32\drivers\KmxStart.sys
2007-01-08 03:25 2,116 –a—— C:\57813944.exe
2007-01-05 12:56 8,413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys
2007-01-05 12:19 80,776 –a—— C:\WINDOWS\system32\drivers\KmxCfg.sys
2007-01-04 22:25 dr-hs—- C:\cmdcons
2007-01-04 22:19 32,528 –a—— C:\WINDOWS\system32\drivers\vetmonnt.sys
2007-01-04 22:19 26,640 –a—— C:\WINDOWS\system32\drivers\vet-filt.sys
2007-01-04 22:19 21,648 –a—— C:\WINDOWS\system32\drivers\vetfddnt.sys
2007-01-04 22:19 21,392 –a—— C:\WINDOWS\system32\drivers\vet-rec.sys
2007-01-04 22:19 11,264 –a—— C:\WINDOWS\system32\SpOrder.dll
2007-01-04 22:19 d——– C:\WINDOWS\system32\ZoneLabs
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\WINDOWS
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\Application Data\Symantec
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\Application Data\Sun
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\Application Data\SampleView
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\Application Data\Real
2007-01-04 20:29 d——– C:\DOCUME~1\HP_Owner\Application Data\Apple Computer
2007-01-04 20:26 21,060 ——— C:\WINDOWS\system32\drivers\iviaspi.sys
2007-01-04 20:26 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-01-04 20:24 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-01-04 20:24 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-01-04 20:24 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-01-04 20:24 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-01-04 20:24 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-01-04 20:24 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-01-04 20:22 172,032 –a—— C:\WINDOWS\system32\NVUninst.exe
2007-01-04 20:17 7,552 –a—— C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-01-04 20:17 61,056 –a—— C:\WINDOWS\system32\drivers\ohci1394.sys
2007-01-04 20:17 60,800 –a—— C:\WINDOWS\system32\drivers\sysaudio.sys
2007-01-04 20:17 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-01-04 20:17 6,400 –a—— C:\WINDOWS\system32\drivers\enum1394.sys
2007-01-04 20:17 54,272 –a—— C:\WINDOWS\system32\drivers\swmidi.sys
2007-01-04 20:17 53,248 –a—— C:\WINDOWS\system32\drivers\1394bus.sys
2007-01-04 20:17 52,864 –a—— C:\WINDOWS\system32\drivers\DMusic.sys
2007-01-04 20:17 5,376 –a—— C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-01-04 20:17 4,992 –a—— C:\WINDOWS\system32\drivers\MSPQM.sys
2007-01-04 20:17 4,096 –a—— C:\WINDOWS\system32\ksuser.dll
2007-01-04 20:17 2,944 –a—— C:\WINDOWS\system32\drivers\drmkaud.sys
2007-01-04 19:34 0 –a—— C:\mjadsii.exe
2007-01-04 19:30 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-01-04 19:27 11,066 –a—— C:\eryvk.exe
2007-01-04 19:26 10,298 –a—— C:\svhost.exe
2007-01-04 19:25 dr-h—– C:\MSOCache
2007-01-04 19:24 dr-hsc— C:\WINDOWS\system32\dllcache
2007-01-03 22:25 d——– C:\WINDOWS\CAVTemp
2007-01-01 02:26 2,116 –a—— C:\12112127.exe
2006-12-25 12:37 d——– C:\WINDOWS\RegisteredPackages
2006-12-25 10:32 d——– C:\Program Files\Rhapsody


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-21 21:15 ——– d——– C:\Program Files\messenger
2007-01-21 21:15 ——– d——– C:\Program Files\Common Files\companion wizard
2007-01-21 19:30 493 –a—— C:\WINDOWS\libes.dll
2007-01-21 18:59 ——– d–h—– C:\Program Files\bho plugin
2007-01-21 18:58 ——– d——– C:\Program Files\symantec
2007-01-21 18:58 ——– d——– C:\Program Files\pacificpoker
2007-01-21 18:58 ——– d——– C:\Program Files\help and support additions
2007-01-21 18:58 ——– d——– C:\Program Files\Common Files\symantec shared
2007-01-21 18:58 ——– d——– C:\DOCUME~1\HP_Owner\Application Data\yahoo!
2007-01-21 18:57 ——– d-a—— C:\Program Files\pc-doctor for windows
2007-01-21 18:57 ——– d——– C:\DOCUME~1\HP_Owner\Application Data\identities
2007-01-14 23:06 ——– d——– C:\Program Files\java
2007-01-14 15:33 ——– d——– C:\DOCUME~1\HP_Owner\Application Data\adobeum
2007-01-05 00:16 ——– d——– C:\Program Files\microsoft streets and trips essentials
2007-01-04 22:49 ——– d——– C:\Program Files\microsoft money 2006
2007-01-04 22:41 ——– d——– C:\Program Files\microsoft works
2007-01-04 20:27 50 –a—— C:\AUTOEXEC.BAT
2007-01-04 20:04 3884 –a—— C:\WINDOWS\viassary-hp.reg
2007-01-04 20:04 ——– d——– C:\Program Files\easy internet signup
2007-01-04 19:37 ——– d——– C:\Program Files\windows nt
2007-01-04 19:37 ——– d——– C:\Program Files\movie maker
2007-01-04 19:31 ——– d—s—- C:\DOCUME~1\HP_Owner\Application Data\microsoft
2006-12-12 19:41 107016 –a—— C:\WINDOWS\system32\drivers\KmxIds.sys
2006-12-10 00:47 69 –a-s—- C:\WINDOWS\test.bat
2006-12-04 21:28 8040 –a—— C:\DOCUME~1\HP_Owner\Application Data\wklnhst.dat
2006-10-28 11:39 67640 –a—— C:\DOCUME~1\HP_Owner\Application Data\gdipfontcachev1.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"FlashPlayerUpdate"="C:\\WINDOWS\\system32\\Macromed\\Flash\\GetFlash.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
"HPHUPD06"="c:\\Program Files\\HP\\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\\hphupd06.exe"
"HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"
"KBD"="C:\\HP\\KBD\\KBD.EXE"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"VTTimer"="VTTimer.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"AlcxMonitor"="ALCXMNTR.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"cctray"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\cctray\\cctray.exe\""
"QOELOADER"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Spam\\QSP-5.0.419.0\\QOELoader.exe\""
"CAVRID"="\"C:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\CAVRID.exe\""
"cafwc"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall\\cafw.exe -cl"
"capfaem"="C:\\Program Files\\CA\\CA Internet Security Suite\\CA Personal Firewall\\capfaem.exe"
"PS2"="C:\\WINDOWS\\system32\\ps2.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk"
"backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
"item"="HP Digital Imaging Monitor"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MI1933~1\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
"path"="C:\\Documents and Settings\\HP_Owner\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup"
"item"="LimeWire On Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperAdBlocker]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SAdBlock"
"hkey"="HKCU"
"command"="C:\\Program Files\\SuperAdBlocker.com\\Super Ad Blocker\\SAdBlock.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YAHOOM~1"
"hkey"="HKCU"
"command"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SABWinLogon

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4443f416-9c62-11db-98bf-806d6172696f}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070121-192724-304
O4 - Global Startup: fugyi.exe
backup-20070121-172527-488
O4 - Global Startup: fugyi.exe.tmp
backup-20070121-172527-313
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,nrsfmmc.exe
backup-20070121-172527-458
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\dwlcc.exe
backup-20070121-123446-990
O4 - Global Startup: fugyi.exe
backup-20070121-123446-758
O4 - HKCU\..\Run: [Uqtcum] C:\Documents and Settings\HP_Owner\My Documents\??mantec\l?gonui.exe
backup-20070121-123446-469
O4 - HKLM\..\Run: [{D8E99DA2-0833-1033-0902-040804030001}] "C:\Program Files\Common Files\{D8E99DA2-0833-1033-0902-040804030001}\Update.exe" te-110-12-0000213
backup-20070121-123446-559
O4 - HKCU\..\Run: [Srro] "C:\WINDOWS\CURITY~1\ping.exe" -vt yazr
backup-20070121-123446-480
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\dwlcc.exe
backup-20070121-123446-292
O4 - HKLM\..\Run: [{D8E99DA2-0834-1033-0902-040804030001}] "C:\Program Files\Common Files\{D8E99DA2-0834-1033-0902-040804030001}\Update.exe" te-110-12-0000213
backup-20070121-123446-563
R3 - URLSearchHook: (no name) - {0B61E60E-03E3-5B47-CB46-5C0798D5E3C7} - C:\WINDOWS\system32\skwjlcsm.dll
backup-20070121-123446-655
O2 - BHO: (no name) - {0B61E60E-03E3-5B47-CB46-5C0798D5E3C7} - C:\WINDOWS\system32\skwjlcsm.dll
backup-20070121-123446-260
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,nrsfmmc.exe

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as HP_Owner at 12 16 AM.job
C:\WINDOWS\tasks\Easy Internet Sign-up.job
C:\WINDOWS\tasks\WebReg 20060928205933.job

Completion time: 07-01-23 17:50:45



annnnnddd..:) then i re booted the system and rescanned w/ HJT and here is the new log..

Logfile of HijackThis v1.99.1
Scan saved at 6:02:37 PM, on 1/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.0.419.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\hijackthis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\sabtb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.0.419.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfaem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfaem.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PFW - C:\WINDOWS\SYSTEM32\UmxWnp.Dll
O20 - Winlogon Notify: SABWinLogon - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Super Ad Blocker Service (SABSVC) - SuperAdBlocker.com - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

:)thanks bunches
hi ashtreysmom, looks like combofix cleaned up some stuff. that last log looks good. time to make new restore points: You must be logged in as an Administrator to do this. If you are not logged in as an Administrator, the System Restore tab will not be displayed. Turning off System Restore will clear out all previous restore points. To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. (will delete possibly infected restore points) 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK. 4. Reboot (new clean restore point) shelf life
Well al is well that ends well, ey..I have done as you told me and hopefully Iam problem free now? Is there anything else I should do? Thank you again for all of your help~~Melissa~~
hi Melissa,

looks good to me. happy safe surfing.

for your reading pleasure:

Be careful of what you download, and where you download it from. Many programs come bundled with extra software.You may be installing more than you think. Learn more about the program, Does it come bundled with other "3rd party" programs? If you search hard enough you can always find a "clean" alternative to any software DO YOU TRUST THE SOURCE? Check this database:Spyware Guide or this: Library before installing free/shareware.

Make sure you keep your Windows OS/Browser current by visiting Windows update
occasionaly to download and install any critical updates and service packs. These patch flaws/bugs that can be exploited.

Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more:
Working with Internet Explorer 6 SecurityUse XP with SP2, consider using the new IE 7.0
Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser. You can have and use more than one browser on your computer.
Like Firefox,

Install a Firewall:A firewall will help to control what comes in from the internet and what leaves your computer to the internet. Zone Alarm is a free and easy to use firewall, that will provide in and outbound protection. Xp's built in firewall isnt as robust as third part firewalls. Zone Alarm is one of the easiest to use "out of the box" others have learning curves. I put them in what I believe is ease of use. Learn how to use it. "allow all" wont do much good if you have a trojan on your computer.
Zone Alarm
Sygate v 5.6 The last version
Tiny Firewall 2005 The last version
OutPost
Look n Stop
Jetico Personal Firewall


Outlook Express with the default settings is not secure. It will run scripts, download images etc, just like a browser, but this was the old Outlook Express. Service Pack 2 has made huge improvements to Outlook, but just like with Internet Explorer, you dont have to use it.
try Pegasus E-Mail.

Make sure you have and keep updated Antivirus software
Free for home users:
avast! 4 Home Edition Download
AVG free version 7.0
AntiVir Personal Edition
Clam Win

Download one or two of these, install and update before using:(if these are constantly finding malware, then you need to make changes to your browser and or your habits)
SuperAntiSpyware
CounterSpy
Spybot Search and destroy
Ad-Aware SE Personal edition
Microsoft Windows Defender
Becarful with spyware "removers and scanners"– there are many "rogue/suspect" programs that "claim to remove" spyware.Check here first.


AntiTrojan software to fill in the gap:
a2 free
Avg Anti-Spyware Free
Trojan Hunter
Tauscan trial version

Other programs to consider:
Process Guard stop events/processes with user intervention
SpywareBlaster add security to IE
IE-SPYAD adds adware peddlers sites/domains to IE restricted zone
ATF cleaner (W2K,XP only) cleans out temp files,history, cookies etc.

Learn More:
Test Your Browser
Parasite Free
Safe Hex
Shelf Lifes page
Browser Security Checkup
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI