This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can you check my log if its clean?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I get pop ups in my windows explorer. I don't know what program is it but it has 2 options; Work Offline and Cancel I guess its a spyware or a its from internet explorer I scanned with Avast home 7, ad aware and spybot S&D. I also have spyware blaster and CCCleaner I also can't delete some of the "missing" files Logfile of HijackThis v1.99.1 Scan saved at 12:16:12 AM, on 3/20/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Kerio\Personal Firewall\persfw.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HHVcdV7Sys\VC7SecS.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\carpserv.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\HHVcdV7Sys\VC7Play.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\HijackThis.exe O2 - BHO: (no name) - {8E5A2506-A3B7-4219-8ED2-BCEB8FCA968E} - C:\WINDOWS\system32\urqrqnk.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\System32\cvyuqnmu.dll",setvm O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{FE5D1075-2381-4822-B8A4-FC932282EED1}: NameServer = 202.81.160.6 202.81.160.7 O20 - Winlogon Notify: urqrqnk - C:\WINDOWS\SYSTEM32\urqrqnk.dll O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!




You are running HJT directly from the E drive.
Create a folder called HJT either in C: or My documents or E drive and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .




Cannot delete all the files that are missing


Don't attempt that. If your referring to File missing in HJT it is a know bug. Just because HJT tells you there missing there not. You may end up deleting important files.

___________________________




Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
VundoFix V6.3.9 Checking Java version… Sun Java not detected Scan started at 5:55:42 PM 2/26/2007 Listing files found while scanning…. C:\WINDOWS\system32\djakjdgh.ini C:\WINDOWS\system32\hfaksfym.exe C:\WINDOWS\system32\hgdjkajd.dll C:\WINDOWS\system32\khyxfqrl.ini C:\WINDOWS\system32\lmsvydnp.dll C:\WINDOWS\system32\lrqfxyhk.dll C:\WINDOWS\System32\sstqp.dll C:\WINDOWS\system32\suctxpfb.dll Beginning removal… Attempting to delete C:\WINDOWS\system32\djakjdgh.ini C:\WINDOWS\system32\djakjdgh.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\hfaksfym.exe C:\WINDOWS\system32\hfaksfym.exe Has been deleted! Attempting to delete C:\WINDOWS\system32\hgdjkajd.dll C:\WINDOWS\system32\hgdjkajd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\khyxfqrl.ini C:\WINDOWS\system32\khyxfqrl.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\lmsvydnp.dll C:\WINDOWS\system32\lmsvydnp.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lrqfxyhk.dll C:\WINDOWS\system32\lrqfxyhk.dll Has been deleted! Attempting to delete C:\WINDOWS\System32\sstqp.dll C:\WINDOWS\System32\sstqp.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\suctxpfb.dll C:\WINDOWS\system32\suctxpfb.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.9 Checking Java version… Sun Java not detected Scan started at 9:19:49 AM 2/27/2007 Listing files found while scanning…. C:\WINDOWS\System32\suctxpfb.dll Beginning removal… Performing Repairs to the registry. Done! VundoFix V6.3.9 Checking Java version… Sun Java not detected Scan started at 4:28:18 PM 3/18/2007 Listing files found while scanning…. C:\WINDOWS\system32\amnhctjv.dll C:\WINDOWS\System32\ijkkj.bak2 C:\WINDOWS\System32\ijkkj.ini C:\WINDOWS\System32\jkkji.dll Beginning removal… Attempting to delete C:\WINDOWS\system32\amnhctjv.dll C:\WINDOWS\system32\amnhctjv.dll Has been deleted! Attempting to delete C:\WINDOWS\System32\ijkkj.bak2 C:\WINDOWS\System32\ijkkj.bak2 Has been deleted! Attempting to delete C:\WINDOWS\System32\ijkkj.ini C:\WINDOWS\System32\ijkkj.ini Has been deleted! Attempting to delete C:\WINDOWS\System32\jkkji.dll C:\WINDOWS\System32\jkkji.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.17 Checking Java version… Sun Java not detected Scan started at 9:17:12 PM 3/23/2007 Listing files found while scanning…. C:\WINDOWS\System32\accdd.ini C:\WINDOWS\system32\ddcaxvs.dll C:\WINDOWS\System32\ddcca.dll C:\WINDOWS\system32\ddccyxu.dll C:\WINDOWS\system32\gebbyvs.dll C:\WINDOWS\system32\jkkheef.dll C:\WINDOWS\system32\jkkljhg.dll C:\WINDOWS\system32\opnnmji.dll C:\WINDOWS\system32\pmnllif.dll C:\WINDOWS\system32\pmnmjkk.dll C:\WINDOWS\system32\pmnnolm.dll C:\WINDOWS\system32\tuvvuss.dll C:\WINDOWS\system32\urqqnno.dll C:\WINDOWS\system32\urqrqnk.dll C:\WINDOWS\system32\wvutrqp.dll C:\WINDOWS\system32\xxyaxwx.dll C:\WINDOWS\system32\xxyxuvv.dll VundoFix V6.3.17 Checking Java version… Sun Java not detected Scan started at 10:17:38 PM 3/23/2007 Listing files found while scanning…. C:\WINDOWS\System32\accdd.ini C:\WINDOWS\system32\ddcaxvs.dll C:\WINDOWS\System32\ddcca.dll C:\WINDOWS\system32\ddccyxu.dll C:\WINDOWS\system32\gebbyvs.dll C:\WINDOWS\system32\jkkheef.dll C:\WINDOWS\system32\jkkljhg.dll C:\WINDOWS\system32\opnnmji.dll C:\WINDOWS\system32\pmnllif.dll C:\WINDOWS\system32\pmnmjkk.dll C:\WINDOWS\system32\pmnnolm.dll C:\WINDOWS\system32\tuvvuss.dll C:\WINDOWS\system32\urqqnno.dll C:\WINDOWS\system32\urqrqnk.dll C:\WINDOWS\system32\wvutrqp.dll C:\WINDOWS\system32\xxyaxwx.dll C:\WINDOWS\system32\xxyxuvv.dll Beginning removal… Attempting to delete C:\WINDOWS\System32\accdd.ini C:\WINDOWS\System32\accdd.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\ddcaxvs.dll C:\WINDOWS\system32\ddcaxvs.dll Has been deleted! Attempting to delete C:\WINDOWS\System32\ddcca.dll C:\WINDOWS\System32\ddcca.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ddccyxu.dll C:\WINDOWS\system32\ddccyxu.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\gebbyvs.dll C:\WINDOWS\system32\gebbyvs.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\jkkheef.dll C:\WINDOWS\system32\jkkheef.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\jkkljhg.dll C:\WINDOWS\system32\jkkljhg.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\opnnmji.dll C:\WINDOWS\system32\opnnmji.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\pmnllif.dll C:\WINDOWS\system32\pmnllif.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll C:\WINDOWS\system32\pmnmjkk.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\pmnnolm.dll C:\WINDOWS\system32\pmnnolm.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\tuvvuss.dll C:\WINDOWS\system32\tuvvuss.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\urqqnno.dll C:\WINDOWS\system32\urqqnno.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\urqrqnk.dll C:\WINDOWS\system32\urqrqnk.dll Could not be deleted. Attempting to delete C:\WINDOWS\system32\wvutrqp.dll C:\WINDOWS\system32\wvutrqp.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyaxwx.dll C:\WINDOWS\system32\xxyaxwx.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\xxyxuvv.dll C:\WINDOWS\system32\xxyxuvv.dll Has been deleted! Performing Repairs to the registry. Done! Beginning removal… Attempting to delete C:\WINDOWS\system32\urqrqnk.dll C:\WINDOWS\system32\urqrqnk.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.17 Checking Java version… Sun Java not detected Scan started at 10:35:41 PM 3/23/2007 Listing files found while scanning…. Logfile of HijackThis v1.99.1 Scan saved at 10:43:21 PM, on 3/23/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe D:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Kerio\Personal Firewall\persfw.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HHVcdV7Sys\VC7SecS.exe C:\WINDOWS\System32\carpserv.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\HHVcdV7Sys\VC7Play.exe D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\System32\ctfmon.exe D:\Program Files\4t Tray Minimizer\4t-min.exe D:\Program Files\Virtual CD v7\System\VC7Tray.exe C:\Documents and Settings\Mama\Desktop\VundoFix.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {BDB42B49-A6B2-43A1-B4E7-C88146CB3A53} - C:\WINDOWS\System32\ddcca.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\System32\cvyuqnmu.dll",setvm O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: 4t Tray Minimizer.lnk = D:\Program Files\4t Tray Minimizer\4t-min.exe O8 - Extra context menu item: Download all with Free Download Manager - file://D:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://D:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://D:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{FE5D1075-2381-4822-B8A4-FC932282EED1}: NameServer = 209.58.80.5 209.58.80.7 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: avast! Antivirus - Unknown owner - D:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
Looking better.

You are still running hijackthis without placing it in it's own folder. If you mistakenly fix something with it it will not create a back up .

PLEASE!!! Do this now.

Open D drive
Right click anywhere in a blank area.
Choose new then folder
Place the hijackthis.exe file in that folder and run it from there from here on in.

I have seen mistakes made and people were glad we had a back up to restore from.



______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O2 - BHO: (no name) - {BDB42B49-A6B2-43A1-B4E7-C88146CB3A53} - C:\WINDOWS\System32\ddcca.dll (file missing)
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\System32\cvyuqnmu.dll",setvm
O8 - Extra context menu item: Download all with Free Download Manager - file://D:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://D:\Program Files\Free Download Manager\dllink.htm

___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.


___________________________________
Search for and remove
Now I want you to search for and delete the following folder and all it's contents if present. If you need help finding them.
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD

C:\WINDOWS\System32\cvyuqnmu.dll




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

Please download to your Desktop or to your usual Download Folder.
AVG Anti-Spyware
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________
It will save a log in C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Post that for me.
Exit AVG.
Reboot normaly.


__________________________

In your next reply I would like to see:
  • A new HJT log
  • The report from AVG antiMalware
I ignored dialupass2, I somewhat need it ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:12:20 PM 3/24/2007 + Scan result: C:\VundoFix Backups\ddcaxvs.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\ddccyxu.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\gebbyvs.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\jkkheef.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\jkkljhg.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\opnnmji.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\pmnllif.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\pmnmjkk.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\pmnnolm.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\tuvvuss.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\urqqnno.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\urqrqnk.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\wvutrqp.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\xxyaxwx.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\VundoFix Backups\xxyxuvv.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined). D:\backups\backup-20070320-001247-914.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). D:\backups\backup-20070320-001303-972.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). D:\backups\backup-20070320-001751-248.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). D:\backups\backup-20070320-162057-175.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Desktop\C-P\KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Desktop\Punks I.D. Creator\KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\Cache\BF1C933Cd01/Punks I.D. Creator/KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\Cache\E4E14255d01/C-P/KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\Cache\EC115647d01/just a toy/KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\WINDOWS\system32\KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\My Documents\Needs\dialupass2\dialupass.exe -> Not-A-Virus.PSWTool.Win32.Dialupass.f : Ignored and added to exceptions :mozilla.53:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.54:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.42:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.43:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.44:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.51:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.52:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.53:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.687:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Adobe : Cleaned. :mozilla.688:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Adobe : Cleaned. :mozilla.26:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.30:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.143:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.601:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Co : Cleaned. :mozilla.11:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.12:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.29:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.154:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.63:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned. :mozilla.64:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned. :mozilla.65:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned. :mozilla.95:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned. :mozilla.76:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.143:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.144:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.239:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.240:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.349:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.657:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.251:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned. :mozilla.85:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.474:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Netflame : Cleaned. :mozilla.79:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.34:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.414:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.61:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.756:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.8:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\i0w82ede.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.109:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Real : Cleaned. :mozilla.146:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.147:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.148:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.149:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.216:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.217:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.218:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.219:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.418:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.419:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.420:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.421:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.70:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.150:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.151:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.152:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.233:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.234:C:\Documents and Settings\Yam\Application Data\Mozilla\Firefox\Profiles\lojcnjud.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.436:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.437:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.438:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.605:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.72:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.36:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.25:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Toplist : Cleaned. :mozilla.163:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.93:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.98:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.101:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.104:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.640:C:\Documents and Settings\Fil\Application Data\Mozilla\Firefox\Profiles\1t74svd8.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.41:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.42:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.43:C:\Documents and Settings\Mama\Application Data\Mozilla\Firefox\Profiles\90jyz9h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.45:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.46:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.51:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.52:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ex76g6dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4WT6OCZ2\teller2[1].htm -> Trojan.Small : Cleaned with backup (quarantined). C:\Shakugan no Shana\Temp.Htt -> Worm.VB.nei : Cleaned with backup (quarantined). ::Report end Logfile of HijackThis v1.99.1 Scan saved at 3:21:42 PM, on 3/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe D:\Program Files\Alwil Software\Avast4\ashServ.exe D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\Kerio\Personal Firewall\persfw.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\HHVcdV7Sys\VC7SecS.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\carpserv.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\HHVcdV7Sys\VC7Play.exe D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Hijack\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [CARPService] carpserv.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [VC7Player] C:\Program Files\HHVcdV7Sys\VC7Play.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: Download all with Free Download Manager - file://D:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://D:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://D:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{FE5D1075-2381-4822-B8A4-FC932282EED1}: NameServer = 209.58.80.5 209.58.80.7 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: avast! Antivirus - Unknown owner - D:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing) O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
Good call on adding that file to exceptions..Known false positive.


___________________________________
You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6
  • Scroll down to where it says "Java Runtime Environment (JRE) 6… allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

Optional fix
nwiz.exe is a part of NVidia's Nview features installable alongside its graphics hardware products. This application will give the user access to additional features which allow the configuration of up to 32 monitors on a host or to expand the desktop across many monitors. This program is not required to start automatically as you can start it manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis. This is the item to fix in HijackThis:

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


______________________________

Post 1 more HJT log and let me know how things are running now.
After I've done running AVG anti-spyware, my direct3d went crazy and my games won't work well


[external image: Posted Image]
Did you run avg again ? Not that this should of done anything. I have look through the log and I do not see any signs of it removing any important files <_< . From the picture it may be drivers video drivers went wonky. Can you tell me what video card you have? If you know how go to the manufacturers web site and see if there are new drivers available for you. If not redownload the drivers and reinstall them. If you need help in doing this let me know. More than happy to help.
Lets see this.
Click start /run and copy this in
dxdiag

Wait for the progress bar on the bottom right to fully load.

Now click on the save all information button.

Save it to your desktop as dxdiag.txt

Post that log for me please.

Oh sorry, fixed this already by installing my motherboard again


Are you going to reformat also ??
Or will you still need help cleaning up the hardrive?

Oh sorry, i'm only using dial up so i don't really have the time to download it completely

BTW, i'm not going to reformat



Download what ?


Your last log looked clean..You just needed to update Java for security reasons.
Yes malware can use outdated Java to attack your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI