This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Please Help!

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me out with my Hijack This logs. I've recently downloaded the program along with Spybot S&D because I felt my computer was seriously lagging and running a lot slower than normal (even though it is an older model). I've posted my logs below. Any help would be more than greatly appreciated!!!! Thanks!



Logfile of HijackThis v1.99.1
Scan saved at 2:56:52 PM, on 8/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://aimtoday.aol.com/today/aimtoday.adp…68&nlogin=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.hotmail.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\aqvhw6wo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\aqvhw6wo.slt\prefs.js)
O2 - BHO: (no name) - {0B1EDEB6-897D-02BF-11AF-9F1EE56199D6} - (no file)
O2 - BHO: (no name) - {1354B9A5-F0D9-43ED-B747-0732726D89C0} - C:\WINDOWS\System32\ssqrr.dll
O2 - BHO: (no name) - {322B3263-4125-83BC-EA0A-3B07AB10E29B} - (no file)
O2 - BHO: (no name) - {44B14A5D-EF05-8A73-645F-321A1D3DA204} - (no file)
O2 - BHO: (no name) - {4EDC72D6-1677-BA8E-A3E9-F6CD337060DB} - (no file)
O2 - BHO: (no name) - {5092ADF3-9DA6-E4D4-FEFF-77B4A9B7DC70} - (no file)
O2 - BHO: (no name) - {52BC631D-9C1A-0E41-A49D-4D4FD49D830C} - (no file)
O2 - BHO: (no name) - {52E6830C-594F-0652-97BC-4BEF29128B11} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {539322FC-A50C-270C-A3BD-3515AA26634A} - (no file)
O2 - BHO: Class - {57DB0F9C-95AA-F3DB-A422-DF9CC22B2876} - (no file)
O2 - BHO: (no name) - {5AEDA511-0157-5F17-AC3D-A3D8D05DFE0C} - (no file)
O2 - BHO: Class - {5D6A3C38-325C-B883-7058-D8512D537117} - C:\WINDOWS\system32\appys32.dll
O2 - BHO: Class - {5F2480E5-41C5-F1D2-7B6F-5DF83C9B61F6} - (no file)
O2 - BHO: Class - {67963C46-D4CE-3BFC-A231-2102B037FC9B} - (no file)
O2 - BHO: (no name) - {681772EF-1514-33C7-0408-B8771F24D4CB} - (no file)
O2 - BHO: (no name) - {71167969-C63A-6FB0-2E12-19AC38D1B9B1} - (no file)
O2 - BHO: Class - {723A508C-C0DA-A207-D99C-49CB499D8E4B} - (no file)
O2 - BHO: (no name) - {750FF540-4850-123F-C121-7AEF5710EE3A} - (no file)
O2 - BHO: (no name) - {877B5096-0FB9-2632-5448-A94D5150B850} - (no file)
O2 - BHO: (no name) - {90B46B07-282D-8DDE-D296-452CDBB0603B} - (no file)
O2 - BHO: Class - {9CE33963-05DF-7E69-EC6A-2B29B35EAE5A} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
O2 - BHO: (no name) - {AD558823-F711-D52F-CF3D-E2058029C0DD} - (no file)
O2 - BHO: (no name) - {B9B34100-D040-0B2A-82D1-D1F5061D5342} - (no file)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\System32\mfmjyurj.dll
O2 - BHO: (no name) - {C8F7745A-EDC7-09F6-2A66-3DBD317341D5} - (no file)
O2 - BHO: (no name) - {CC358019-D328-40B4-8E2D-818CE142616C} - C:\WINDOWS\System32\yaywtrq.dll
O2 - BHO: Class - {D3DD24BD-375D-1229-E7E9-92878A1D7DBE} - (no file)
O2 - BHO: (no name) - {D74BCADB-C0DA-FC8B-4B57-102D803A3C3B} - (no file)
O2 - BHO: Class - {E70BCFE8-4567-8803-D4D5-7B3E4E06E85F} - (no file)
O2 - BHO: (no name) - {F0E095A0-3EA9-8479-E393-7CB483F3BC0D} - (no file)
O2 - BHO: (no name) - {F76604BF-96C5-81C9-07E5-094D1BB88043} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [appvl.exe] C:\WINDOWS\system32\appvl.exe
O4 - HKLM\..\Run: [msrs.exe] C:\WINDOWS\system32\msrs.exe
O4 - HKLM\..\Run: [sdkws32.exe] C:\WINDOWS\system32\sdkws32.exe
O4 - HKLM\..\Run: [appxd.exe] C:\WINDOWS\system32\appxd.exe
O4 - HKLM\..\Run: [wincz.exe] C:\WINDOWS\system32\wincz.exe
O4 - HKLM\..\Run: [javalp32.exe] C:\WINDOWS\javalp32.exe
O4 - HKLM\..\Run: [atlvv32.exe] C:\WINDOWS\atlvv32.exe
O4 - HKLM\..\Run: [appqp32.exe] C:\WINDOWS\appqp32.exe
O4 - HKLM\..\Run: [netkx32.exe] C:\WINDOWS\system32\netkx32.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [addaw.exe] C:\WINDOWS\system32\addaw.exe
O4 - HKLM\..\Run: [ienc.exe] C:\WINDOWS\system32\ienc.exe
O4 - HKLM\..\Run: [d3es.exe] C:\WINDOWS\d3es.exe
O4 - HKLM\..\Run: [sdkuh.exe] C:\WINDOWS\sdkuh.exe
O4 - HKLM\..\Run: [ipxr32.exe] C:\WINDOWS\ipxr32.exe
O4 - HKLM\..\Run: [winki.exe] C:\WINDOWS\system32\winki.exe
O4 - HKLM\..\Run: [ipck32.exe] C:\WINDOWS\system32\ipck32.exe
O4 - HKLM\..\Run: [addim32.exe] C:\WINDOWS\addim32.exe
O4 - HKLM\..\Run: [ntlw.exe] C:\WINDOWS\ntlw.exe
O4 - HKLM\..\Run: [atlsb32.exe] C:\WINDOWS\atlsb32.exe
O4 - HKLM\..\Run: [winto.exe] C:\WINDOWS\system32\winto.exe
O4 - HKLM\..\Run: [netxd32.exe] C:\WINDOWS\system32\netxd32.exe
O4 - HKLM\..\Run: [atlfa32.exe] C:\WINDOWS\atlfa32.exe
O4 - HKLM\..\Run: [sysyt.exe] C:\WINDOWS\sysyt.exe
O4 - HKLM\..\Run: [d3go.exe] C:\WINDOWS\system32\d3go.exe
O4 - HKLM\..\Run: [sysum32.exe] C:\WINDOWS\system32\sysum32.exe
O4 - HKLM\..\Run: [d3is32.exe] C:\WINDOWS\d3is32.exe
O4 - HKLM\..\Run: [apiuj.exe] C:\WINDOWS\system32\apiuj.exe
O4 - HKLM\..\Run: [apied32.exe] C:\WINDOWS\apied32.exe
O4 - HKLM\..\Run: [syszx32.exe] C:\WINDOWS\syszx32.exe
O4 - HKLM\..\Run: [apikb32.exe] C:\WINDOWS\apikb32.exe
O4 - HKLM\..\Run: [ntbb.exe] C:\WINDOWS\ntbb.exe
O4 - HKLM\..\Run: [crju32.exe] C:\WINDOWS\crju32.exe
O4 - HKLM\..\Run: [appni.exe] C:\WINDOWS\appni.exe
O4 - HKLM\..\Run: [sdkto.exe] C:\WINDOWS\system32\sdkto.exe
O4 - HKLM\..\Run: [atljd32.exe] C:\WINDOWS\atljd32.exe
O4 - HKLM\..\Run: [atlxa.exe] C:\WINDOWS\atlxa.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\wwoytiei.dll",forkonce
O4 - HKLM\..\RunOnce: [SpybotDeletingA7370] command /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6436] cmd /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/P…00001e.0000004a
O4 - HKCU\..\RunOnce: [SpybotDeletingB1839] command /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6381] cmd /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll
O15 - Trusted Zone: *.att.net
O15 - Trusted Zone: http://*.att.net
O15 - Trusted Zone: *.sbcglobal.net
O15 - Trusted Zone: http://*.sbcglobal.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqrr - C:\WINDOWS\System32\ssqrr.dll
O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll
O20 - Winlogon Notify: yaywtrq - C:\WINDOWS\SYSTEM32\yaywtrq.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: MPService - Unknown owner - C:\Program Files\Canon\MultiPASS\mpservic.exe (file missing)
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\Owner\Desktop\SFUninstaller.exe" service (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)






StartupList report, 8/19/2007, 3:02:47 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Owner\Desktop\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
appvl.exe = C:\WINDOWS\system32\appvl.exe
msrs.exe = C:\WINDOWS\system32\msrs.exe
sdkws32.exe = C:\WINDOWS\system32\sdkws32.exe
appxd.exe = C:\WINDOWS\system32\appxd.exe
wincz.exe = C:\WINDOWS\system32\wincz.exe
javalp32.exe = C:\WINDOWS\javalp32.exe
atlvv32.exe = C:\WINDOWS\atlvv32.exe
appqp32.exe = C:\WINDOWS\appqp32.exe
netkx32.exe = C:\WINDOWS\system32\netkx32.exe
BJCFD = C:\Program Files\BroadJump\Client Foundation\CFD.exe
AlcxMonitor = ALCXMNTR.EXE
addaw.exe = C:\WINDOWS\system32\addaw.exe
ienc.exe = C:\WINDOWS\system32\ienc.exe
d3es.exe = C:\WINDOWS\d3es.exe
sdkuh.exe = C:\WINDOWS\sdkuh.exe
ipxr32.exe = C:\WINDOWS\ipxr32.exe
winki.exe = C:\WINDOWS\system32\winki.exe
ipck32.exe = C:\WINDOWS\system32\ipck32.exe
addim32.exe = C:\WINDOWS\addim32.exe
ntlw.exe = C:\WINDOWS\ntlw.exe
atlsb32.exe = C:\WINDOWS\atlsb32.exe
winto.exe = C:\WINDOWS\system32\winto.exe
netxd32.exe = C:\WINDOWS\system32\netxd32.exe
atlfa32.exe = C:\WINDOWS\atlfa32.exe
sysyt.exe = C:\WINDOWS\sysyt.exe
d3go.exe = C:\WINDOWS\system32\d3go.exe
sysum32.exe = C:\WINDOWS\system32\sysum32.exe
d3is32.exe = C:\WINDOWS\d3is32.exe
apiuj.exe = C:\WINDOWS\system32\apiuj.exe
apied32.exe = C:\WINDOWS\apied32.exe
syszx32.exe = C:\WINDOWS\syszx32.exe
apikb32.exe = C:\WINDOWS\apikb32.exe
ntbb.exe = C:\WINDOWS\ntbb.exe
crju32.exe = C:\WINDOWS\crju32.exe
appni.exe = C:\WINDOWS\appni.exe
sdkto.exe = C:\WINDOWS\system32\sdkto.exe
atljd32.exe = C:\WINDOWS\atljd32.exe
atlxa.exe = C:\WINDOWS\atlxa.exe
SystemOptimizer = rundll32.exe "C:\WINDOWS\System32\wwoytiei.dll",forkonce

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

SpybotDeletingA7370 = command /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"
SpybotDeletingC6436 = cmd /c del "C:\WINDOWS\n_ymzfxk.dat_tobedeleted"

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Download Program Files:

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\xscan60.ocx
CODEBASE = http://housecall60.trendmicro.com/housecall/xscan60.cab

[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINDOWS\n_ymzfxk.dat_tobedeleted|||x

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 5,725 bytes
Report generated in 0.094 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

You currently are running HijackThis from here:

C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\


Please make a folder here:
c:\HJT
and place HijackThis in that folder.

DO NOT follow the steps below until you have moved HijackThis

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

You have no anti-virus on your computer. It is important you install one now before we continue with your fix. Check this out for a list of free AV scanners, AVG is highly recommended
Thank you for the fast response!!! I did what you said about creating the folder for HJT. However, your next instruction told me to open a uninstall list and save it and copy and paste it here. The only problem is that everytime I hit the "save" button, the entire HJT program and Folder as well both disappear as if the process was terminated or something. I have tried several times to see if it might have been something I did or if I had a process running that might have interfered, but i get the same result every time. So I am unable to generate that uninstall list for you as of right now. I then followed your advice about installing a virus scan software. I had Norton 2006 on here for a little while, but the installation was corrupt and wouldnt allow me to fix things properly or even uninstall it, so I recently followed internet prompts to uninstall it completely a few days ago. That is why I didnt have any virus protection. However, like I said, I took your advice and installed AVG and ran it. Seveal "threats" were detected and I have moved them "to the vault". Is it necessary for me to now run another HJT log for you? Thanks again for any continued help!
well i apologize, but since my last post i have been able to pull up the uninstall list. since the AVG program has been running as well it has prompted me to "Vault" several "threats" so I have done so. In doing that, I have created new logs up to this point so that I can keep you up to date and from here on out I will ignore or do nothing until you prompt me to otherwise.

Logfile of HijackThis v1.99.1
Scan saved at 9:37:36 PM, on 8/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\gackz.dll/sp.html#37049%
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://aimtoday.aol.com/today/aimtoday.adp…68&nlogin=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.hotmail.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\aqvhw6wo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\aqvhw6wo.slt\prefs.js)
O2 - BHO: (no name) - {0B1EDEB6-897D-02BF-11AF-9F1EE56199D6} - (no file)
O2 - BHO: (no name) - {147ECC61-5187-4D53-BC69-D7143D8E3456} - C:\WINDOWS\System32\ssqrr.dll (file missing)
O2 - BHO: (no name) - {322B3263-4125-83BC-EA0A-3B07AB10E29B} - (no file)
O2 - BHO: (no name) - {44B14A5D-EF05-8A73-645F-321A1D3DA204} - (no file)
O2 - BHO: (no name) - {4EDC72D6-1677-BA8E-A3E9-F6CD337060DB} - (no file)
O2 - BHO: (no name) - {5092ADF3-9DA6-E4D4-FEFF-77B4A9B7DC70} - (no file)
O2 - BHO: (no name) - {52BC631D-9C1A-0E41-A49D-4D4FD49D830C} - (no file)
O2 - BHO: (no name) - {52E6830C-594F-0652-97BC-4BEF29128B11} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {539322FC-A50C-270C-A3BD-3515AA26634A} - (no file)
O2 - BHO: Class - {57DB0F9C-95AA-F3DB-A422-DF9CC22B2876} - (no file)
O2 - BHO: (no name) - {5AEDA511-0157-5F17-AC3D-A3D8D05DFE0C} - (no file)
O2 - BHO: Class - {5D6A3C38-325C-B883-7058-D8512D537117} - C:\WINDOWS\system32\appys32.dll
O2 - BHO: Class - {5F2480E5-41C5-F1D2-7B6F-5DF83C9B61F6} - (no file)
O2 - BHO: Class - {67963C46-D4CE-3BFC-A231-2102B037FC9B} - (no file)
O2 - BHO: (no name) - {681772EF-1514-33C7-0408-B8771F24D4CB} - (no file)
O2 - BHO: (no name) - {71167969-C63A-6FB0-2E12-19AC38D1B9B1} - (no file)
O2 - BHO: Class - {723A508C-C0DA-A207-D99C-49CB499D8E4B} - (no file)
O2 - BHO: Class - {740EFDF9-C3B0-986E-D595-83C15B23083A} - C:\WINDOWS\ntpt32.dll
O2 - BHO: (no name) - {750FF540-4850-123F-C121-7AEF5710EE3A} - (no file)
O2 - BHO: (no name) - {877B5096-0FB9-2632-5448-A94D5150B850} - (no file)
O2 - BHO: (no name) - {90B46B07-282D-8DDE-D296-452CDBB0603B} - (no file)
O2 - BHO: Class - {9CE33963-05DF-7E69-EC6A-2B29B35EAE5A} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
O2 - BHO: (no name) - {AD558823-F711-D52F-CF3D-E2058029C0DD} - (no file)
O2 - BHO: (no name) - {B9B34100-D040-0B2A-82D1-D1F5061D5342} - (no file)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\System32\uyisujoc.dll
O2 - BHO: (no name) - {C8F7745A-EDC7-09F6-2A66-3DBD317341D5} - (no file)
O2 - BHO: (no name) - {CC358019-D328-40B4-8E2D-818CE142616C} - C:\WINDOWS\System32\yaywtrq.dll (file missing)
O2 - BHO: Class - {D3DD24BD-375D-1229-E7E9-92878A1D7DBE} - (no file)
O2 - BHO: (no name) - {D74BCADB-C0DA-FC8B-4B57-102D803A3C3B} - (no file)
O2 - BHO: Class - {E70BCFE8-4567-8803-D4D5-7B3E4E06E85F} - (no file)
O2 - BHO: (no name) - {F0E095A0-3EA9-8479-E393-7CB483F3BC0D} - (no file)
O2 - BHO: (no name) - {F76604BF-96C5-81C9-07E5-094D1BB88043} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [appvl.exe] C:\WINDOWS\system32\appvl.exe
O4 - HKLM\..\Run: [msrs.exe] C:\WINDOWS\system32\msrs.exe
O4 - HKLM\..\Run: [sdkws32.exe] C:\WINDOWS\system32\sdkws32.exe
O4 - HKLM\..\Run: [appxd.exe] C:\WINDOWS\system32\appxd.exe
O4 - HKLM\..\Run: [wincz.exe] C:\WINDOWS\system32\wincz.exe
O4 - HKLM\..\Run: [atlvv32.exe] C:\WINDOWS\atlvv32.exe
O4 - HKLM\..\Run: [appqp32.exe] C:\WINDOWS\appqp32.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [addaw.exe] C:\WINDOWS\system32\addaw.exe
O4 - HKLM\..\Run: [ienc.exe] C:\WINDOWS\system32\ienc.exe
O4 - HKLM\..\Run: [d3es.exe] C:\WINDOWS\d3es.exe
O4 - HKLM\..\Run: [sdkuh.exe] C:\WINDOWS\sdkuh.exe
O4 - HKLM\..\Run: [ipxr32.exe] C:\WINDOWS\ipxr32.exe
O4 - HKLM\..\Run: [winki.exe] C:\WINDOWS\system32\winki.exe
O4 - HKLM\..\Run: [ipck32.exe] C:\WINDOWS\system32\ipck32.exe
O4 - HKLM\..\Run: [addim32.exe] C:\WINDOWS\addim32.exe
O4 - HKLM\..\Run: [ntlw.exe] C:\WINDOWS\ntlw.exe
O4 - HKLM\..\Run: [atlsb32.exe] C:\WINDOWS\atlsb32.exe
O4 - HKLM\..\Run: [winto.exe] C:\WINDOWS\system32\winto.exe
O4 - HKLM\..\Run: [netxd32.exe] C:\WINDOWS\system32\netxd32.exe
O4 - HKLM\..\Run: [atlfa32.exe] C:\WINDOWS\atlfa32.exe
O4 - HKLM\..\Run: [sysyt.exe] C:\WINDOWS\sysyt.exe
O4 - HKLM\..\Run: [d3go.exe] C:\WINDOWS\system32\d3go.exe
O4 - HKLM\..\Run: [sysum32.exe] C:\WINDOWS\system32\sysum32.exe
O4 - HKLM\..\Run: [d3is32.exe] C:\WINDOWS\d3is32.exe
O4 - HKLM\..\Run: [apiuj.exe] C:\WINDOWS\system32\apiuj.exe
O4 - HKLM\..\Run: [apied32.exe] C:\WINDOWS\apied32.exe
O4 - HKLM\..\Run: [syszx32.exe] C:\WINDOWS\syszx32.exe
O4 - HKLM\..\Run: [apikb32.exe] C:\WINDOWS\apikb32.exe
O4 - HKLM\..\Run: [ntbb.exe] C:\WINDOWS\ntbb.exe
O4 - HKLM\..\Run: [crju32.exe] C:\WINDOWS\crju32.exe
O4 - HKLM\..\Run: [appni.exe] C:\WINDOWS\appni.exe
O4 - HKLM\..\Run: [sdkto.exe] C:\WINDOWS\system32\sdkto.exe
O4 - HKLM\..\Run: [atljd32.exe] C:\WINDOWS\atljd32.exe
O4 - HKLM\..\Run: [atlxa.exe] C:\WINDOWS\atlxa.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\System32\ncwngake.dll",forkonce
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\iexplore.exe http://www.symantec.com/techsupp/servlet/P…00001e.0000004a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .tiff: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin6.dll
O15 - Trusted Zone: *.att.net
O15 - Trusted Zone: http://*.att.net
O15 - Trusted Zone: *.sbcglobal.net
O15 - Trusted Zone: http://*.sbcglobal.net
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqrr - C:\WINDOWS\System32\ssqrr.dll (file missing)
O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll
O20 - Winlogon Notify: yaywtrq - yaywtrq.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: MPService - Unknown owner - C:\Program Files\Canon\MultiPASS\mpservic.exe (file missing)
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\Owner\Desktop\SFUninstaller.exe" service (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)






StartupList report, 8/20/2007, 9:39:15 PM
StartupList version: 1.52.2
Started from : C:\HJT\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\notepad.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
appvl.exe = C:\WINDOWS\system32\appvl.exe
msrs.exe = C:\WINDOWS\system32\msrs.exe
sdkws32.exe = C:\WINDOWS\system32\sdkws32.exe
appxd.exe = C:\WINDOWS\system32\appxd.exe
wincz.exe = C:\WINDOWS\system32\wincz.exe
atlvv32.exe = C:\WINDOWS\atlvv32.exe
appqp32.exe = C:\WINDOWS\appqp32.exe
BJCFD = C:\Program Files\BroadJump\Client Foundation\CFD.exe
AlcxMonitor = ALCXMNTR.EXE
addaw.exe = C:\WINDOWS\system32\addaw.exe
ienc.exe = C:\WINDOWS\system32\ienc.exe
d3es.exe = C:\WINDOWS\d3es.exe
sdkuh.exe = C:\WINDOWS\sdkuh.exe
ipxr32.exe = C:\WINDOWS\ipxr32.exe
winki.exe = C:\WINDOWS\system32\winki.exe
ipck32.exe = C:\WINDOWS\system32\ipck32.exe
addim32.exe = C:\WINDOWS\addim32.exe
ntlw.exe = C:\WINDOWS\ntlw.exe
atlsb32.exe = C:\WINDOWS\atlsb32.exe
winto.exe = C:\WINDOWS\system32\winto.exe
netxd32.exe = C:\WINDOWS\system32\netxd32.exe
atlfa32.exe = C:\WINDOWS\atlfa32.exe
sysyt.exe = C:\WINDOWS\sysyt.exe
d3go.exe = C:\WINDOWS\system32\d3go.exe
sysum32.exe = C:\WINDOWS\system32\sysum32.exe
d3is32.exe = C:\WINDOWS\d3is32.exe
apiuj.exe = C:\WINDOWS\system32\apiuj.exe
apied32.exe = C:\WINDOWS\apied32.exe
syszx32.exe = C:\WINDOWS\syszx32.exe
apikb32.exe = C:\WINDOWS\apikb32.exe
ntbb.exe = C:\WINDOWS\ntbb.exe
crju32.exe = C:\WINDOWS\crju32.exe
appni.exe = C:\WINDOWS\appni.exe
sdkto.exe = C:\WINDOWS\system32\sdkto.exe
atljd32.exe = C:\WINDOWS\atljd32.exe
atlxa.exe = C:\WINDOWS\atlxa.exe
SystemOptimizer = rundll32.exe "C:\WINDOWS\System32\ncwngake.dll",forkonce
AVG7_CC = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Aim6 = "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - {0B1EDEB6-897D-02BF-11AF-9F1EE56199D6}
(no name) - C:\WINDOWS\System32\ssqrr.dll (file missing) - {147ECC61-5187-4D53-BC69-D7143D8E3456}
(no name) - (no file) - {322B3263-4125-83BC-EA0A-3B07AB10E29B}
(no name) - (no file) - {44B14A5D-EF05-8A73-645F-321A1D3DA204}
(no name) - (no file) - {4EDC72D6-1677-BA8E-A3E9-F6CD337060DB}
(no name) - (no file) - {5092ADF3-9DA6-E4D4-FEFF-77B4A9B7DC70}
(no name) - (no file) - {52BC631D-9C1A-0E41-A49D-4D4FD49D830C}
(no name) - (no file) - {52E6830C-594F-0652-97BC-4BEF29128B11}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - (no file) - {539322FC-A50C-270C-A3BD-3515AA26634A}
(no name) - (no file) - {57DB0F9C-95AA-F3DB-A422-DF9CC22B2876}
(no name) - (no file) - {5AEDA511-0157-5F17-AC3D-A3D8D05DFE0C}
(no name) - C:\WINDOWS\system32\appys32.dll - {5D6A3C38-325C-B883-7058-D8512D537117}
(no name) - (no file) - {5F2480E5-41C5-F1D2-7B6F-5DF83C9B61F6}
(no name) - (no file) - {67963C46-D4CE-3BFC-A231-2102B037FC9B}
(no name) - (no file) - {681772EF-1514-33C7-0408-B8771F24D4CB}
(no name) - (no file) - {71167969-C63A-6FB0-2E12-19AC38D1B9B1}
(no name) - (no file) - {723A508C-C0DA-A207-D99C-49CB499D8E4B}
(no name) - C:\WINDOWS\ntpt32.dll - {740EFDF9-C3B0-986E-D595-83C15B23083A}
(no name) - (no file) - {750FF540-4850-123F-C121-7AEF5710EE3A}
(no name) - (no file) - {877B5096-0FB9-2632-5448-A94D5150B850}
(no name) - (no file) - {90B46B07-282D-8DDE-D296-452CDBB0603B}
(no name) - (no file) - {9CE33963-05DF-7E69-EC6A-2B29B35EAE5A}
NAV Helper - (no file) - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD}
(no name) - (no file) - {AD558823-F711-D52F-CF3D-E2058029C0DD}
(no name) - (no file) - {B9B34100-D040-0B2A-82D1-D1F5061D5342}
(no name) - C:\WINDOWS\System32\uyisujoc.dll - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC}
(no name) - (no file) - {C8F7745A-EDC7-09F6-2A66-3DBD317341D5}
(no name) - C:\WINDOWS\System32\yaywtrq.dll (file missing) - {CC358019-D328-40B4-8E2D-818CE142616C}
(no name) - (no file) - {D3DD24BD-375D-1229-E7E9-92878A1D7DBE}
(no name) - (no file) - {D74BCADB-C0DA-FC8B-4B57-102D803A3C3B}
(no name) - (no file) - {E70BCFE8-4567-8803-D4D5-7B3E4E06E85F}
(no name) - (no file) - {F0E095A0-3EA9-8479-E393-7CB483F3BC0D}
(no name) - (no file) - {F76604BF-96C5-81C9-07E5-094D1BB88043}

————————————————–

Enumerating Download Program Files:

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\xscan60.ocx
CODEBASE = http://housecall60.trendmicro.com/housecall/xscan60.cab

[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 7,762 bytes
Report generated in 0.032 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only







3Com HomeConnect PC Digital Video
AC3Filter (remove only)
ACDSee
Adobe Acrobat 5.0
AIM 6.0
AOL Instant Messenger
ATI Control Panel
ATI Display Driver
ATI DVD Decoder 2.1.0.1
ATI Multimedia Center 8.8.0.0
ATI Remote Wonder 1.4
AVG 7.5
BroadJump Client Foundation
Canon Camera Support Core Library
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon Utilities ZoomBrowser EX
Coloreal
DAO
DivX Pro Codec
ESSvpaht
HijackThis 1.99.1
Home Search Assistent
Huffyuv AVI lossless video codec (Remove Only)
Indeo® Software
Intel® 82845G Graphics Driver Software
InterVideo WinDVD 4
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1_02
Java 2 Runtime Environment, SE v1.4.0_01
Java Web Start
Lexmark X1100 Series
LG USB Drivers
LimeWire 4.12.15
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft .NET Framework (English) v1.0.3705
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft Office XP Professional with FrontPage
Mozilla Firefox (2.0.0.6)
Netscape (7.0)
Netscape Browser (remove only)
QuickTime
RecordNow
RecordNow Update Manager
Registry Mechanic
S3Display
S3Gamma2
S3Info2
S3Overlay
Search Extender
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Shopping Wizard
Spybot - Search & Destroy 1.4
Symantec KB-DocID:2003093015493306
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Viewpoint Media Player
Windows Installer 3.1 (KB893803)
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows Media Tools 4.1
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB911567
Windows XP Hotfix - KB918439
Windows XP Hotfix - KB918899
Windows XP Hotfix - KB925486
Windows XP Hotfix (SP2) [See q330638 for more information]
Windows XP Hotfix (SP2) [See Q331060 for more information]
XviD MPEG-4 Codec
Yahoo! Install Manager
Yahoo! Messenger
Yahoo! Toolbar







that should be everything in it's entirety up to this point. sorry for any confusion!
Hi

P2P Warning!
Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current malware infestation
Additional information on the safety of Peer to Peer programs themselves is here :
Clean/Infected P2P Programs
Please refrain from using P2P during the fix, to avoid introducing new infections.

Download AboutBuster
About Buster can be downloaded here
Once it is downloaded extract it to c:\aboutbuster and check for updates. Do NOT use it yet.


Run About Buster
  • Double-click on the AboutBuster.exe icon to start the program.
  • Next, click Begin Removal.
  • When the scan is done, click Ok.

    In the same folder as AboutBuster.exe, you will find a file 'Ab LogFile.txt'
    Please post the contents of this file in your next post.


Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI