This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with Hijack This Log/Trojan detected

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to remove a trojan (Vundo.dll/BLJFTPRG.DLL) Here is the log of Hijack this.

Logfile of HijackThis v1.99.1
Scan saved at 4:36:18 PM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Updater.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Dynex Wireless G Adapter\WLService.exe
C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {04CF6848-F35D-43FC-812B-32D022228615} - C:\WINDOWS\system\yssvdd.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\WINDOWS\system32\mubiftbd.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {821F87FF-8245-4972-9E28-732E92EC2F51} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1133789217468
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Zango/ie/bridge-c32.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Dynex DX-WGDTC Service (Dynex DX-WGDTC WLService) - Unknown owner - C:\Program Files\Dynex Wireless G Adapter\WLService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Thanks!

Sue
SueT :)

Copy and Paste this post into a new text document

Step 1

Please disable SpySweeper, as it may hinder the removal of some HijackThis entries. You can re-enable it after you're clean.

Open it, click > Options over to the left then > click the Program tab > Uncheck "Start Spy Sweeper at Windows startup".
Over to the left click "shields"
  • Click the "Internet Explorer" tab and uncheck all there.
  • Click the "Windows System" tab and uncheck all there.
  • Click the "Host File" tab and uncheck all there.
  • Click the "Startup Programs" tab and uncheck "Startup Items Shield".

Scan with HijackThis again and place a checkmark in the boxes before the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: (no name) - {04CF6848-F35D-43FC-812B-32D022228615} - C:\WINDOWS\system\yssvdd.dll (file missing)
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\WINDOWS\system32\mubiftbd.dll
O3 - Toolbar: (no name) - {821F87FF-8245-4972-9E28-732E92EC2F51} - (no file)
O4 - HKLM\..\Run: [UserFaultCheck] C:\WINDOWS\system32\dumprep 0 -u
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Zango/ie/bridge-c32.cab

Close any Explorer windows which may be open and click the "Fix Checked" button.


Step 2

Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files,
    click YES
  • Once you click yes, your desktop will go blank as it starts removing
    Vundo.
  • When completed, it will prompt that it will reboot your computer,
    click OK.
  • Please post the contents of C:\vundofix.txt in your next reply
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button."
when VundoFix appears at reboot.


Step 3

Please Re-scan with HijackThis and post

1/ The new HJT log
2/ The vundofix.txt

Thank you
Hi,

Here is the HJT log, after I ran Vundofix.exe:

Logfile of HijackThis v1.99.1
Scan saved at 9:44:21 PM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Updater.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Dynex Wireless G Adapter\WLService.exe
C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1133789217468
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Dynex DX-WGDTC Service (Dynex DX-WGDTC WLService) - Unknown owner - C:\Program Files\Dynex Wireless G Adapter\WLService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Here is the Vundofix.txt file:


VundoFix V6.1.5

Checking Java version…

Java version is 1.5.0.2

Scan started at 9:22:16 PM 2/12/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.3.6

Checking Java version…

Java version is 1.5.0.2

Scan started at 9:35:01 PM 2/12/2007

Listing files found while scanning….

C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\WINDOWS\system32\acyedpit.exe
C:\WINDOWS\system32\aiheffxd.exe
C:\WINDOWS\system32\ajbbalkc.exe
C:\WINDOWS\system32\amvjpohj.exe
C:\WINDOWS\system32\anltdrds.exe
C:\WINDOWS\system32\aqdvcivw.exe
C:\WINDOWS\system32\arpfwuer.exe
C:\WINDOWS\system32\aulpmlum.exe
C:\WINDOWS\system32\bafdoddi.exe
C:\WINDOWS\system32\bggkdljn.exe
C:\WINDOWS\system32\bgtexfdu.exe
C:\WINDOWS\system32\bivxendk.exe
C:\WINDOWS\system32\blfvtxte.exe
C:\WINDOWS\system32\bljftprg.dll
C:\WINDOWS\system32\bwkjagmw.exe
C:\WINDOWS\system32\bxptodsy.exe
C:\WINDOWS\system32\caxsctja.exe
C:\WINDOWS\system32\caycmdyi.exe
C:\WINDOWS\system32\cdsmenyt.exe
C:\WINDOWS\system32\cktdiqul.exe
C:\WINDOWS\system32\cvaslebl.exe
C:\WINDOWS\system32\cxlbcldv.exe
C:\WINDOWS\system32\elfevxew.exe
C:\WINDOWS\system32\eloelclr.exe
C:\WINDOWS\system32\enaxubba.exe
C:\WINDOWS\system32\enitchkw.exe
C:\WINDOWS\system32\eratcxqc.exe
C:\WINDOWS\system32\esxbsffr.exe
C:\WINDOWS\system32\evhdxjut.exe
C:\WINDOWS\system32\exfmpbyw.exe
C:\WINDOWS\system32\eylltjdn.exe
C:\WINDOWS\system32\fhfajdvl.exe
C:\WINDOWS\system32\fisecjam.exe
C:\WINDOWS\system32\fkqcehxu.exe
C:\WINDOWS\system32\fksliswa.exe
C:\WINDOWS\system32\gpcygqss.exe
C:\WINDOWS\system32\grptfjlb.ini
C:\WINDOWS\system32\gxnqxaup.exe
C:\WINDOWS\system32\hbkhxtfa.exe
C:\WINDOWS\system32\hdhvwtwi.exe
C:\WINDOWS\system32\hevcrvfq.exe
C:\WINDOWS\system32\hffetmba.exe
C:\WINDOWS\system32\hgxvxqtj.exe
C:\WINDOWS\system32\hlcboeqi.exe
C:\WINDOWS\system32\hmbyqofu.exe
C:\WINDOWS\system32\hmrfdwwr.exe
C:\WINDOWS\system32\hondwsje.exe
C:\WINDOWS\system32\hpnqgkav.exe
C:\WINDOWS\system32\hrmlbllx.exe
C:\WINDOWS\system32\hyswrkcm.exe
C:\WINDOWS\system32\iagjeuqw.exe
C:\WINDOWS\system32\ibfawtjq.exe
C:\WINDOWS\system32\icdjaaqn.exe
C:\WINDOWS\system32\ihxkrfwy.exe
C:\WINDOWS\system32\imlitttk.exe
C:\WINDOWS\system32\ipjagtan.exe
C:\WINDOWS\system32\iudgkuuc.exe
C:\WINDOWS\system32\joijoail.exe
C:\WINDOWS\system32\kbhjdlks.exe
C:\WINDOWS\system32\kdmlvxig.exe
C:\WINDOWS\system32\klcfgifg.exe
C:\WINDOWS\system32\kmbyoxxq.exe
C:\WINDOWS\system32\kpwxdxxj.exe
C:\WINDOWS\system32\krbsxeiy.exe
C:\WINDOWS\system32\ksaxqxup.exe
C:\WINDOWS\system32\ksbthvyi.exe
C:\WINDOWS\system32\kuerqopd.exe
C:\WINDOWS\system32\kwkisfrk.exe
C:\WINDOWS\system32\lfouuapg.exe
C:\WINDOWS\system32\lomxxiaw.exe
C:\WINDOWS\system32\lsnhomxm.exe
C:\WINDOWS\system32\lvgvtskc.exe
C:\WINDOWS\system32\lwsqydps.exe
C:\WINDOWS\system32\lwtewtoa.exe
C:\WINDOWS\system32\megirhwj.exe
C:\WINDOWS\system32\mhrmwqdc.exe
C:\WINDOWS\system32\mkdkiwau.exe
C:\WINDOWS\system32\mmdfiiul.exe
C:\WINDOWS\system32\mtqqowwx.exe
C:\WINDOWS\system32\mvxbtkio.dll
C:\WINDOWS\system32\naslvydq.exe
C:\WINDOWS\system32\ncpvuokt.exe
C:\WINDOWS\system32\ndttpwno.exe
C:\WINDOWS\system32\nejtpory.exe
C:\WINDOWS\system32\nnnvajvn.exe
C:\WINDOWS\system32\nnthuwoa.exe
C:\WINDOWS\system32\nnydugle.exe
C:\WINDOWS\system32\nonacwql.exe
C:\WINDOWS\system32\ntkhnyav.exe
C:\WINDOWS\system32\nvsejmbh.exe
C:\WINDOWS\system32\nxbiorfq.exe
C:\WINDOWS\system32\nxnfoqrj.exe
C:\WINDOWS\system32\onqsdgsx.exe
C:\WINDOWS\system32\otkhhbkc.exe
C:\WINDOWS\system32\pbnrbkqi.exe
C:\WINDOWS\system32\pbreujvv.exe
C:\WINDOWS\system32\pefhbpeo.exe
C:\WINDOWS\system32\pfugoauy.exe
C:\WINDOWS\system32\pgwapvie.exe
C:\WINDOWS\system32\plkueecn.exe
C:\WINDOWS\system32\ptdglmag.exe
C:\WINDOWS\system32\qbqmsvec.exe
C:\WINDOWS\system32\qjvbodsq.exe
C:\WINDOWS\system32\qnatdfna.exe
C:\WINDOWS\system32\qoxepqwj.exe
C:\WINDOWS\system32\qqvubpve.exe
C:\WINDOWS\system32\qsnkpvxj.exe
C:\WINDOWS\system32\qstljbqj.exe
C:\WINDOWS\system32\qswoubkw.exe
C:\WINDOWS\system32\qtirirrh.exe
C:\WINDOWS\system32\qwudsatr.dll
C:\WINDOWS\system32\rgqkglcr.exe
C:\WINDOWS\system32\rimhhsqy.exe
C:\WINDOWS\system32\rkdhebum.exe
C:\WINDOWS\system32\rowabxyg.exe
C:\WINDOWS\system32\sheakjou.exe
C:\WINDOWS\system32\sjmkmbsc.exe
C:\WINDOWS\system32\snyqpjwd.exe
C:\WINDOWS\system32\spelairx.exe
C:\WINDOWS\system32\toycixuk.exe
C:\WINDOWS\system32\ttqylqai.exe
C:\WINDOWS\system32\tvhcjywo.exe
C:\WINDOWS\system32\tyuswvtx.exe
C:\WINDOWS\system32\ubkfnmiv.exe
C:\WINDOWS\system32\uenesvcd.exe
C:\WINDOWS\system32\ufhjymxk.exe
C:\WINDOWS\system32\ugxqooem.exe
C:\WINDOWS\system32\ukgxjlmf.exe
C:\WINDOWS\system32\ukxfqcfo.exe
C:\WINDOWS\system32\urasgkay.exe
C:\WINDOWS\system32\uyjssxfx.exe
C:\WINDOWS\system32\uykioxrg.dll
C:\WINDOWS\system32\uytmurmg.exe
C:\WINDOWS\system32\vbnjxrkx.exe
C:\WINDOWS\system32\vftasvav.exe
C:\WINDOWS\system32\visbttmn.exe
C:\WINDOWS\system32\vjxoiqgi.exe
C:\WINDOWS\system32\vkpnqwdq.exe
C:\WINDOWS\system32\vpbsooyk.exe
C:\WINDOWS\system32\wataqcoo.exe
C:\WINDOWS\system32\whvqpybn.exe
C:\WINDOWS\system32\whyocigh.exe
C:\WINDOWS\system32\wlqtrkrm.exe
C:\WINDOWS\system32\wnsibnfg.exe
C:\WINDOWS\system32\wnvrpsdu.exe
C:\WINDOWS\system32\wxdcoygt.exe
C:\WINDOWS\system32\wyfegyra.exe
C:\WINDOWS\system32\xkhwhsfd.exe
C:\WINDOWS\system32\xplxjqiw.exe
C:\WINDOWS\system32\xqiianaf.exe
C:\WINDOWS\system32\xrlappnl.exe
C:\WINDOWS\system32\xsnwatxe.exe
C:\WINDOWS\system32\yawlvoch.exe
C:\WINDOWS\system32\ycegruek.exe
C:\WINDOWS\system32\yfoiapwh.exe
C:\WINDOWS\system32\yhofqkmj.exe

Beginning removal…

Attempting to delete C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

Attempting to delete C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and settings\Owner\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

Attempting to delete C:\WINDOWS\system32\acyedpit.exe
C:\WINDOWS\system32\acyedpit.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\aiheffxd.exe
C:\WINDOWS\system32\aiheffxd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ajbbalkc.exe
C:\WINDOWS\system32\ajbbalkc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\amvjpohj.exe
C:\WINDOWS\system32\amvjpohj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\anltdrds.exe
C:\WINDOWS\system32\anltdrds.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\aqdvcivw.exe
C:\WINDOWS\system32\aqdvcivw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\arpfwuer.exe
C:\WINDOWS\system32\arpfwuer.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\aulpmlum.exe
C:\WINDOWS\system32\aulpmlum.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bafdoddi.exe
C:\WINDOWS\system32\bafdoddi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bggkdljn.exe
C:\WINDOWS\system32\bggkdljn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bgtexfdu.exe
C:\WINDOWS\system32\bgtexfdu.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bivxendk.exe
C:\WINDOWS\system32\bivxendk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\blfvtxte.exe
C:\WINDOWS\system32\blfvtxte.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bljftprg.dll
C:\WINDOWS\system32\bljftprg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bwkjagmw.exe
C:\WINDOWS\system32\bwkjagmw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\bxptodsy.exe
C:\WINDOWS\system32\bxptodsy.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\caxsctja.exe
C:\WINDOWS\system32\caxsctja.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\caycmdyi.exe
C:\WINDOWS\system32\caycmdyi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cdsmenyt.exe
C:\WINDOWS\system32\cdsmenyt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cktdiqul.exe
C:\WINDOWS\system32\cktdiqul.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cvaslebl.exe
C:\WINDOWS\system32\cvaslebl.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cxlbcldv.exe
C:\WINDOWS\system32\cxlbcldv.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\elfevxew.exe
C:\WINDOWS\system32\elfevxew.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\eloelclr.exe
C:\WINDOWS\system32\eloelclr.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\enaxubba.exe
C:\WINDOWS\system32\enaxubba.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\enitchkw.exe
C:\WINDOWS\system32\enitchkw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\eratcxqc.exe
C:\WINDOWS\system32\eratcxqc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\esxbsffr.exe
C:\WINDOWS\system32\esxbsffr.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\evhdxjut.exe
C:\WINDOWS\system32\evhdxjut.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\exfmpbyw.exe
C:\WINDOWS\system32\exfmpbyw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\eylltjdn.exe
C:\WINDOWS\system32\eylltjdn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhfajdvl.exe
C:\WINDOWS\system32\fhfajdvl.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fisecjam.exe
C:\WINDOWS\system32\fisecjam.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fkqcehxu.exe
C:\WINDOWS\system32\fkqcehxu.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fksliswa.exe
C:\WINDOWS\system32\fksliswa.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\gpcygqss.exe
C:\WINDOWS\system32\gpcygqss.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\grptfjlb.ini
C:\WINDOWS\system32\grptfjlb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\gxnqxaup.exe
C:\WINDOWS\system32\gxnqxaup.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hbkhxtfa.exe
C:\WINDOWS\system32\hbkhxtfa.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hdhvwtwi.exe
C:\WINDOWS\system32\hdhvwtwi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hevcrvfq.exe
C:\WINDOWS\system32\hevcrvfq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hffetmba.exe
C:\WINDOWS\system32\hffetmba.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hgxvxqtj.exe
C:\WINDOWS\system32\hgxvxqtj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hlcboeqi.exe
C:\WINDOWS\system32\hlcboeqi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hmbyqofu.exe
C:\WINDOWS\system32\hmbyqofu.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hmrfdwwr.exe
C:\WINDOWS\system32\hmrfdwwr.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hondwsje.exe
C:\WINDOWS\system32\hondwsje.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hpnqgkav.exe
C:\WINDOWS\system32\hpnqgkav.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hrmlbllx.exe
C:\WINDOWS\system32\hrmlbllx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\hyswrkcm.exe
C:\WINDOWS\system32\hyswrkcm.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\iagjeuqw.exe
C:\WINDOWS\system32\iagjeuqw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ibfawtjq.exe
C:\WINDOWS\system32\ibfawtjq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\icdjaaqn.exe
C:\WINDOWS\system32\icdjaaqn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ihxkrfwy.exe
C:\WINDOWS\system32\ihxkrfwy.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\imlitttk.exe
C:\WINDOWS\system32\imlitttk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ipjagtan.exe
C:\WINDOWS\system32\ipjagtan.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\iudgkuuc.exe
C:\WINDOWS\system32\iudgkuuc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\joijoail.exe
C:\WINDOWS\system32\joijoail.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kbhjdlks.exe
C:\WINDOWS\system32\kbhjdlks.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kdmlvxig.exe
C:\WINDOWS\system32\kdmlvxig.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\klcfgifg.exe
C:\WINDOWS\system32\klcfgifg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kmbyoxxq.exe
C:\WINDOWS\system32\kmbyoxxq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kpwxdxxj.exe
C:\WINDOWS\system32\kpwxdxxj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\krbsxeiy.exe
C:\WINDOWS\system32\krbsxeiy.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ksaxqxup.exe
C:\WINDOWS\system32\ksaxqxup.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ksbthvyi.exe
C:\WINDOWS\system32\ksbthvyi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kuerqopd.exe
C:\WINDOWS\system32\kuerqopd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\kwkisfrk.exe
C:\WINDOWS\system32\kwkisfrk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lfouuapg.exe
C:\WINDOWS\system32\lfouuapg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lomxxiaw.exe
C:\WINDOWS\system32\lomxxiaw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lsnhomxm.exe
C:\WINDOWS\system32\lsnhomxm.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lvgvtskc.exe
C:\WINDOWS\system32\lvgvtskc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lwsqydps.exe
C:\WINDOWS\system32\lwsqydps.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\lwtewtoa.exe
C:\WINDOWS\system32\lwtewtoa.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\megirhwj.exe
C:\WINDOWS\system32\megirhwj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mhrmwqdc.exe
C:\WINDOWS\system32\mhrmwqdc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mkdkiwau.exe
C:\WINDOWS\system32\mkdkiwau.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mmdfiiul.exe
C:\WINDOWS\system32\mmdfiiul.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mtqqowwx.exe
C:\WINDOWS\system32\mtqqowwx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mvxbtkio.dll
C:\WINDOWS\system32\mvxbtkio.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\naslvydq.exe
C:\WINDOWS\system32\naslvydq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ncpvuokt.exe
C:\WINDOWS\system32\ncpvuokt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ndttpwno.exe
C:\WINDOWS\system32\ndttpwno.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nejtpory.exe
C:\WINDOWS\system32\nejtpory.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnvajvn.exe
C:\WINDOWS\system32\nnnvajvn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnthuwoa.exe
C:\WINDOWS\system32\nnthuwoa.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnydugle.exe
C:\WINDOWS\system32\nnydugle.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nonacwql.exe
C:\WINDOWS\system32\nonacwql.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ntkhnyav.exe
C:\WINDOWS\system32\ntkhnyav.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nvsejmbh.exe
C:\WINDOWS\system32\nvsejmbh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nxbiorfq.exe
C:\WINDOWS\system32\nxbiorfq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nxnfoqrj.exe
C:\WINDOWS\system32\nxnfoqrj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\onqsdgsx.exe
C:\WINDOWS\system32\onqsdgsx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\otkhhbkc.exe
C:\WINDOWS\system32\otkhhbkc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\pbnrbkqi.exe
C:\WINDOWS\system32\pbnrbkqi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\pbreujvv.exe
C:\WINDOWS\system32\pbreujvv.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\pefhbpeo.exe
C:\WINDOWS\system32\pefhbpeo.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\pfugoauy.exe
C:\WINDOWS\system32\pfugoauy.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\pgwapvie.exe
C:\WINDOWS\system32\pgwapvie.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\plkueecn.exe
C:\WINDOWS\system32\plkueecn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ptdglmag.exe
C:\WINDOWS\system32\ptdglmag.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qbqmsvec.exe
C:\WINDOWS\system32\qbqmsvec.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qjvbodsq.exe
C:\WINDOWS\system32\qjvbodsq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qnatdfna.exe
C:\WINDOWS\system32\qnatdfna.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qoxepqwj.exe
C:\WINDOWS\system32\qoxepqwj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qqvubpve.exe
C:\WINDOWS\system32\qqvubpve.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qsnkpvxj.exe
C:\WINDOWS\system32\qsnkpvxj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qstljbqj.exe
C:\WINDOWS\system32\qstljbqj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qswoubkw.exe
C:\WINDOWS\system32\qswoubkw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qtirirrh.exe
C:\WINDOWS\system32\qtirirrh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qwudsatr.dll
C:\WINDOWS\system32\qwudsatr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rgqkglcr.exe
C:\WINDOWS\system32\rgqkglcr.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\rimhhsqy.exe
C:\WINDOWS\system32\rimhhsqy.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\rkdhebum.exe
C:\WINDOWS\system32\rkdhebum.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\rowabxyg.exe
C:\WINDOWS\system32\rowabxyg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\sheakjou.exe
C:\WINDOWS\system32\sheakjou.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\sjmkmbsc.exe
C:\WINDOWS\system32\sjmkmbsc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\snyqpjwd.exe
C:\WINDOWS\system32\snyqpjwd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\spelairx.exe
C:\WINDOWS\system32\spelairx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\toycixuk.exe
C:\WINDOWS\system32\toycixuk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttqylqai.exe
C:\WINDOWS\system32\ttqylqai.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\tvhcjywo.exe
C:\WINDOWS\system32\tvhcjywo.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\tyuswvtx.exe
C:\WINDOWS\system32\tyuswvtx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ubkfnmiv.exe
C:\WINDOWS\system32\ubkfnmiv.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\uenesvcd.exe
C:\WINDOWS\system32\uenesvcd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ufhjymxk.exe
C:\WINDOWS\system32\ufhjymxk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ugxqooem.exe
C:\WINDOWS\system32\ugxqooem.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ukgxjlmf.exe
C:\WINDOWS\system32\ukgxjlmf.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ukxfqcfo.exe
C:\WINDOWS\system32\ukxfqcfo.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\urasgkay.exe
C:\WINDOWS\system32\urasgkay.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\uyjssxfx.exe
C:\WINDOWS\system32\uyjssxfx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\uykioxrg.dll
C:\WINDOWS\system32\uykioxrg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uytmurmg.exe
C:\WINDOWS\system32\uytmurmg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\vbnjxrkx.exe
C:\WINDOWS\system32\vbnjxrkx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\vftasvav.exe
C:\WINDOWS\system32\vftasvav.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\visbttmn.exe
C:\WINDOWS\system32\visbttmn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\vjxoiqgi.exe
C:\WINDOWS\system32\vjxoiqgi.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\vkpnqwdq.exe
C:\WINDOWS\system32\vkpnqwdq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\vpbsooyk.exe
C:\WINDOWS\system32\vpbsooyk.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wataqcoo.exe
C:\WINDOWS\system32\wataqcoo.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\whvqpybn.exe
C:\WINDOWS\system32\whvqpybn.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\whyocigh.exe
C:\WINDOWS\system32\whyocigh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wlqtrkrm.exe
C:\WINDOWS\system32\wlqtrkrm.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wnsibnfg.exe
C:\WINDOWS\system32\wnsibnfg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wnvrpsdu.exe
C:\WINDOWS\system32\wnvrpsdu.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxdcoygt.exe
C:\WINDOWS\system32\wxdcoygt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wyfegyra.exe
C:\WINDOWS\system32\wyfegyra.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xkhwhsfd.exe
C:\WINDOWS\system32\xkhwhsfd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xplxjqiw.exe
C:\WINDOWS\system32\xplxjqiw.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xqiianaf.exe
C:\WINDOWS\system32\xqiianaf.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xrlappnl.exe
C:\WINDOWS\system32\xrlappnl.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\xsnwatxe.exe
C:\WINDOWS\system32\xsnwatxe.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\yawlvoch.exe
C:\WINDOWS\system32\yawlvoch.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ycegruek.exe
C:\WINDOWS\system32\ycegruek.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\yfoiapwh.exe
C:\WINDOWS\system32\yfoiapwh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\yhofqkmj.exe
C:\WINDOWS\system32\yhofqkmj.exe Has been deleted!

Performing Repairs to the registry.
Done!

Did it get everything? How do I prevent this from happening again? I've updated McAfee. Do I need a special spysweeper program as well?

Thanks,

Sue
SueT :)

You are doing great and things are looking a little better,
and the protection you have already is also fine, can you please now complete this fix

Copy and Paste this post into a new text document

Step 1

Download CCleaner
Double click on the file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location. Click Install then finish to complete installation.
Double click the CCleaner shortcut on the desktop to start the program.
Click Run Cleaner to run the program.
Caution: It is not recommended to use the 'Issues' tab as it allegedly find's legitimate items.
After it has completed it's process, click Exit
.


Step 2

Please use Internet Explorer and run The Panda Online Activescan
http://www.pandasoftware.com/products/activescan.htm

Once you are on the Panda site click the Scan your PC button.
A new window will open…click the Check Now button.
Enter your Country.
Enter your State/Province.
Enter your e-mail address and click send.
Select either Home User or Company.
Click the big Scan Now button.
If it wants to install an ActiveX component, allow it to.
It will start downloading the files it requires for the scan (Note: It may take a minute or two).
When download is complete, click on Local Disks to start the scan.
When the scan completes, click the See Report button, then Save Report, and save it to your desktop.

Please Re-scan with HijackThis and post:

1/ The new HJT Log
2/ The Online Panda Result's

Thank you
Hi, Here is the HJT Log: Logfile of HijackThis v1.99.1 Scan saved at 8:02:01 AM, on 2/14/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Digital Media Reader\shwiconem.exe C:\WINDOWS\zHotkey.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Updater.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Dynex Wireless G Adapter\WLService.exe C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\PROGRA~1\McAfee\MPS\mps.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\McAfee\MPS\mpsevh.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe Here is the Panda Log: Incident Status Location Adware:adware/statblaster Not disinfected Windows Registry Adware:adware/wupd Not disinfected Windows Registry Adware:adware/sbsoft Not disinfected Windows Registry Adware:adware/zango Not disinfected Windows Registry Potentially unwanted tool:application/funweb Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\acyedpit.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\aiheffxd.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ajbbalkc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\amvjpohj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\anltdrds.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\aqdvcivw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\arpfwuer.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\aulpmlum.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bafdoddi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bggkdljn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bgtexfdu.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bivxendk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\blfvtxte.exe.bad Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\bljftprg.dll.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bwkjagmw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\bxptodsy.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\caxsctja.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\caycmdyi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\cdsmenyt.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\cktdiqul.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\cvaslebl.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\cxlbcldv.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\elfevxew.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\eloelclr.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\enaxubba.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\enitchkw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\eratcxqc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\esxbsffr.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\evhdxjut.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\exfmpbyw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\eylltjdn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\fhfajdvl.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\fisecjam.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\fkqcehxu.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\fksliswa.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\gpcygqss.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\gxnqxaup.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hbkhxtfa.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hdhvwtwi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hevcrvfq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hffetmba.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hgxvxqtj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hlcboeqi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hmbyqofu.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hmrfdwwr.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hondwsje.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hpnqgkav.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hrmlbllx.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\hyswrkcm.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\iagjeuqw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ibfawtjq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\icdjaaqn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ihxkrfwy.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\imlitttk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ipjagtan.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\iudgkuuc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\joijoail.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kbhjdlks.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kdmlvxig.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\klcfgifg.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kmbyoxxq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kpwxdxxj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\krbsxeiy.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ksaxqxup.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ksbthvyi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kuerqopd.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\kwkisfrk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lfouuapg.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lomxxiaw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lsnhomxm.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lvgvtskc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lwsqydps.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\lwtewtoa.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\megirhwj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\mhrmwqdc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\mkdkiwau.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\mmdfiiul.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\mtqqowwx.exe.bad Adware:Adware/Alexa-Toolbar Not disinfected C:\VundoFix Backups\mvxbtkio.dll.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\naslvydq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ncpvuokt.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ndttpwno.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nejtpory.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nnnvajvn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nnthuwoa.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nnydugle.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nonacwql.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ntkhnyav.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nvsejmbh.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nxbiorfq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\nxnfoqrj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\onqsdgsx.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\otkhhbkc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\pbnrbkqi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\pbreujvv.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\pefhbpeo.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\pfugoauy.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\pgwapvie.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\plkueecn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ptdglmag.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qbqmsvec.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qjvbodsq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qnatdfna.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qoxepqwj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qqvubpve.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qsnkpvxj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qstljbqj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qswoubkw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\qtirirrh.exe.bad Adware:Adware/WebSearch Not disinfected C:\VundoFix Backups\qwudsatr.dll.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\rgqkglcr.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\rimhhsqy.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\rkdhebum.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\rowabxyg.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\sheakjou.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\sjmkmbsc.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\snyqpjwd.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\spelairx.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\toycixuk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ttqylqai.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\tvhcjywo.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\tyuswvtx.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ubkfnmiv.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\uenesvcd.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ufhjymxk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ugxqooem.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ukgxjlmf.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ukxfqcfo.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\urasgkay.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\uyjssxfx.exe.bad Adware:Adware/WebSearch Not disinfected C:\VundoFix Backups\uykioxrg.dll.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\uytmurmg.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\vbnjxrkx.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\vftasvav.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\visbttmn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\vjxoiqgi.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\vkpnqwdq.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\vpbsooyk.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wataqcoo.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\whvqpybn.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\whyocigh.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wlqtrkrm.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wnsibnfg.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wnvrpsdu.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wxdcoygt.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\wyfegyra.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\xkhwhsfd.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\xplxjqiw.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\xqiianaf.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\xrlappnl.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\xsnwatxe.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\yawlvoch.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\ycegruek.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\yfoiapwh.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\yhofqkmj.exe.bad Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\caarrtye.exe Thanks! Sue
Hi SueT :)

I'm afraid you did not post all of the HijackThis log in your last reply..
'Not to worry' for now can you please continue with this fix.

Copy and Paste this post into a new text document

Step 1

Before we start you will need to make a back-up of the registry. This is standard procedure before carrying out any alterations to it.
Go to Start > Run, enter "regedit" (without the quotes) and click on OK.
Highlight My Computer by clicking on it and then go to File > Export…
Give the file an appropriate name, registry backup perhaps, leave the "Save As Type:" as it is and save it somewhere safe.
The Desktop is NOT a good idea as it's too close to the Recycle Bin for comfort!
This may take a moment or two so don't worry.

Go to: Start | Run, type in Notepad

Click Format from the Notepad menu and ensure "Word Wrap" is NOT selected.
Copy the Red Text below into Notepad.

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}]


Click : File | Save As
Change the Save as type to All Files
Save it to your desktop as fix.reg

Locate Fix.reg [external image: Posted Image] on your desktop and double-click it.
When asked if you want to merge with the registry, click YES.
Wait for the merged successfully prompt.


Step 2

Right-Click on and Delete this Folder: C:\VundoFix Backups


Then please go to: http://virusscan.jotti.org/
At the top select the Browse button then navigate to this File and Submit it to be scanned.
C:\WINDOWS\system32\caarrtye.exe
can you please Copy & Paste the scan result in your next reply


Step 3

Please Re-scan with HijackThis and post

1/ The new HJT log
2/ The Jotti Result

Thank you
Sorry, I thought I got it all. I still have the Notepad…do you want me to send you the rest, or just go to the next step? It will have to wait until tonight, when I'm home. Sue
Hi,

Here's the new HJT:
Logfile of HijackThis v1.99.1
Scan saved at 10:08:41 PM, on 2/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Updater.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Dynex Wireless G Adapter\WLService.exe
C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1133789217468
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Dynex DX-WGDTC Service (Dynex DX-WGDTC WLService) - Unknown owner - C:\Program Files\Dynex Wireless G Adapter\WLService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Here's the Jotti:

Scanner results
Scan taken on 15 Feb 2007 05:00:20 (GMT)
AntiVir Found ADSPY/Searchcolor.A adware
ArcaVir Found Adware.Searchcolor.A
Avast Found Win32:Searchcolor
AVG Antivirus Found Generic.RUN
BitDefender Found nothing
ClamAV Found Adware.Toolbar-46
Dr.Web Found Adware.SearchColours
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found not-a-virus:AdWare.Win32.Searchcolor.a (4, 1, 400)
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.Searchcolor.a
NOD32 Found Win32/Adware.Toolbar.SearchColours application
Norman Virus Control Found W32/Smalldrp.KEZ
VirusBuster Found Trojan.DR.Agent.QOE
VBA32 Found AdWare.Win32.Searchcolor.a

What next?

Thanks,

Sue
Hi SueT :)

Please remove VundoFix from your system

Re-Open HijackThis
Click on "Open the Misc Tools" section.
Click on "Delete a file on reboot"…
navigate to and select C:\WINDOWS\system32\caarrtye.exe
Click "Open" and select "Yes" to Reboot your computer.

————————–

Go to Start | Control Panel | Add/Remove Programs and Uninstall:

any item with Java Runtime Environment (JRE) in the name

Restart the computer.

Now CLICK HERE select the Download button next to "Java Runtime Environment (JRE) 6"
"Accept" the License Agreement Then choose the First download link "Windows Offline Installation, Multi-language".
Please note - You must Install this version Offline.

————————–

Run both Spysweeper and McAfee, Quarantine anything found

Can you let me know how your system is running now

Thank you.
Hi, I followed all the steps in the last email, and things seem to be better. Spysweeper found 18 items, and has quarentined all of them. Mcafee found 8. I haven't really used this computer much during the process of trying to fix it, so I'll turn my daughter loose on it again and have her test it out. Thanks very much for all the time you've put into this. Sue
SueT

Spysweeper found 18 items, and has quarentined all of them. Mcafee found 8

Run CCleaner then Re-scan again and let me know if anything is found
and as it's been a few day's.. post a new HijackThis log for me to check.

ourwilly
Hi,

Sorry it's taken so long for me to run this. Here's HJT:

Logfile of HijackThis v1.99.1
Scan saved at 8:18:14 PM, on 2/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Updater.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Dynex Wireless G Adapter\WLService.exe
C:\Program Files\Dynex Wireless G Adapter\WLanCfgG.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1133789217468
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Dynex DX-WGDTC Service (Dynex DX-WGDTC WLService) - Unknown owner - C:\Program Files\Dynex Wireless G Adapter\WLService.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Here's what Cleaner found: Uh, oh. I deleted it, by accident.

What next?

Thanks,

Sue
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI