This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Scan of Dell

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:25:41 PM, on 1/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\Dell\QuickSet\quickset.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toast.net/start/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.toast.net/start
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\system32\1.tmp
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RunBus Class - {4865F155-CE00-4E93-A414-147844D7C81A} - C:\WINDOWS\System32\tcblsblt.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: mycpmads.com Browser Optimizer - {582FDCF0-A82E-4fc1-A6F6-0D2F36881F63} - C:\WINDOWS\System32\br_rt.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\System32\SearchTool\nsz16A.dll
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-436325722327} - C:\WINDOWS\System32\SmartShopper\SmartShopper0.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\PROGRA~1\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [adstart] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\System32\br_rt.dll" DllVerify
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [MSN Messenger /background] msnmsgr.exeX
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installd…leanerstart.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase9602.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163375090041
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O20 - AppInit_DLLs: inicfg32.dll
O20 - Winlogon Notify: iexplore - 3fm3f.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: D0BCCGCH - {086D0717-1D9C-78F2-46EA-47052ADD2C4C} - C:\WINDOWS\System32\Kpqllj32.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISEXEng - Unknown owner - C:\WINDOWS\System32\angelex.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi RustyKeys, you got some infections there….

Please post an uninstall list to here.
  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.
  • Click on the Save list… button and specify where you would like to save this file.
  • When you press Save button a notepad will open with the contents of that file.
  • Simply copy and paste the contents of that notepad here on your next reply.
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A940ENG5 ABBYY FineReader 5.0 Sprint AccessDirect Ad-Aware SE Personal Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Download Manager 1.2 (Remove Only) Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 6.0.1 AOL Toolbar 2.0 Apple Software Update ATI Display Driver AVG Free Edition BCM V.92 56K Modem Broadcom Advanced Control Suite CommAid Dell AIO Printer A940 Dell Digital Jukebox Driver Dell Media Experience Dell Solution Center Dell Support 5.0.0 (766) DellConnect DS21Patch DVDSentry Google Toolbar for Internet Explorer HijackThis 1.99.1 Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Indeo® Software Internet Explorer Default Page Internet Update iTunes Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2 KISS Pinball 1.0 Learn2 Player (Uninstall Only) LimeWire 4.12.6 Macromedia Flash Player 8 MailFrontier Desktop MetaFrame Presentation Server Web Client for Win32 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Encarta Encyclopedia Standard 2004 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft National Language Support Downlevel APIs Microsoft Office 2000 Professional Microsoft Office Excel Viewer 2003 Microsoft Office PowerPoint Viewer 2003 Microsoft Office Word Viewer 2003 Modem Helper MSN Music Assistant MSXML 4.0 SP2 (KB927978) MUSICMATCH® Jukebox MyCPMAds Browser Optimizer pacman Game PowerDVD QuickSet QuickTime RapidPlayer v4.0 ActiveX Control RealOne Player SAM 2003 Search Enhancer Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB926255) Shockwave Smart Shopper Sonic DLA Sonic RecordNow! Sonic Update Manager Spybot - Search & Destroy 1.4 Synaptics Pointing Device Driver Terminology Tutor Uninstall 180search Assistant Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Viewpoint Manager (Remove Only) Viewpoint Media Player Visualizer Photo Resize Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 WordPerfect Office 11 ZoneAlarm
"johnny cappelletty" - 07-01-28 15:24:22 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Program Files\HiJackThis"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\dlh9jkd1q8.exe
C:\DOCUME~1\JOHNNY~1\Application Data\Sskuknwrd.dll
C:\WINDOWS\system32\bin29a.log
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\vx.tll
C:\secure32.html
C:\uniq


((((((((((((((((((((((((((((((( Files Created from 2006-12-28 to 2007-01-28 ))))))))))))))))))))))))))))))))))


2007-01-28 15:13 d——– C:\WINDOWS\LastGood
2007-01-27 18:34 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-27 18:00 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-01-27 18:00 11,264 –a—— C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-01-27 17:58 1,087,216 –a—— C:\WINDOWS\SYSTEM32\zpeng24.dll
2007-01-27 17:58 d——– C:\WINDOWS\SYSTEM32\ZoneLabs
2007-01-27 17:25 dr-h—– C:\$VAULT$.AVG
2007-01-27 15:01 d——– C:\DOCUME~1\JOHNNY~1\Application Data\AVG7
2007-01-27 14:57 816,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys
2007-01-27 14:57 4,960 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgtdi.sys
2007-01-27 14:57 4,224 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsw.sys
2007-01-27 14:57 3,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgclean.sys
2007-01-27 14:57 28,416 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7rsxp.sys
2007-01-27 14:57 18,240 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys
2007-01-27 14:57 d——– C:\Program Files\Grisoft
2007-01-27 14:57 d——– C:\DOCUME~1\LOCALS~1\Application Data\AVG7
2007-01-27 14:57 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft
2007-01-27 14:57 d——– C:\DOCUME~1\ALLUSE~1\Application Data\avg7
2007-01-27 14:32 d——– C:\WINDOWS\Internet Logs
2007-01-27 14:22 d——– C:\Program Files\HiJackThis
2007-01-27 13:33 d——– C:\Program Files\Windows Live Safety Center
2007-01-24 20:29 d——– C:\WINDOWS\WBEM
2007-01-24 20:29 d——– C:\WINDOWS\SYSTEM32\en-US
2007-01-24 20:26 d–h-c— C:\WINDOWS\ie7
2007-01-24 20:24 121,856 ——— C:\WINDOWS\SYSTEM32\xmllite.dll
2007-01-24 20:23 d——– C:\WINDOWS\network diagnostic
2007-01-20 14:51 d——– C:\Program Files\MSXML 4.0
2007-01-20 14:51 d——– C:\04d11aeea5dd98299fa03243b1
2007-01-19 11:55 d——– C:\WINDOWS\Prefetch
2007-01-18 21:27 d——– C:\WINDOWS\provisioning
2007-01-18 21:27 d——– C:\WINDOWS\peernet
2007-01-18 21:20 d——– C:\WINDOWS\ServicePackFiles
2007-01-18 20:56 d——– C:\WINDOWS\EHome
2007-01-18 20:38 d——– C:\WINDOWS\pss
2007-01-18 18:36 d——– C:\Program Files\Lavasoft
2007-01-08 06:27 61,440 –a—— C:\WINDOWS\SYSTEM32\br_rt.dll
2006-12-28 13:05 d——– C:\DOCUME~1\JOHNNY~1\Application Data\DriveCleaner 2006 Free


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-28 15:21 49 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb41.dat
2007-01-28 15:21 382 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb1942.dat
2007-01-28 15:20 20480 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb4827.dat
2007-01-28 15:20 151 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb292.dat
2007-01-28 15:20 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb2391.dat
2007-01-27 14:52 ——– d—s—- C:\DOCUME~1\JOHNNY~1\Application Data\microsoft
2007-01-25 11:14 ——– d——– C:\Program Files\google
2007-01-21 15:52 ——– d——– C:\Program Files\messenger
2007-01-18 21:27 ——– d——– C:\Program Files\movie maker
2007-01-18 21:19 ——– d——– C:\Program Files\windows nt
2007-01-18 18:36 ——– d——– C:\DOCUME~1\JOHNNY~1\Application Data\lavasoft
2007-01-11 12:54 ——– d——– C:\Program Files\viewpoint
2007-01-10 10:33 39745 –a—— C:\WINDOWS\SYSTEM32\br_rt-uninst.exe
2007-01-05 19:26 28256 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\MxlW2k.sys
2006-12-19 19:57 ——– d——– C:\DOCUME~1\JOHNNY~1\Application Data\apple computer
2006-12-19 10:33 ——– d——– C:\Program Files\dellconnect
2006-12-19 10:05 9216 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb8467.dat
2006-12-19 10:05 909503 –a—— C:\WINDOWS\SYSTEM32\winnb66.dll
2006-12-19 10:05 44888 –a—— C:\WINDOWS\SYSTEM32\caunst.exe
2006-12-19 10:05 36864 –a—— C:\WINDOWS\SYSTEM32\slimukkp.exe
2006-12-19 10:05 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb6334.dat
2006-12-19 10:05 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb5436.dat
2006-12-19 10:05 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb4604.dat
2006-12-19 10:05 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb3902.dat
2006-12-19 10:05 0 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\internaldb153.dat
2006-12-19 10:04 417792 –a—— C:\WINDOWS\SYSTEM32\tcblsblt.dll
2006-12-19 10:04 24576 –a—— C:\WINDOWS\SYSTEM32\msxml3a.dll
2006-12-19 10:04 116138 –a—— C:\WINDOWS\18-979cccfcc7622e89302a49c23b6fa37a.exe
2006-12-19 10:03 66267 –a—— C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
2006-12-19 10:03 622613 –a—— C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
2006-12-19 10:03 365132 –a—— C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe
2006-12-19 10:03 356663 –a—— C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
2006-12-19 10:03 23 –a—— C:\DOCUME~1\JOHNNY~1\Application Data\inifile41.ini
2006-12-19 10:03 139264 –a—— C:\WINDOWS\mirar_distro_876088.exe
2006-12-16 13:14 ——– d——– C:\Program Files\microsoft frontpage
2006-12-16 13:14 ——– d——– C:\DOCUME~1\JOHNNY~1\Application Data\microsoft web folders
2006-12-07 01:40 2362184 –a—— C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-12-06 20:58 ——– d–h—– C:\Program Files\installshield installation information
2006-12-06 20:58 ——– d——– C:\Program Files\Common Files\xstream
2006-11-08 00:06 679424 –a—— C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 ——— C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 ——— C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 ——— C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 –a—— C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 –a—— C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 ——— C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 –a—— C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 –a—— C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 –a—— C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 –a—— C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 –a—— C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 –a—— C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 –a—— C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 –a—— C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 –a—— C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 –a—— C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 –a—— C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\SYSTEM32\msxml4.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"BCMSMMSG"="BCMSMMSG.exe"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"DadApp"="C:\\Program Files\\Dell\\AccessDirect\\dadapp.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"StorageGuard"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"mmtask"="c:\\Program Files\\MusicMatch\\MusicMatch Jukebox\\mmtask.exe"
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"Dell AIO Printer A940"="\"C:\\Program Files\\Dell AIO Printer A940\\dlbabmgr.exe\""
"Dell QuickSet"="C:\\PROGRA~1\\Dell\\QuickSet\\quickset.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"adstart"="C:\\WINDOWS\\System32\\Rundll32.exe \"C:\\WINDOWS\\System32\\br_rt.dll\" DllVerify"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"MSN Messenger /background"="msnmsgr.exeX"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~4\\Office\\OSA9.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^johnny cappelletty^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
"path"="C:\\Documents and Settings\\johnny cappelletty\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup"
"item"="LimeWire On Startup"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^johnny cappelletty^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
"path"="C:\\Documents and Settings\\johnny cappelletty\\Start Menu\\Programs\\Startup\\PowerReg Scheduler V3.exe"
"backup"="C:\\WINDOWS\\pss\\PowerReg Scheduler V3.exeStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\johnny cappelletty\\Start Menu\\Programs\\Startup\\PowerReg Scheduler V3.exe"
"item"="PowerReg Scheduler V3"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSAgnt"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UDC2006"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\DriveCleaner 2006 Free\\UDC2006.exe\" /min"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSentry"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\DSentry.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Messenger /background]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKLM"
"command"="msnmsgr.exeX"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ypager"
"hkey"="HKCU"
"command"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="inicfg32.dll"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"D0BCCGCH"="{086D0717-1D9C-78F2-46EA-47052ADD2C4C}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Sygate Personal Firewall"="host32.exe"
"EXPLORER MICROSOFT SYSTEM"="task.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Sygate Personal Firewall"="host32.exe"
"EXPLORER MICROSOFT SYSTEM"="task.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"pngrcl"="C:\\WINDOWS\\System32\\pngrcl.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://webmail.toast.net/getattachment.asp…83234&idx=6

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iexplore

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-28 15:44:37
Hi again, we'll continue :)

You should print these instructions or save these to a text file. Follow these instructions carefully.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner by Atribune to your desktop.
Do NOT run yet.

Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
==================

Open Control Panel -> Add/Remove programs -> Remove all the of the following or similar entries if found:
CommAid
Java 2 Runtime Environment, SE v1.4.2
MyCPMAds Browser Optimizer
Search Enhancer
Smart Shopper
Uninstall 180search Assistant
Viewpoint Manager (Remove Only)
Viewpoint Media Player

and any other programs you didn't install or don't recognize - if your not sure please ask first

Backup your registry:
  • Start
  • Run
  • Type the following to the box and hit Ok: regedit
  • A window opens, click on File
  • Choose Export form the menu
  • Change the save location to C:\
  • Give the filename, RegBackUp
  • Make sure that the filetype is set to Registryfiles (*.reg)
  • Click on Save and Close the window
Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriveCleaner 2006 Free]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Messenger /background]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"D0BCCGCH"=-

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Sygate Personal Firewall"=-
"EXPLORER MICROSOFT SYSTEM"=-

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Sygate Personal Firewall"=-
"EXPLORER MICROSOFT SYSTEM"=-

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"pngrcl"=-

[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

Disable the bad service
  • Start
  • Run
  • Type services.msc to the field and press enter.
  • A window opens, scroll down to ISEXEng
  • Rightclick it and choose Stop
  • Then choose Properties
  • Set Startup to Disabled
  • Click Apply and OK.
Then, open HijackThis.
  • Open the Misc Tools section
  • Delete an NT service
  • Copy the following line to the box and press OK; ISEXEng
  • Answer Yes
  • Close HIjackThis
Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,C:\WINDOWS\system32\1.tmp
O2 - BHO: RunBus Class - {4865F155-CE00-4E93-A414-147844D7C81A} - C:\WINDOWS\System32\tcblsblt.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: mycpmads.com Browser Optimizer - {582FDCF0-A82E-4fc1-A6F6-0D2F36881F63} - C:\WINDOWS\System32\br_rt.dll
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\System32\SearchTool\nsz16A.dll
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-436325722327} - C:\WINDOWS\System32\SmartShopper\SmartShopper0.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [adstart] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\System32\br_rt.dll" DllVerify
O4 - HKLM\..\RunServices: [MSN Messenger /background] msnmsgr.exeX
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installd…leanerstart.cab
O20 - AppInit_DLLs: inicfg32.dll
O20 - Winlogon Notify: iexplore - 3fm3f.dll (file missing)
O21 - SSODL: D0BCCGCH - {086D0717-1D9C-78F2-46EA-47052ADD2C4C} - C:\WINDOWS\System32\Kpqllj32.dll

Please run Killbox.

Select "Delete on Reboot".

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\System32\angelex.exe
C:\WINDOWS\system32\1.tmp
C:\WINDOWS\System32\tcblsblt.dll
C:\WINDOWS\System32\br_rt.dll
C:\WINDOWS\System32\Kpqllj32.dll
C:\WINDOWS\System32\pngrcl.exe
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb41.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb1942.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb4827.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb292.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb2391.dat
C:\WINDOWS\SYSTEM32\br_rt-uninst.exe
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb8467.dat
C:\WINDOWS\SYSTEM32\winnb66.dll
C:\WINDOWS\SYSTEM32\caunst.exe
C:\WINDOWS\SYSTEM32\slimukkp.exe
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb6334.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb5436.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb4604.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb3902.dat
C:\Documents and Settings\johnny cappelletty\Application Data\internaldb153.dat
C:\WINDOWS\18-979cccfcc7622e89302a49c23b6fa37a.exe
C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
C:\WINDOWS\7-7c15eb3352bcc3049d7e9e974ad283bf.exe
C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
C:\Documents and Settings\johnny cappelletty\Application Data\inifile41.ini
C:\WINDOWS\mirar_distro_876088.exe

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Select "All Files".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.
Go to the My Computer and delete the following folders (if present):
C:\Program Files\viewpoint
C:\Documents and Settings\johnny cappelletty\Application Data\DriveCleaner 2006 Free
C:\Program Files\DriveCleaner 2006 Free
C:\Program Files\Search Enhancer
C:\Program Files\SearchTool
C:\Program Files\SmartShopper
C:\Program Files\180 Search

Use the Windows search
  • Start
  • Search
  • All files and folders
  • More advanced options
Checkmark these options:
  • "Search system folders"
  • "Search hidden files and folders"
  • "Search subfolders"
  • Search for this and delete if found: msnmsgr.exeX
  • Search for this and delete if found: host32.exe
  • Search for this and delete if found: task.exe
  • Search for this and delete if found: inicfg32.dll
Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
Because no reply was made. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI