This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Needed Pop Ups, Winantivirus, & Software In S

53 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer run slow - I deleted cookies &files; I have Macfee Virus Scan 8.0.0; When I first log on I get the following message:
RUNTIME ERROR
Program:…orgam files\common files\sonic\update manager\sgtray.exe
This application has requested the Runtime to terminate in an unusual way. Please contact the application's support team for more information.
I have Sonic Record Now & Express Labeler (preinstalled software; don't know how to contact support team.

I have been getting many pop ups: dating, winantivirus, perfertlovercalculator, and a few poker pop ups. In my control panel under "add/remove programs, I found winantivirus in my program files. I removed it. The next day I got the same winantivirus pop up. Also under Start Up, I found Think-Adz & TA_Start. Tonight when I first opened Internet Explorer, it did not open; I closed it and tried again and it opened.

I finially got to tomcoyotecom and ran Highjack This and got the following:

Logfile of HijackThis v1.99.1
Scan saved at 10:21:25 PM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\SYSTEM32\lldsrngl.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
O4 - HKLM\..\Run: [HelpCenter] C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe /P HelpCenter
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\mwinmmdt.exe CHD003
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [{7B-BE-EF-F1-ZN}] C:\WINDOWS\SYSTEM32\lldsrngl.exe CHD003
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\lldsrngl.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\mwinmmdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c9.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Then I got the startuplist:
StartupList report, 8/23/2007, 10:35:10 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\SYSTEM32\lldsrngl.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\David\Start Menu\Programs\Startup]
TA_Start.lnk = C:\WINDOWS\SYSTEM32\lldsrngl.exe
Think-Adz.lnk = C:\WINDOWS\SYSTEM32\mwinmmdt.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
Digital Line Detect.lnk = ?
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
dla = C:\WINDOWS\system32\dla\tfswctrl.exe
PCMService = "C:\Program Files\Dell\Media Experience\PCMService.exe"
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
MMTray = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
UpdateManager = "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
EPSON Stylus CX5400 = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
SsAAD.exe = C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
ISUSPM Startup = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
ShStatEXE = "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
McAfeeUpdaterUI = "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
Network Associates Error Reporting Service = "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
BearShare = "C:\Program Files\BearShare\BearShare.exe" /pause
ViewpointPhotosDeviceConnect = C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
HelpCenter = C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe /P HelpCenter
ExploreUpdSched = C:\WINDOWS\SYSTEM32\mwinmmdt.exe CHD003
Salestart = "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
{7B-BE-EF-F1-ZN} = C:\WINDOWS\SYSTEM32\lldsrngl.exe CHD003

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Sonic RecordNow! =
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
MoneyAgent = "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
AIM = C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
ISUSPM = "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[{32505657-9980-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/0/A…01F/wmvadvd.cab

[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab

[MediaGatewayX]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll
CODEBASE = http://static.zangocash.com/cab/Seekmo/ie/bridge-c9.cab

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 7,995 bytes
Report generated in 0.062 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

You were highly recommended my a friend who had similar issues.
Thank you for your time and assistance,
catcher33

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Hi catcher33,

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


You appear to have one of the Vundo varients, this one hides from HijackThis, so it is necessary to re-name it so we can see what's being hidden.
  • Go to C:\Program Files and create a folder HJT now move HijackThis.exe into that folder.
  • Now rename HijackThis.exe to FredFlintstone.exe
  • Run a new scan with HJT (FredFlintstone) and send me the new log please.
Can you also send me an Uninstall list.

Creating an Uninstall List
  • Open HJT, and click on Config, followed by Misc Tools.
  • Click on Open Uninstall Manager, and then click on Save List.
  • This will create a file uninstall_list.txt and prompt you to save it to your HJT folder.
  • Save it please and post it back to me here.
Sorry to be so late getting back to you. For some reason I didn't get the usual e-mail notification when you posted. OK, we'll need to check all the other accounts when we've finished with the one we're seeing to now. For the moment just follow the instructions in my last post for re-naming HJT and sending me the new log.
Gary R,
Below are the results of Fred Flintstone.


Logfile of HijackThis v1.99.1
Scan saved at 8:48:21 PM, on 8/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\SYSTEM32\lldsrngl.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HJT\FredFlintstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7CB2C07C-5A3D-4330-9876-56616DDB8BEF} - C:\WINDOWS\system32\jkhfc.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\scgsjtuf.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\FotomatDeviceConnect.exe
O4 - HKLM\..\Run: [HelpCenter] C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe /P HelpCenter
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\mwinmmdt.exe CHD003
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [{7B-BE-EF-F1-ZN}] C:\WINDOWS\SYSTEM32\lldsrngl.exe CHD003
O4 - HKLM\..\Run: [SystemRestoreStatus] rundll32.exe "C:\WINDOWS\system32\ydljmrfv.dll",sitypnow
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\lldsrngl.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\mwinmmdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c9.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkhfc - C:\WINDOWS\system32\jkhfc.dll
O20 - Winlogon Notify: jkkjhhf - jkkjhhf.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


uninstall_list.txt
BBYY FineReader 5.0 Sprint Plus
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat and Reader 6.0.3 Update
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
AIM Toolbar
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
ArcSoft PhotoImpression 4
ArcSoft Software Suite
BadCopy Pro
BellSouth FastAccess DSL WEB Controls
BellSouth® FastAccess® DSL Help Center 4.0
Broadcom Management Programs
Camera Driver
Canon Camera Support Core Library
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window DVC for ZoomBrowser EX
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
Conexant SmartHSFi V.9x 56K DF PCI Modem
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
DellSupport
DeltaCad
Digital Line Detect
EPSON Copy Utility
EPSON EIC CX5400
EPSON Photo Print
EPSON Printer Software
EPSON Scan
EPSON Smart Panel
F22 Air Dominance Fighter
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 1.99.1
Intel® 537EP V9x DF PCI Modem
Intel® Extreme Graphics Driver
Internet Explorer Default Page
iPod for Windows 2005-09-23
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
Lernout & Hauspie TruVoice for Microsoft Agent
Logitech Gaming Software
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Data Access Components KB870669
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office XP Media Content
Microsoft Office XP Professional
Modem Helper
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
NetWaiting
Nortel Networks Contivity VPN Client
OpenMG Limited Patch 4.1-05-14-24-01
OpenMG Secure Module 4.1.00
Outerinfo
Quicken 2004
QuickTime
RealOne Player
ScanToWeb
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Shockwave
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
SonicStage 3.1
Ultimate Puzzles 500
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar
Wal-Mart Music Downloads Store
WeatherBug
WildTangent Web Driver
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WordPerfect Office 11

Thanks,
catcher33
OK, let's get started.

Round one (there will be more to do).

Please go to Control Panel > Add/Remove Programs and Uninstall the following.

Outerinfo
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar
WeatherBug
WildTangent Web Driver


Be careful and read closely any messages that may pop up when removing them, some will try to trick you into not removing them.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix will encounter a file it can't remove. In this case, VundoFix will run on reboot. Simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.
Gary R,
I removed the programs in red. When I removed viewpoint media player, I got the following message:
vmpremov.exe - Application Error
The instruction at "0x77124920" referenced memory at "0x77124920".
The memory could not be "read".
Click OK to terminate program - I clicked OK and I assume it terminated the program.

Below are the results of Vundofix
VundoFix V6.5.7

Checking Java version…

Scan started at 7:26:36 PM 8/29/2007

Listing files found while scanning….

C:\WINDOWS\system32\cfhkj.bak1
C:\WINDOWS\system32\cfhkj.bak2
C:\WINDOWS\system32\cfhkj.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cfhkj.tmp
C:\WINDOWS\system32\jkhfc.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cfhkj.bak1
C:\WINDOWS\system32\cfhkj.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfhkj.bak2
C:\WINDOWS\system32\cfhkj.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfhkj.ini
C:\WINDOWS\system32\cfhkj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cfhkj.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfhkj.tmp
C:\WINDOWS\system32\cfhkj.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\jkhfc.dll Has been deleted!

Performing Repairs to the registry.
Done!

Below is a new Hijack This log
Logfile of HijackThis v1.99.1
Scan saved at 7:34:55 PM, on 8/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\SYSTEM32\lldsrngl.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HJT\FredFlintstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7CB2C07C-5A3D-4330-9876-56616DDB8BEF} - C:\WINDOWS\system32\jkhfc.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\raggtldf.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [HelpCenter] C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe /P HelpCenter
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\mwinmmdt.exe CHD003
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [{7B-BE-EF-F1-ZN}] C:\WINDOWS\SYSTEM32\lldsrngl.exe CHD003
O4 - HKLM\..\Run: [SystemRestoreStatus] rundll32.exe "C:\WINDOWS\system32\bhqdusjg.dll",sitypnow
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\lldsrngl.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\mwinmmdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c9.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkkjhhf - jkkjhhf.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Thanks again,
catcher33
Looking better, still some work to do.

I presume there was something wrong with the Viewpoint uninstaller, can you send me another Uninstall List please so we can see if it's still showing.

Next

Run a scan with HJT and when finished check the following items (if found).

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {7CB2C07C-5A3D-4330-9876-56616DDB8BEF} - C:\WINDOWS\system32\jkhfc.dll (file missing)

O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\raggtldf.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\SYSTEM32\mwinmmdt.exe CHD003

O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

O4 - HKLM\..\Run: [{7B-BE-EF-F1-ZN}] C:\WINDOWS\SYSTEM32\lldsrngl.exe CHD003

O4 - HKLM\..\Run: [SystemRestoreStatus] rundll32.exe "C:\WINDOWS\system32\bhqdusjg.dll",sitypnow

O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\lldsrngl.exe

O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\mwinmmdt.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Seekmo/ie/bridge-c9.cab

O20 - Winlogon Notify: jkkjhhf - jkkjhhf.dll (file missing)



Now close all open windows and click Fix Checked to remove them.

Download OTMoveIt by OldTimer to your Desktop.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\WINDOWS\system32\raggtldf.dll
C:\WINDOWS\SYSTEM32\mwinmmdt.exe
C:\Program Files\Common Files\WinAntiSpyware 2007
C:\WINDOWS\SYSTEM32\lldsrngl.exe
C:\WINDOWS\system32\bhqdusjg.dll

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please.
  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.
Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post please.
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

Now run a new HJT scan and send me the log please.

Summary of the logs I need from you in your next post:
  • New Uninstall List
  • OTMoveIt log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
8/30/07 New Uninstall List ABBYY FineReader 5.0 Sprint Plus Adobe Acrobat - Reader 6.0.2 Update Adobe Acrobat and Reader 6.0.3 Update Adobe Flash Player ActiveX Adobe Reader 6.0.1 AIM Toolbar America Online (Choose which version to remove) AOL Coach Version 1.0(Build:20030807.3) AOL Instant Messenger ArcSoft PhotoImpression 4 ArcSoft Software Suite BadCopy Pro BellSouth FastAccess DSL WEB Controls BellSouth® FastAccess® DSL Help Center 4.0 Broadcom Management Programs Camera Driver Canon Camera Support Core Library Canon Camera Window DS for ZoomBrowser EX Canon Camera Window DVC for ZoomBrowser EX Canon Camera Window for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon ZoomBrowser EX Conexant SmartHSFi V.9x 56K DF PCI Modem Dell Digital Jukebox Driver Dell Media Experience Dell Solution Center DellSupport DeltaCad Digital Line Detect EPSON Copy Utility EPSON EIC CX5400 EPSON Photo Print EPSON Printer Software EPSON Scan EPSON Smart Panel F22 Air Dominance Fighter Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer HijackThis 1.99.1 Intel® 537EP V9x DF PCI Modem Intel® Extreme Graphics Driver Internet Explorer Default Page iPod for Windows 2005-09-23 iTunes Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2 Learn2 Player (Uninstall Only) Lernout & Hauspie TruVoice for Microsoft Agent Logitech Gaming Software McAfee VirusScan Enterprise Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Data Access Components KB870669 Microsoft Encarta Encyclopedia Standard 2004 Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office XP Media Content Microsoft Office XP Professional Modem Helper MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) NetWaiting Nortel Networks Contivity VPN Client OpenMG Limited Patch 4.1-05-14-24-01 OpenMG Secure Module 4.1.00 Quicken 2004 QuickTime RealOne Player ScanToWeb Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Shockwave Sonic DLA Sonic RecordNow! Sonic Update Manager SonicStage 3.1 Ultimate Puzzles 500 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Wal-Mart Music Downloads Store Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WordPerfect Office 11 catcher33
8/30/07 OTMoveIt DllUnregisterServer procedure not found in C:\WINDOWS\system32\raggtldf.dll C:\WINDOWS\system32\raggtldf.dll NOT unregistered. C:\WINDOWS\system32\raggtldf.dll moved successfully. C:\WINDOWS\SYSTEM32\mwinmmdt.exe moved successfully. C:\Program Files\Common Files\WinAntiSpyware 2007 moved successfully. C:\WINDOWS\SYSTEM32\lldsrngl.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\bhqdusjg.dll C:\WINDOWS\system32\bhqdusjg.dll NOT unregistered. C:\WINDOWS\system32\bhqdusjg.dll moved successfully. Created on 08/30/2007 21:14:33 catcher33
8/30/07 KASPERSKY ONLINE SCANNER REPORT Thursday, August 30, 2007 11:30:58 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 31/08/2007 Kaspersky Anti-Virus database records: 400536 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 98236 Number of viruses found: 10 Number of infected objects: 78 Number of suspicious objects: 0 Duration of the scan process: 01:17:42 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070829_Time-204727921_EnterceptExceptions.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20070829_Time-204727921_EnterceptRules.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_D69R9941.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_D69R9941.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped C:\Documents and Settings\David\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\David\Local Settings\Application Data\SupportSoft\HelpCenter\David\state\logs\sprtcmd.log Object is locked skipped C:\Documents and Settings\David\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\David\Local Settings\History\History.IE5\MSHist012007083020070831\index.dat Object is locked skipped C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\816F8XIR\UserStatusChange[6].html Object is locked skipped C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\David\NTUSER.DAT Object is locked skipped C:\Documents and Settings\David\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\kmer[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\8HQ7CHU7\nym_test[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\Documents and Settings\Emily\Local Settings\Temp\snapsnet.exe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped C:\Documents and Settings\Emily\Local Settings\Temp\snapsnet.exe NSIS: infected - 1 skipped C:\Documents and Settings\Emily\Local Settings\Temp\thinksnet.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\Documents and Settings\Emily\Local Settings\Temp\yazzlesnet.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\Documents and Settings\Emily\Local Settings\Temp\yazzlesnet.exe NSIS: infected - 1 skipped C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\A5I7GTYB\nym_test[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\W1YVSLEZ\asdfasd[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Save\SaveNowupdate.exe/Acm.dll Infected: not-a-virus:AdTool.Win32.WhenU.i skipped C:\Program Files\Save\SaveNowupdate.exe/Save.exe Infected: not-a-virus:AdTool.Win32.WhenU.i skipped C:\Program Files\Save\SaveNowupdate.exe CAB: infected - 2 skipped C:\System Volume Information\catalog.wci\000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\010002.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1305\A0291392.exe/file2 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1305\A0291392.exe Inno: infected - 1 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299613.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299614.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299615.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1312\A0299616.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299666.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE/WISE0008.BIN/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE/WISE0008.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE WiseSFX: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299740.EXE WiseSFX Dropper: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE/WISE0008.BIN/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE/WISE0008.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE WiseSFX: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299741.EXE WiseSFX Dropper: infected - 2 skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299884.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299885.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1314\A0299886.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1315\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Intel® 537EP V9x DF PCI Modem.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\abhmmeap.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\aparfadx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\bpyucqcm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\cbdvatnl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\cynhujqh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\dbgjwhnb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\dmlbabha.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\WINDOWS\SYSTEM32\dnsheups.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\dwdsrngt.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\WINDOWS\SYSTEM32\emdfxqul.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\esoqlyfm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\WINDOWS\SYSTEM32\eywsmhth.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\faanstjn.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\fxmwjefx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\hnojubay.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\hpdgvyuk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\hyomdwsp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\jwgxxbly.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\kephllns.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\lwekfjfv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\mbwbxgpv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\moiruhxj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\mygrnjku.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\nepsnobr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\nkquesbl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\nyjhvgem.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\offynynu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\okogaowg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\plwqfgfe.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\prwbadre.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\pvmqclhl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\qenpvuwg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\rfxhvcsv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\sfspbtkq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\ufamdxjp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\uksiedqu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\veegayfd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\wjlogwlu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\WINDOWS\SYSTEM32\xdeavpss.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\xmyjjkoo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\ykywoooa.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\ypncwdfk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\SYSTEM32\ywxwptqh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.md skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\_OTMoveIt\MovedFiles\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\_OTMoveIt\MovedFiles\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\bhqdusjg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mh skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\lldsrngl.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\mwinmmdt.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.r skipped Scan process completed. catcher33
8/30/07
HJT Rusults

Logfile of HijackThis v1.99.1
Scan saved at 11:35:08 PM, on 8/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\David\Desktop\FredFlintstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [HelpCenter] C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe /P HelpCenter
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

catcher33
Still some work to do.
  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\kmer[1
C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\8HQ7CHU7\nym_test[1
C:\Documents and Settings\Emily\Local Settings\Temp\snapsnet.exe
C:\Documents and Settings\Emily\Local Settings\Temp\thinksnet.exe
C:\Documents and Settings\Emily\Local Settings\Temp\yazzlesnet.exe
C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\A5I7GTYB\nym_test[1
C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\W1YVSLEZ\asdfasd[1
C:\Program Files\Save\SaveNowupdate.exe
C:\Program Files\Save\SaveNowupdate.exe
C:\WINDOWS\SYSTEM32\abhmmeap.dll
C:\WINDOWS\SYSTEM32\aparfadx.dll
C:\WINDOWS\SYSTEM32\bpyucqcm.dll
C:\WINDOWS\SYSTEM32\cbdvatnl.dll
C:\WINDOWS\SYSTEM32\cynhujqh.dll
C:\WINDOWS\SYSTEM32\dbgjwhnb.dll
C:\WINDOWS\SYSTEM32\dmlbabha.dll
C:\WINDOWS\SYSTEM32\dnsheups.dll
C:\WINDOWS\SYSTEM32\dwdsrngt.exe
C:\WINDOWS\SYSTEM32\emdfxqul.dll
C:\WINDOWS\SYSTEM32\esoqlyfm.dll
C:\WINDOWS\SYSTEM32\eywsmhth.dll
C:\WINDOWS\SYSTEM32\faanstjn.dll
C:\WINDOWS\SYSTEM32\fxmwjefx.dll
C:\WINDOWS\SYSTEM32\hnojubay.dll
C:\WINDOWS\SYSTEM32\hpdgvyuk.dll
C:\WINDOWS\SYSTEM32\hyomdwsp.dll
C:\WINDOWS\SYSTEM32\jwgxxbly.dll
C:\WINDOWS\SYSTEM32\kephllns.dll
C:\WINDOWS\SYSTEM32\lwekfjfv.dll
C:\WINDOWS\SYSTEM32\mbwbxgpv.dll
C:\WINDOWS\SYSTEM32\moiruhxj.dll
C:\WINDOWS\SYSTEM32\mygrnjku.dll
C:\WINDOWS\SYSTEM32\nepsnobr.dll
C:\WINDOWS\SYSTEM32\nkquesbl.dll
C:\WINDOWS\SYSTEM32\nyjhvgem.dll
C:\WINDOWS\SYSTEM32\offynynu.dll
C:\WINDOWS\SYSTEM32\okogaowg.dll
C:\WINDOWS\SYSTEM32\plwqfgfe.dll
C:\WINDOWS\SYSTEM32\prwbadre.dll
C:\WINDOWS\SYSTEM32\pvmqclhl.dll
C:\WINDOWS\SYSTEM32\qenpvuwg.dll
C:\WINDOWS\SYSTEM32\rfxhvcsv.dll
C:\WINDOWS\SYSTEM32\sfspbtkq.dll
C:\WINDOWS\SYSTEM32\ufamdxjp.dll
C:\WINDOWS\SYSTEM32\uksiedqu.dll
C:\WINDOWS\SYSTEM32\veegayfd.dll
C:\WINDOWS\SYSTEM32\wjlogwlu.dll
C:\WINDOWS\SYSTEM32\xdeavpss.dll
C:\WINDOWS\SYSTEM32\xmyjjkoo.dll
C:\WINDOWS\SYSTEM32\ykywoooa.dll
C:\WINDOWS\SYSTEM32\ypncwdfk.dll
C:\WINDOWS\SYSTEM32\ywxwptqh.dll

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the programme.
  • A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
  • Post the log back here please.
Now can you run another Kaspersky scan please and post me the log, also a new HJT log please.

Summary of the logs I need from you in your next post:
  • OTMoveIt
  • New Kaspersky
  • New HJT


Please post each log separately to prevent them being cut off by the forum post size limiter.
8/31/07 OTMoveIt results File/Folder C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\kmer[1 not found. File/Folder C:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\8HQ7CHU7\nym_test[1 not found. File move failed. C:\Documents and Settings\Emily\Local Settings\Temp\snapsnet.exe scheduled to be moved on reboot. C:\Documents and Settings\Emily\Local Settings\Temp\thinksnet.exe moved successfully. C:\Documents and Settings\Emily\Local Settings\Temp\yazzlesnet.exe moved successfully. File/Folder C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\A5I7GTYB\nym_test[1 not found. File/Folder C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\W1YVSLEZ\asdfasd[1 not found. C:\Program Files\Save\SaveNowupdate.exe moved successfully. File/Folder C:\Program Files\Save\SaveNowupdate.exe not found. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\abhmmeap.dll C:\WINDOWS\SYSTEM32\abhmmeap.dll NOT unregistered. C:\WINDOWS\SYSTEM32\abhmmeap.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\aparfadx.dll C:\WINDOWS\SYSTEM32\aparfadx.dll NOT unregistered. C:\WINDOWS\SYSTEM32\aparfadx.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\bpyucqcm.dll C:\WINDOWS\SYSTEM32\bpyucqcm.dll NOT unregistered. C:\WINDOWS\SYSTEM32\bpyucqcm.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\cbdvatnl.dll C:\WINDOWS\SYSTEM32\cbdvatnl.dll NOT unregistered. C:\WINDOWS\SYSTEM32\cbdvatnl.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\cynhujqh.dll C:\WINDOWS\SYSTEM32\cynhujqh.dll NOT unregistered. C:\WINDOWS\SYSTEM32\cynhujqh.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\dbgjwhnb.dll C:\WINDOWS\SYSTEM32\dbgjwhnb.dll NOT unregistered. C:\WINDOWS\SYSTEM32\dbgjwhnb.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\dmlbabha.dll C:\WINDOWS\SYSTEM32\dmlbabha.dll NOT unregistered. C:\WINDOWS\SYSTEM32\dmlbabha.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\dnsheups.dll C:\WINDOWS\SYSTEM32\dnsheups.dll NOT unregistered. C:\WINDOWS\SYSTEM32\dnsheups.dll moved successfully. C:\WINDOWS\SYSTEM32\dwdsrngt.exe moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\emdfxqul.dll C:\WINDOWS\SYSTEM32\emdfxqul.dll NOT unregistered. C:\WINDOWS\SYSTEM32\emdfxqul.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\esoqlyfm.dll C:\WINDOWS\SYSTEM32\esoqlyfm.dll NOT unregistered. C:\WINDOWS\SYSTEM32\esoqlyfm.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\eywsmhth.dll C:\WINDOWS\SYSTEM32\eywsmhth.dll NOT unregistered. C:\WINDOWS\SYSTEM32\eywsmhth.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\faanstjn.dll C:\WINDOWS\SYSTEM32\faanstjn.dll NOT unregistered. C:\WINDOWS\SYSTEM32\faanstjn.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\fxmwjefx.dll C:\WINDOWS\SYSTEM32\fxmwjefx.dll NOT unregistered. C:\WINDOWS\SYSTEM32\fxmwjefx.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\hnojubay.dll C:\WINDOWS\SYSTEM32\hnojubay.dll NOT unregistered. C:\WINDOWS\SYSTEM32\hnojubay.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\hpdgvyuk.dll C:\WINDOWS\SYSTEM32\hpdgvyuk.dll NOT unregistered. C:\WINDOWS\SYSTEM32\hpdgvyuk.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\hyomdwsp.dll C:\WINDOWS\SYSTEM32\hyomdwsp.dll NOT unregistered. C:\WINDOWS\SYSTEM32\hyomdwsp.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\jwgxxbly.dll C:\WINDOWS\SYSTEM32\jwgxxbly.dll NOT unregistered. C:\WINDOWS\SYSTEM32\jwgxxbly.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\kephllns.dll C:\WINDOWS\SYSTEM32\kephllns.dll NOT unregistered. C:\WINDOWS\SYSTEM32\kephllns.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\lwekfjfv.dll C:\WINDOWS\SYSTEM32\lwekfjfv.dll NOT unregistered. C:\WINDOWS\SYSTEM32\lwekfjfv.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\mbwbxgpv.dll C:\WINDOWS\SYSTEM32\mbwbxgpv.dll NOT unregistered. C:\WINDOWS\SYSTEM32\mbwbxgpv.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\moiruhxj.dll C:\WINDOWS\SYSTEM32\moiruhxj.dll NOT unregistered. C:\WINDOWS\SYSTEM32\moiruhxj.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\mygrnjku.dll C:\WINDOWS\SYSTEM32\mygrnjku.dll NOT unregistered. C:\WINDOWS\SYSTEM32\mygrnjku.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\nepsnobr.dll C:\WINDOWS\SYSTEM32\nepsnobr.dll NOT unregistered. C:\WINDOWS\SYSTEM32\nepsnobr.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\nkquesbl.dll C:\WINDOWS\SYSTEM32\nkquesbl.dll NOT unregistered. C:\WINDOWS\SYSTEM32\nkquesbl.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\nyjhvgem.dll C:\WINDOWS\SYSTEM32\nyjhvgem.dll NOT unregistered. C:\WINDOWS\SYSTEM32\nyjhvgem.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\offynynu.dll C:\WINDOWS\SYSTEM32\offynynu.dll NOT unregistered. C:\WINDOWS\SYSTEM32\offynynu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\okogaowg.dll C:\WINDOWS\SYSTEM32\okogaowg.dll NOT unregistered. C:\WINDOWS\SYSTEM32\okogaowg.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\plwqfgfe.dll C:\WINDOWS\SYSTEM32\plwqfgfe.dll NOT unregistered. C:\WINDOWS\SYSTEM32\plwqfgfe.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\prwbadre.dll C:\WINDOWS\SYSTEM32\prwbadre.dll NOT unregistered. C:\WINDOWS\SYSTEM32\prwbadre.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\pvmqclhl.dll C:\WINDOWS\SYSTEM32\pvmqclhl.dll NOT unregistered. C:\WINDOWS\SYSTEM32\pvmqclhl.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\qenpvuwg.dll C:\WINDOWS\SYSTEM32\qenpvuwg.dll NOT unregistered. C:\WINDOWS\SYSTEM32\qenpvuwg.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\rfxhvcsv.dll C:\WINDOWS\SYSTEM32\rfxhvcsv.dll NOT unregistered. C:\WINDOWS\SYSTEM32\rfxhvcsv.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\sfspbtkq.dll C:\WINDOWS\SYSTEM32\sfspbtkq.dll NOT unregistered. C:\WINDOWS\SYSTEM32\sfspbtkq.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\ufamdxjp.dll C:\WINDOWS\SYSTEM32\ufamdxjp.dll NOT unregistered. C:\WINDOWS\SYSTEM32\ufamdxjp.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\uksiedqu.dll C:\WINDOWS\SYSTEM32\uksiedqu.dll NOT unregistered. C:\WINDOWS\SYSTEM32\uksiedqu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\veegayfd.dll C:\WINDOWS\SYSTEM32\veegayfd.dll NOT unregistered. C:\WINDOWS\SYSTEM32\veegayfd.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\wjlogwlu.dll C:\WINDOWS\SYSTEM32\wjlogwlu.dll NOT unregistered. C:\WINDOWS\SYSTEM32\wjlogwlu.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\xdeavpss.dll C:\WINDOWS\SYSTEM32\xdeavpss.dll NOT unregistered. C:\WINDOWS\SYSTEM32\xdeavpss.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\xmyjjkoo.dll C:\WINDOWS\SYSTEM32\xmyjjkoo.dll NOT unregistered. C:\WINDOWS\SYSTEM32\xmyjjkoo.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\ykywoooa.dll C:\WINDOWS\SYSTEM32\ykywoooa.dll NOT unregistered. C:\WINDOWS\SYSTEM32\ykywoooa.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\ypncwdfk.dll C:\WINDOWS\SYSTEM32\ypncwdfk.dll NOT unregistered. C:\WINDOWS\SYSTEM32\ypncwdfk.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\SYSTEM32\ywxwptqh.dll C:\WINDOWS\SYSTEM32\ywxwptqh.dll NOT unregistered. C:\WINDOWS\SYSTEM32\ywxwptqh.dll moved successfully. Created on 08/31/2007 20:54:42 catcher33

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI