This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer Adware Spyware Can You Take a Look At My HJT Log

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Do you see anything that needs to be removed? I have adaware but i still have issues with my overall speed and CPU processes, as well as continual popups.

Logfile of HijackThis v1.99.1
Scan saved at 1:39:33 AM, on 2/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\stejuvaA.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Jtcavxo\Ohrqm.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\thiselt.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\webHancer\Programs\whagent.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
c:\documents and settings\all users\start menu\programs\startup\dllhost.exe
C:\Program Files\LG Software Innovations\1Click DVD Copy Pro\1ClickDvdCopyPro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,iaxjayp.exe,ddjfihw.exe
O2 - BHO: (no name) - {158B3AE0-23B8-4EDB-BBA3-0E0FF680D841} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {1859F01F-545E-4CBD-A70F-FABDB4D7F122} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3DF1ED39-9225-4F5C-BEFB-92D8E0EA370C} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3F9BF32C-6F3C-4451-BE44-CBCA386450DF} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {44CBB95F-04BA-482C-8462-D174232F0618} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {4F9AD2F7-C7A6-42DF-A5B9-6B544E03AD1F} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6116F0B9-E18B-46B5-BB2E-0D672A178BE6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {64CCE2F9-BDE8-4022-A675-B3F6EEFFE9FE} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6F3B0E8E-3281-439C-A8D6-2F3FBC30E883} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {761A8D17-615D-4112-B727-D5A179979C92} - \
O2 - BHO: (no name) - {809D0A50-A214-4809-829A-E524ACE688E7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {8F805C1B-0C26-4A43-B994-C3DA020B58B6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {958F55D4-ECBF-4732-992E-0180BA46972D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {984F4F31-5ADD-4A9B-8D00-AAE28BC0EB03} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {990E53C6-A59C-4728-97F6-095A2A7C1A5A} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9D410882-BA89-437F-AC25-2885802F1640} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9DFEBA88-960C-49E3-9002-7E42C71AC828} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {A07B63F0-B655-4DE2-BF2B-9B742453B9BA} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: 0 - {A4A49707-AEB3-4D86-6181-59E24A1635D2} - C:\Program Files\NewDotNet\quhar.dll
O2 - BHO: (no name) - {AD1B9915-D71F-42C4-8CD5-27CF477905E6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B47B1434-E1B6-4D92-82B2-B05A526C2DE2} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B9F9B0C3-1F74-4BD2-8BDA-EAFC785BE2FD} - \
O2 - BHO: (no name) - {BD116767-BA84-424F-A1EE-5B4791EB8689} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O2 - BHO: (no name) - {CA61976B-F077-4FF0-82E8-776FD0A80C6B} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {DE9052BE-902C-EF8F-7A06-C889197F69EF} - C:\WINDOWS\system32\rvm.dll (file missing)
O2 - BHO: (no name) - {ECF8F1F6-133B-418F-B4C1-23A6F629FDB7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F3EDB774-EC7A-4F00-971C-8EE6239AF335} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F4BE91EB-467D-4368-92C8-9F241E497160} - C:\Program Files\Common Files\mevoxuzak.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [stejuvaA] C:\WINDOWS\stejuvaA.exe
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [windows] C:\\windows_e58.exe
O4 - HKLM\..\Run: [w0555362.dll] RUNDLL32.EXE w0555362.dll,I2 00270dca00555362
O4 - HKLM\..\Run: [Uijnk] C:\Program Files\Jtcavxo\Ohrqm.exe
O4 - HKLM\..\Run: [sys021074179016] C:\WINDOWS\sys021074179016.exe
O4 - HKLM\..\Run: [sys016107417901] C:\WINDOWS\sys016107417901.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e57.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e177.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [sipi] C:\WINDOWS\$NtUninstallKB892559$\sipi.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmwpy] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinqpem.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: http://*.metrolist.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://*.rapmls.com
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://click.mirarsearch.com/CABUPDATES/winwcd.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000140 (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\stejuva.exe
Download Winhelp2002's deldomain.inf to your desktop. http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'
It will not appear to have done anything, thats ok.

***Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection.

Lets try running combofix.exe
Download it from one of the links below:

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

Double click combofix.exe & follow the prompts.
When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
I did both of what you asked… the del domains is on my desktop, when i install it nothing happens like you said(however the first time i did this, my ad-aware started up, do i need to delete my ad-aware program?) Secondly when i run the other the combofix.exe, it starts up the DOS program comes up then it shuts down automatically… this also happens when i try the CMD prompt in RUN.. Thank you for your help
Logfile of HijackThis v1.99.1
Scan saved at 3:08:59 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stejuvaA.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Jtcavxo\Ohrqm.exe
C:\WINDOWS\sys016107417901.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\thiselt.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Sloopy7.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\sys021074179016.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,iaxjayp.exe,ddjfihw.exe
O2 - BHO: (no name) - {158B3AE0-23B8-4EDB-BBA3-0E0FF680D841} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {1859F01F-545E-4CBD-A70F-FABDB4D7F122} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3DF1ED39-9225-4F5C-BEFB-92D8E0EA370C} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3F9BF32C-6F3C-4451-BE44-CBCA386450DF} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {44CBB95F-04BA-482C-8462-D174232F0618} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {4EF921E8-0451-4773-8AFB-B40023E7DDBC} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {4F9AD2F7-C7A6-42DF-A5B9-6B544E03AD1F} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6116F0B9-E18B-46B5-BB2E-0D672A178BE6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {64CCE2F9-BDE8-4022-A675-B3F6EEFFE9FE} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6F3B0E8E-3281-439C-A8D6-2F3FBC30E883} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {739899E7-119F-4139-B967-746706BA6821} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {761A8D17-615D-4112-B727-D5A179979C92} - \
O2 - BHO: (no name) - {7C48EDD4-F51A-4BFF-9285-3AEC34BF5879} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {809D0A50-A214-4809-829A-E524ACE688E7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {835826BF-4DF3-4476-B182-517FB1A4727E} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {8F805C1B-0C26-4A43-B994-C3DA020B58B6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {958F55D4-ECBF-4732-992E-0180BA46972D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {984F4F31-5ADD-4A9B-8D00-AAE28BC0EB03} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: 0 - {98BA6F35-C3D0-4550-C090-B550A1AD431A} - C:\Program Files\NewDotNet\quhar.dll
O2 - BHO: (no name) - {990E53C6-A59C-4728-97F6-095A2A7C1A5A} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9D410882-BA89-437F-AC25-2885802F1640} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9DFEBA88-960C-49E3-9002-7E42C71AC828} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {A07B63F0-B655-4DE2-BF2B-9B742453B9BA} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {AD1B9915-D71F-42C4-8CD5-27CF477905E6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B47B1434-E1B6-4D92-82B2-B05A526C2DE2} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B9F9B0C3-1F74-4BD2-8BDA-EAFC785BE2FD} - \
O2 - BHO: (no name) - {BD116767-BA84-424F-A1EE-5B4791EB8689} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CA61976B-F077-4FF0-82E8-776FD0A80C6B} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {DE9052BE-902C-EF8F-7A06-C889197F69EF} - C:\WINDOWS\system32\rvm.dll (file missing)
O2 - BHO: (no name) - {ECF8F1F6-133B-418F-B4C1-23A6F629FDB7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F3EDB774-EC7A-4F00-971C-8EE6239AF335} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F4BE91EB-467D-4368-92C8-9F241E497160} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {FF1FA9B4-B5CE-4281-86F5-76D7E8567959} - C:\Program Files\Common Files\mevoxuzak.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [stejuvaA] C:\WINDOWS\stejuvaA.exe
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [windows] C:\\windows_e58.exe
O4 - HKLM\..\Run: [w0555362.dll] RUNDLL32.EXE w0555362.dll,I2 00270dca00555362
O4 - HKLM\..\Run: [Uijnk] C:\Program Files\Jtcavxo\Ohrqm.exe
O4 - HKLM\..\Run: [sys021074179016] C:\WINDOWS\sys021074179016.exe
O4 - HKLM\..\Run: [sys016107417901] C:\WINDOWS\sys016107417901.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e57.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e177.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [vurutuqu] C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Sloopy7.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmwpy] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinqpem.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://click.mirarsearch.com/CABUPDATES/winwcd.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\stejuva.exe
Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
SDFix: Version 1.63

Thu 02/08/2007 - 16:10:10.06

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
Client IP-IPX
Windows Overlay Components

Path:
"C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137
C:\WINDOWS\stejuva.exe

Client IP-IPX Deleted
Windows Overlay Components Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting…

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\DOCUME~1\CORY\LOCALS~1\TEMP\AFFILI~1.EXE - Deleted
C:\DOCUME~1\CORY\LOCALS~1\TEMP\AFF_001.EXE - Deleted
C:\DOCUME~1\CORY\LOCALS~1\TEMP\FRED.EXE - Deleted
C:\DOCUME~1\CORY\LOCALS~1\TEMP\SILVER.EXE - Deleted
C:\DOCUME~1\Cory\LOCALS~1\Temp\ac2_0004.exe - Deleted
C:\DOCUME~1\Cory\LOCALS~1\Temp\ac2_0006.exe - Deleted
C:\DOCUME~1\Cory\LOCALS~1\Temp\ac3_0004.exe - Deleted
C:\DOCUME~1\Cory\LOCALS~1\Temp\rsi.exe - Deleted
C:\DOCUME~1\Cory\LOCALS~1\Temp\setup.exe - Deleted
C:\dbg.txt - Deleted
C:\WINDOWS\system32\dwdsregt.exe - Deleted
C:\WINDOWS\system32\netstat.com - Deleted
C:\WINDOWS\system32\p2pnetworking.exe - Deleted
C:\WINDOWS\system32\svchosts.exe - Deleted
C:\WINDOWS\system32\taskkill.com - Deleted
C:\WINDOWS\system32\unsvchosts.lzma - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\Uninst2.htm - Deleted
C:\WINDOWS\Unist1.htm - Deleted



ADS Check:

C:\WINDOWS\system32
No streams found.

Final Check:

Remaining Services:
——————


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\regedit.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
C:\Documents and Settings\Cory\Local Settings\Temp\A3584.exe
C:\Documents and Settings\Cory\Local Settings\Temp\sdexe.exe
C:\WINDOWS\stejuvaA.exe
C:\hiberfil.sys
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Cory\Local Settings\Temp\win6798.tmp
C:\Documents and Settings\Cory\Local Settings\Temp\winBADA.tmp

Finished












Logfile of HijackThis v1.99.1
Scan saved at 4:24:42 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stejuvaA.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Jtcavxo\Ohrqm.exe
C:\WINDOWS\sys021074179016.exe
C:\WINDOWS\sys016107417901.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\thiselt.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\Sloopy7.exe
C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\p2pnetworking.exe
C:\WINDOWS\system32\stup9x.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {158B3AE0-23B8-4EDB-BBA3-0E0FF680D841} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {1859F01F-545E-4CBD-A70F-FABDB4D7F122} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3DF1ED39-9225-4F5C-BEFB-92D8E0EA370C} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3F9BF32C-6F3C-4451-BE44-CBCA386450DF} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {44CBB95F-04BA-482C-8462-D174232F0618} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {4EF921E8-0451-4773-8AFB-B40023E7DDBC} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {4F9AD2F7-C7A6-42DF-A5B9-6B544E03AD1F} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6116F0B9-E18B-46B5-BB2E-0D672A178BE6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {64CCE2F9-BDE8-4022-A675-B3F6EEFFE9FE} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6F3B0E8E-3281-439C-A8D6-2F3FBC30E883} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {739899E7-119F-4139-B967-746706BA6821} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {761A8D17-615D-4112-B727-D5A179979C92} - \
O2 - BHO: (no name) - {7C48EDD4-F51A-4BFF-9285-3AEC34BF5879} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {809D0A50-A214-4809-829A-E524ACE688E7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {835826BF-4DF3-4476-B182-517FB1A4727E} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {8F805C1B-0C26-4A43-B994-C3DA020B58B6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {958F55D4-ECBF-4732-992E-0180BA46972D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {984F4F31-5ADD-4A9B-8D00-AAE28BC0EB03} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {990E53C6-A59C-4728-97F6-095A2A7C1A5A} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9D410882-BA89-437F-AC25-2885802F1640} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9DFEBA88-960C-49E3-9002-7E42C71AC828} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9EC418A3-2EA9-4A30-83AE-9ED91003EED6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {A07B63F0-B655-4DE2-BF2B-9B742453B9BA} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {AD1B9915-D71F-42C4-8CD5-27CF477905E6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B31213FD-A3B4-42C5-8C1B-645603007BF1} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B47B1434-E1B6-4D92-82B2-B05A526C2DE2} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B9F9B0C3-1F74-4BD2-8BDA-EAFC785BE2FD} - \
O2 - BHO: (no name) - {BA3FE6A2-19FC-401E-AC06-7AF4F5E17C9D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {BD116767-BA84-424F-A1EE-5B4791EB8689} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CA61976B-F077-4FF0-82E8-776FD0A80C6B} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: 0 - {CA9E4FF7-A534-436E-85AA-166415360E89} - C:\Program Files\NewDotNet\quhar.dll
O2 - BHO: (no name) - {DE9052BE-902C-EF8F-7A06-C889197F69EF} - C:\WINDOWS\system32\rvm.dll (file missing)
O2 - BHO: (no name) - {ECF8F1F6-133B-418F-B4C1-23A6F629FDB7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F3EDB774-EC7A-4F00-971C-8EE6239AF335} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F4BE91EB-467D-4368-92C8-9F241E497160} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {FF1FA9B4-B5CE-4281-86F5-76D7E8567959} - C:\Program Files\Common Files\mevoxuzak.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [stejuvaA] C:\WINDOWS\stejuvaA.exe
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [w0555362.dll] RUNDLL32.EXE w0555362.dll,I2 00270dca00555362
O4 - HKLM\..\Run: [Uijnk] C:\Program Files\Jtcavxo\Ohrqm.exe
O4 - HKLM\..\Run: [sys021074179016] C:\WINDOWS\sys021074179016.exe
O4 - HKLM\..\Run: [sys016107417901] C:\WINDOWS\sys016107417901.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e57.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e177.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Sloopy7.exe
O4 - HKLM\..\Run: [vurutuqu] C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmwpy] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinqpem.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://click.mirarsearch.com/CABUPDATES/winwcd.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
Download The Avenger Copyright © Swandog46
You must extract avenger.exe to your desktop, before you run it.
The Avenger must be run from a user account with administrator privileges,
and ONLY works on Windows 2000 and XP, and only on 32-bit versions!

Copy all the text contained in the code box below to your Clipboard.

Files to delete:
C:\WINDOWS\thiselt.exe
C:\WINDOWS\system32\p2pnetworking.exe
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\Common Files\mevoxuzak.dll
C:\Program Files\NewDotNet\newdotnet7_48.dll
C:\Program Files\NewDotNet\quhar.dll
C:\WINDOWS\system32\rvm.dll
C:\WINDOWS\stejuvaA.exe
C:\Program Files\Jtcavxo\Ohrqm.exe
C:\WINDOWS\sys021074179016.exe
C:\WINDOWS\sys016107417901.exe
C:\WINDOWS\thiselt.exe
C:\nwnmff_e57.exe
C:\kybrdff_e177.exe
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\Program Files\winupdates\winupdates.exe
C:\WINDOWS\Sloopy7.exe
C:\WINDOWS\system32\bxlwxc.exe
C:\Program Files\System Files\System.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\kwinqpem.exe
Folders to delete:
C:\Program Files\NewDotNet
C:\Program Files\DeluxeCommunications


The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply.

Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.


Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {158B3AE0-23B8-4EDB-BBA3-0E0FF680D841} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {1859F01F-545E-4CBD-A70F-FABDB4D7F122} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3DF1ED39-9225-4F5C-BEFB-92D8E0EA370C} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {3F9BF32C-6F3C-4451-BE44-CBCA386450DF} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {44CBB95F-04BA-482C-8462-D174232F0618} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {4EF921E8-0451-4773-8AFB-B40023E7DDBC} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {4F9AD2F7-C7A6-42DF-A5B9-6B544E03AD1F} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6116F0B9-E18B-46B5-BB2E-0D672A178BE6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {64CCE2F9-BDE8-4022-A675-B3F6EEFFE9FE} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {6F3B0E8E-3281-439C-A8D6-2F3FBC30E883} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {739899E7-119F-4139-B967-746706BA6821} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {761A8D17-615D-4112-B727-D5A179979C92} - \
O2 - BHO: (no name) - {7C48EDD4-F51A-4BFF-9285-3AEC34BF5879} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {809D0A50-A214-4809-829A-E524ACE688E7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {835826BF-4DF3-4476-B182-517FB1A4727E} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {8F805C1B-0C26-4A43-B994-C3DA020B58B6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {958F55D4-ECBF-4732-992E-0180BA46972D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {984F4F31-5ADD-4A9B-8D00-AAE28BC0EB03} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {990E53C6-A59C-4728-97F6-095A2A7C1A5A} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9D410882-BA89-437F-AC25-2885802F1640} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9DFEBA88-960C-49E3-9002-7E42C71AC828} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {9EC418A3-2EA9-4A30-83AE-9ED91003EED6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {A07B63F0-B655-4DE2-BF2B-9B742453B9BA} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {AD1B9915-D71F-42C4-8CD5-27CF477905E6} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B31213FD-A3B4-42C5-8C1B-645603007BF1} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B47B1434-E1B6-4D92-82B2-B05A526C2DE2} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {B9F9B0C3-1F74-4BD2-8BDA-EAFC785BE2FD} - \
O2 - BHO: (no name) - {BA3FE6A2-19FC-401E-AC06-7AF4F5E17C9D} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {BD116767-BA84-424F-A1EE-5B4791EB8689} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CA61976B-F077-4FF0-82E8-776FD0A80C6B} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: 0 - {CA9E4FF7-A534-436E-85AA-166415360E89} - C:\Program Files\NewDotNet\quhar.dll
O2 - BHO: (no name) - {DE9052BE-902C-EF8F-7A06-C889197F69EF} - C:\WINDOWS\system32\rvm.dll (file missing)
O2 - BHO: (no name) - {ECF8F1F6-133B-418F-B4C1-23A6F629FDB7} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F3EDB774-EC7A-4F00-971C-8EE6239AF335} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {F4BE91EB-467D-4368-92C8-9F241E497160} - C:\Program Files\Common Files\mevoxuzak.dll
O2 - BHO: (no name) - {FF1FA9B4-B5CE-4281-86F5-76D7E8567959} - C:\Program Files\Common Files\mevoxuzak.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [stejuvaA] C:\WINDOWS\stejuvaA.exe
O4 - HKLM\..\Run: [w0555362.dll] RUNDLL32.EXE w0555362.dll,I2 00270dca00555362
O4 - HKLM\..\Run: [Uijnk] C:\Program Files\Jtcavxo\Ohrqm.exe
O4 - HKLM\..\Run: [sys021074179016] C:\WINDOWS\sys021074179016.exe
O4 - HKLM\..\Run: [sys016107417901] C:\WINDOWS\sys016107417901.exe
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e57.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e177.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Sloopy7.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmwpy] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinqpem.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://click.mirarsearch.com/CABUPDATES/winwcd.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)




Right-click on the deldomains.inf file and select 'Install'

Reboot after scanning and post a new HJT log.
I don't have an avenger.txt like it said it would make but here is the HJT Log…. Should i re-run the avenger program? Im still getting a few pop-ups but my computers overall performance seems a little better.THankYOu

Logfile of HijackThis v1.99.1
Scan saved at 5:52:13 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {0AEF69C7-29B0-4110-B92E-118BC13BEF6B} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1ABCAC7B-50A3-460E-B811-F2AFEC09228E} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {4B6EB507-A700-47A5-41AC-B06B78426D05} - C:\Program Files\321Studios\quhar.dll
O2 - BHO: (no name) - {6099345E-3496-4422-891E-B5C5C4492870} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {7A736801-2F07-4571-814F-B9D8970BAB15} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {B9F52E2F-2AB8-4918-B192-B91F7AE99C47} - C:\Program Files\Windows NT\mevoxuzak.dll
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [vurutuqu] C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
The file my have hidden atributes.
Click Here Should you need instructions for Showing hidden files and folders in Windows.
Click start / then my computer / local disk which will be C:

Or using Windows Explorer, locate the first file.
We need to see if it ran.
Logfile of HijackThis v1.99.1
Scan saved at 10:16:24 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {0AEF69C7-29B0-4110-B92E-118BC13BEF6B} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {10441A9A-5BF7-42E5-A872-C647C6134DF7} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1ABCAC7B-50A3-460E-B811-F2AFEC09228E} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {2F897507-03E2-42F6-918E-CA3523FFEE36} - C:\Program Files\321Studios\quhar800.dll
O2 - BHO: (no name) - {6099345E-3496-4422-891E-B5C5C4492870} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {7A736801-2F07-4571-814F-B9D8970BAB15} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {B9F52E2F-2AB8-4918-B192-B91F7AE99C47} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DFDF4D88-B616-4253-A0C5-E0D010CBBCEE} - C:\Program Files\Windows NT\mevoxuzak.dll
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [vurutuqu] C:\WINDOWS\$NtUninstallKB894391$\vurutuqu.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe







Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\uorfvtpb

*******************

Script file located at: \??\C:\xhpipsba.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\thiselt.exe deleted successfully.
File C:\WINDOWS\system32\p2pnetworking.exe deleted successfully.
File C:\Program Files\DeluxeCommunications\DxcBho.dll deleted successfully.
File C:\Program Files\Common Files\mevoxuzak.dll deleted successfully.
File C:\Program Files\NewDotNet\newdotnet7_48.dll deleted successfully.
File C:\Program Files\NewDotNet\quhar.dll deleted successfully.


File C:\WINDOWS\system32\rvm.dll not found!
Deletion of file C:\WINDOWS\system32\rvm.dll failed!

Could not process line:
C:\WINDOWS\system32\rvm.dll
Status: 0xc0000034

File C:\WINDOWS\stejuvaA.exe deleted successfully.
File C:\Program Files\Jtcavxo\Ohrqm.exe deleted successfully.
File C:\WINDOWS\sys021074179016.exe deleted successfully.
File C:\WINDOWS\sys016107417901.exe deleted successfully.


File C:\WINDOWS\thiselt.exe not found!
Deletion of file C:\WINDOWS\thiselt.exe failed!

Could not process line:
C:\WINDOWS\thiselt.exe
Status: 0xc0000034



File C:\nwnmff_e57.exe not found!
Deletion of file C:\nwnmff_e57.exe failed!

Could not process line:
C:\nwnmff_e57.exe
Status: 0xc0000034



File C:\kybrdff_e177.exe not found!
Deletion of file C:\kybrdff_e177.exe failed!

Could not process line:
C:\kybrdff_e177.exe
Status: 0xc0000034

File C:\Program Files\DeluxeCommunications\Dxc.exe deleted successfully.


File C:\Program Files\winupdates\winupdates.exe not found!
Deletion of file C:\Program Files\winupdates\winupdates.exe failed!

Could not process line:
C:\Program Files\winupdates\winupdates.exe
Status: 0xc0000034

File C:\WINDOWS\Sloopy7.exe deleted successfully.


File C:\WINDOWS\system32\bxlwxc.exe not found!
Deletion of file C:\WINDOWS\system32\bxlwxc.exe failed!

Could not process line:
C:\WINDOWS\system32\bxlwxc.exe
Status: 0xc0000034



Could not open file C:\Program Files\System Files\System.exe for deletion
Deletion of file C:\Program Files\System Files\System.exe failed!

Could not process line:
C:\Program Files\System Files\System.exe
Status: 0xc000003a

File C:\Program Files\LimeWire\LimeWire.exe deleted successfully.


File C:\WINDOWS\system32\kwinqpem.exe not found!
Deletion of file C:\WINDOWS\system32\kwinqpem.exe failed!

Could not process line:
C:\WINDOWS\system32\kwinqpem.exe
Status: 0xc0000034

Folder C:\Program Files\NewDotNet deleted successfully.
Folder C:\Program Files\DeluxeCommunications deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {0AEF69C7-29B0-4110-B92E-118BC13BEF6B} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {10441A9A-5BF7-42E5-A872-C647C6134DF7} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1ABCAC7B-50A3-460E-B811-F2AFEC09228E} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {2F897507-03E2-42F6-918E-CA3523FFEE36} - C:\Program Files\321Studios\quhar800.dll
O2 - BHO: (no name) - {6099345E-3496-4422-891E-B5C5C4492870} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {7A736801-2F07-4571-814F-B9D8970BAB15} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {B9F52E2F-2AB8-4918-B192-B91F7AE99C47} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DFDF4D88-B616-4253-A0C5-E0D010CBBCEE} - C:\Program Files\Windows NT\mevoxuzak.dll
O4 - HKLM\..\Run: [{6001F81E-0702-1033-0102-060503310001}] "C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\f40o0ed3eh0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\aza209foe.dll (file missing)
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe


Reboot in safe mode, instructions here.
Some of these files my have hidden atributes.
Click Here Should you need instructions for Showing hidden files and folders in Windows.
Once in safe mode, Click start / then my computer / local disk then follow the process tree.
Or using Windows Explorer, locate the first file right click then select delete.

Delete the following file(s) listed in bold.
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\WINDOWS\dls0523pmw.exe

Delete the following folder(s) listed in bold.
C:\Program Files\DeluxeCommunications

If you were unable to find any of the files then please follow these additional instructions:

Download Pocket Killbox and unzip it; save it to your Desktop.

Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.

The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.

Let the system reboot.

Run this online scan and post the results here.
i was able to delete the c:\Windows\dls0523pmw.exe… but the two deluxe communications said that the program was being used by another person or program and was unable to delete… so i am going to try the pocket killbox now… I also noticed a lot of weird files in the c:\windows file should i delete some of that???
continued…. Also now the kill box program is not deleting the DeluxeCommunications after the reboot… I am going to do the online scan now…
Here is the online scan report… Let me know what i should do next. Detected Disinfected Virus 9321 9319 Spyware 350 0 Hacking tools and rootkits 6 0 Dialers 2 0 Security Risks 0 0 Suspicious files 0 0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI