This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log Help

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run all the prerequisite utilities and they really helped. However, there is still some malware lingering as my McAfee antivirus continues to stop suspect programs from running. Attached are the Hijack this logs and AVG Anti-Spyware report.

Thanks, Giovanni

HiJack Log

Logfile of HijackThis v1.99.1
Scan saved at 11:27:31 AM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - C:\WINDOWS\system32\efcdbab.dll (file missing)
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - C:\WINDOWS\system32\ddcya.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {320F26E1-8F10-4143-B433-B2DB14896D1F} - c:\windows\system\fontdisk.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\vmnqxtwa.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\system32\hnxnmjmk.dll",realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.m033002
O15 - Trusted Zone: http://*.m033028
O15 - Trusted Zone: http://m033002.sct.com
O15 - Trusted Zone: http://m033028.sct.com
O15 - Trusted IP range: http://149.24.33.2
O15 - Trusted IP range: http://149.24.33.51
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: fontdisk - c:\windows\system\fontdisk.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

AVG LOG

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:04:18 AM 6/4/2007

+ Scan result:



C:\WINDOWS\system32\efcawwv.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\efcdbab.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\gebbxwv.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\pmnonkk.dll -> Adware.Virtumonde : No action taken.
[1196] C:\WINDOWS\system32\ddcya.dll -> Adware.Virtumonde : No action taken.
[652] C:\WINDOWS\system32\efcdbab.dll -> Adware.Virtumonde : No action taken.
C:\System Volume Information\_restore{1FCBB1B4-8C17-4AB8-BF14-DBA8E3236CB8}\RP289\A0055259.exe -> Dropper.Agent.mu : No action taken.
C:\Documents and Settings\spiterig\Local Settings\Temporary Internet Files\Content.IE5\X7C18CH5\ErrorSafeFreeInstallW[1].cab/UERS_9999_N91S1502NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\UERS_9999_N91S1502NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\spiterig\Local Settings\Temp\WinAntiVirusPro2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.u : No action taken.
:mozilla.105:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.11:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.12:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.13:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.14:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.15:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.160:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.16:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.17:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.18:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.19:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.350:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.78:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.478:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Abcsearch : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : No action taken.
:mozilla.326:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.25:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.23:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Adengage : No action taken.
:mozilla.450:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.451:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.452:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adobe : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Adocean : No action taken.
:mozilla.491:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.75:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.400:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Cnn : No action taken.
:mozilla.89:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\spiterig\Cookies\spiterig@connextra[2].txt -> TrackingCookie.Connextra : No action taken.
:mozilla.92:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.93:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.94:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.95:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\spiterig\Cookies\spiterig@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.396:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Cqcounter : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Dbbsrv : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Dealtime : No action taken.
:mozilla.129:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Enhance : No action taken.
:mozilla.130:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Enhance : No action taken.
:mozilla.133:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Epilot : No action taken.
:mozilla.24:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.45:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.175:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.176:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
C:\Documents and Settings\spiterig\Cookies\spiterig@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Live : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.427:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Msn : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
:mozilla.247:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Navrcholu : No action taken.
:mozilla.457:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.458:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.459:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.460:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.461:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.26:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.27:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.28:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.29:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.275:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pro-market : No action taken.
:mozilla.276:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Pro-market : No action taken.
C:\Documents and Settings\spiterig\Cookies\spiterig@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.288:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.289:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.290:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.291:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.432:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.297:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.298:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.299:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.300:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.301:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.302:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Starware : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Starware : No action taken.
:mozilla.329:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.408:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.334:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Toplist : No action taken.
C:\Documents and Settings\spiterig\Cookies\spiterig@toplist[1].txt -> TrackingCookie.Toplist : No action taken.
:mozilla.337:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.338:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.339:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.341:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.292:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.293:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.294:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.295:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.296:C:\Documents and Settings\spiterig\Application Data\Mozilla\Firefox\Profiles\lnlssskx.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\spiterig\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : No action taken.


::Report end
gspiteri,

It looks like you are running an older version of HJT, do this and when you post I need to see the entire log including the header.


Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis


  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go Format and make sure Wordwrap is unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use [external image: Posted Image]and not [external image: Posted Image]
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.




Now go to C:\Program Files\Hijackthis , open the folder and right click on the HJT icon ( looks like a red stick of dynamite with a plunger ) and rename it to Scanner.exe <– Don't forget the .exe

Now post an entire new HJT log with it renamed to Scanner.exe
Ken - Here you go - Gio


Logfile of HijackThis v1.99.1
Scan saved at 1:44:07 PM, on 6/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
c:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - C:\WINDOWS\system32\efcdbab.dll (file missing)
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - C:\WINDOWS\system32\ddcya.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {320F26E1-8F10-4143-B433-B2DB14896D1F} - c:\windows\system\fontdisk.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\vmnqxtwa.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\system32\hnxnmjmk.dll",realset
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.m033002
O15 - Trusted Zone: http://*.m033028
O15 - Trusted Zone: http://m033002.sct.com
O15 - Trusted Zone: http://m033028.sct.com
O15 - Trusted IP range: http://149.24.33.2
O15 - Trusted IP range: http://149.24.33.51
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: fontdisk - c:\windows\system\fontdisk.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe

Scanner.exe File
Logfile of HijackThis v1.99.1
Scan saved at 1:47:32 PM, on 6/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
c:\Program Files\Cisco Systems\VPN Client\vpngui.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2432F099-F8E2-43C9-B765-3AF002FFC6A7} - C:\WINDOWS\system32\efcdbab.dll (file missing)
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - C:\WINDOWS\system32\ddcya.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {320F26E1-8F10-4143-B433-B2DB14896D1F} - c:\windows\system\fontdisk.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\vmnqxtwa.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\system32\hnxnmjmk.dll",realset
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.m033002
O15 - Trusted Zone: http://*.m033028
O15 - Trusted Zone: http://m033002.sct.com
O15 - Trusted Zone: http://m033028.sct.com
O15 - Trusted IP range: http://149.24.33.2
O15 - Trusted IP range: http://149.24.33.51
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: fontdisk - c:\windows\system\fontdisk.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
Lets run the tool to remove vundo,


Download VundoFix to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on
reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when
VundoFix appears upon rebooting.


Let me see the Vundofix log and a new HJT log, there may be more to do.
Here is the latest HJT file. McAffe was not able to Quarantine Vundo, but I believe your program removed it.

Logfile of HijackThis v1.99.1
Scan saved at 12:25:40 PM, on 6/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Hijackthis\Hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - C:\WINDOWS\system32\ddcya.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {320F26E1-8F10-4143-B433-B2DB14896D1F} - c:\windows\system\fontdisk.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.m033002
O15 - Trusted Zone: http://*.m033028
O15 - Trusted Zone: http://m033002.sct.com
O15 - Trusted Zone: http://m033028.sct.com
O15 - Trusted IP range: http://149.24.33.2
O15 - Trusted IP range: http://149.24.33.51
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
gspiteri :D

You need to read the instructions through and follow them, I can't help you if you don't follow the instructions and post the reports I ask for. Vundo is still present If I saw the report I could see which files were deleted and which ones were not.

Delete the Vundofix program and download a fresh copy because those files should have been removed.

Download VundoFix to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread. <– Do this
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.



Do this also.
Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer
Run this system cleaner after you run the Vundofix.
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Let me see the Vundofix Log and a New HJT log .
I followed the instruction to the T! :wavey:


HIJACK LOG
Logfile of HijackThis v1.99.1
Scan saved at 2:23:03 PM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Hijackthis\Hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - (no file)
O2 - BHO: (no name) - {320F26E1-8F10-4143-B433-B2DB14896D1F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe


VUNDO
undoFix V6.4.2

Checking Java version…

Java version is 1.4.2.2
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:45:19 AM 6/6/2007

Listing files found while scanning….

c:\windows\system\fontdisk.dll
C:\WINDOWS\system32\aycdd.bak1
C:\WINDOWS\system32\aycdd.bak2
C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\aycdd.tmp
C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\efcdbab.dll
C:\WINDOWS\system32\hnxnmjmk.dll
C:\WINDOWS\system32\kmjmnxnh.ini
C:\WINDOWS\system32\vmnqxtwa.dll

Beginning removal…

Attempting to delete c:\windows\system\fontdisk.dll
c:\windows\system\fontdisk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aycdd.bak1
C:\WINDOWS\system32\aycdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\aycdd.bak2
C:\WINDOWS\system32\aycdd.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\aycdd.ini
C:\WINDOWS\system32\aycdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\aycdd.ini2
C:\WINDOWS\system32\aycdd.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\aycdd.tmp
C:\WINDOWS\system32\aycdd.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\hnxnmjmk.dll
C:\WINDOWS\system32\hnxnmjmk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kmjmnxnh.ini
C:\WINDOWS\system32\kmjmnxnh.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\vmnqxtwa.dll
C:\WINDOWS\system32\vmnqxtwa.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.4.2

Checking Java version…

Java version is 1.4.2.2
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 1:15:23 PM 6/8/2007

Listing files found while scanning….

C:\WINDOWS\system32\ddcya.dll

Beginning removal…

Performing Repairs to the registry.
Done!
Thats better , Vundo was removed :thumbup:

Go to C:\Program Files\HijackThis and open the folder and right click on the HJT Icon, (looks like a red stick of dynamite with a plunger) and rename it to Scanner.exe. <– Don't forget the .exe and post a new log.
Here you go! Thanks for all the help. Gio

Logfile of HijackThis v1.99.1
Scan saved at 12:03:08 PM, on 6/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - (no file)
O2 - BHO: (no name) - {320F26E1-8F10-4143-B433-B2DB14896D1F} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
How ya doing??

Remove these with HJT.

O2 - BHO: (no name) - {26D916B2-D99D-4EAF-A48E-45788D124015} - (no file)
O2 - BHO: (no name) - {320F26E1-8F10-4143-B433-B2DB14896D1F} - (no file)
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll

O20 - Winlogon Notify: ddcya - C:\WINDOWS\system32\ddcya.dll (file missing)
O20 - Winlogon Notify: efcdbab - efcdbab.dll (file missing)




Download Pocket Killbox to your desktop.

Highlight all the files with the complete path inside the quote and press Ctrl C on your keyboard.
  • C:\WINDOWS\system32\ddcya.dll
    C:\WINDOWS\system32\efcdbab.dll
    C:\WINDOWS\system32\gaydmccv.dll


  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes
If you get a message "pending operations has been stopped by external process!" then reboot the computer manually.

Post a new log please.
Ken - Here you go. Sorry for the late response I took an extended weekend. Gio

Logfile of HijackThis v1.99.1
Scan saved at 6:58:25 PM, on 6/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\WINDOWS\system32\TpScrLk.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Hijackthis\Hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www-proxy.sct.com:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll (file missing)
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_02\bin\npjpi142_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00D9C306-6B11-492A-9AFC-C53CE30849CF} (Siebel SmartScript) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Smartscript.cab
O16 - DPF: {06314967-EECF-11D2-9D64-0000949887BE} (Siebel ERM eBriefings Offline Content Synchronization Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_ERM_ContentSync.cab
O16 - DPF: {07070BFD-C501-4899-934D-0B96A9F70795} (Siebel Option Pack for IE 7.5.3) - http://sahara.inquira.com/callcenter_enu/1…lOptionPack.cab
O16 - DPF: {0D68687A-A2A3-46EB-9ED9-956C83875A6C} (Siebel Marketing HTML Editor) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_HTML_Editor.cab
O16 - DPF: {169ADD4B-EE8B-4B27-B332-2941A82DA7E2} (Siebel Microsite Layout Designer) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Microsite_Layout.cab
O16 - DPF: {16C7BBB7-738A-47D7-956E-52DD9A166A9A} (Siebel Event Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Calendar.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1C1DE932-8D89-4C07-BF9C-D8627EDB4849} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/18372/applets…x_HI_Client.cab
O16 - DPF: {1D922C61-16AB-4179-8302-6B8A688C88D0} (CSSAxContainerCtrl Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Container_Control.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {353F130D-72DB-4F14-B750-625F90D75D1B} (Siebel Test Automation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Test_Automation.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://sctmnot4.sct.com/iNotes6W.cab
O16 - DPF: {3E8C4740-70C5-439E-AE2F-16234083E248} (Siebel High Interactivity Framework) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_HI_Client.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.apple.com.edgesuite.net/qt…meInstaller.exe
O16 - DPF: {48CE1C1F-092D-461C-A385-A0C3D19FE052} (Siebel iHelp) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_iHelp.cab
O16 - DPF: {48D5324D-D593-47DF-AAE4-18CB09F1F86F} (Siebel High Interactivity Framework) - http://spiterig1.inforte.com/19224/applets…x_HI_Client.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re…es/MsnPUpld.cab
O16 - DPF: {519B48ED-2242-4F0F-A1F6-65B3A505972D} (Pslocalr Class) - https://opus.sct.com/opus/docs/pslocalr.dll
O16 - DPF: {5FCAD8CF-85C1-4FD9-BD04-995CBEBA5BEB} (Siebel Hospitality Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Hospitality_Gantt.cab
O16 - DPF: {73EF83D1-DA75-4F58-8DB6-1CD6D8F9C8A1} (Siebel Calendar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Calendar.cab
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - https://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {756E01C3-2CF9-4364-8724-B8C850CB0D50} (UInboxDynBtn Class) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_UInbox.cab
O16 - DPF: {76E5AF9D-2B3E-4FEB-A31F-A9E63A27FA29} (IASRunner Class) - https://www-307.ibm.com/pc/support/access/a…ntent/AcpIR.cab
O16 - DPF: {8C244272-1DC1-4CE7-9C6C-FABCA09EB543} (Siebel Desktop Integration) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Desktop_Integration.cab
O16 - DPF: {959B5F63-7654-4BED-B2C3-B7CD543FF6E6} (Siebel Gantt Chart) - http://crm.sct.com/marketing/18372/applets…Gantt_Chart.cab
O16 - DPF: {96A3E5AB-C228-4D1D-B31F-712BA35EE470} (Siebel Gantt Chart) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Gantt_Chart.cab
O16 - DPF: {C5FEEC93-506D-4B41-A38B-3A59BF5B41AB} (Siebel Callcenter Communications Toolbar) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_CTI_Toolbar.cab
O16 - DPF: {C657D5D2-D725-4F0E-91A9-EA74647DCF84} (Siebel Marketing Allocation) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_Marketing_Allocation.cab
O16 - DPF: {D6CC2526-859B-40C0-8515-1A47946478B6} (Siebel Email Support for Microsoft Outlook and Lotus Notes) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\SiebelAx_OutBound_mail.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://genentech.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {EFB7D763-97A3-11CF-AE19-00608CEADE00} (CIC Ink Control) - file://C:\Program Files\Siebel\7.8\web client\PUBLIC\enu\19213\applets\iTools.cab
O16 - DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} (Livelink ActiveX Control) - http://genell/support/webedit/lledit.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\Software\..\Telephony: DomainName = inforte.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = inforte.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = inforte.com
O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.5.0.464.dll
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
Not a problem with the reply.

Make sure your disconnected from the internet and the only program you have open is HJT and fix this entry.

O2 - BHO: (no name) - {83D00848-6184-463B-BB84-23E77AB5E40a} - C:\WINDOWS\system32\gaydmccv.dll (file missing)

You can also browse through all the 016 entries and remove any that you are not using or don't know about, you won't harm anything by removing them, you will just be prompted to download them again the next time you use the site.

Please keep HJT renamed to Scanner.exe so I can see if any of vundo has come back.


When you ran AVG Anti Spyware you had it set to TAKE NO ACTION so none of it was removed, run the program again, this will show if there is any of it left , make sure to have it set to Remove or Quarantine what it finds and to let me see the report so be sure to save it.



Make sure you follow these instructions correctly to Remove or Quarantine what it finds and also to save the report, without me seeing the report my hands are tied.
Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system <–Don't forget this
  • make sure to remember where you saved that file, this is important, I need to see that log.
  • Close AVG Anti-Spyware 7.5

Let me see the AVG Report and a New HJT log renamed to Scanner.exe
New version of AVG Anti Spyware , remove the other one you downloaded via the Add Remove Programs in the Control Panel , then install this one and it should run in Safemode.

AVG Anti-Spyware 7.5.1.43

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI