This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

No Response To Hijackthis Log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've posted two HijackThis logs April 26 and April 24, in HijackThis Logs and Problems and HijackThis logs, but have not gotten any response. What am I doing wrong?
Hi raymm,

Please post a fresh HijackThis log; the other one is simply too old to give us any reliable information about the present state of your computer.

Unfortunately, sometimes a log WILL get passed over; in this case (and seeing the record now, about a month later) it seems that you posted a log in a new thread after Little Eagle had been helping you. Since he was probably looking for replies to THAT thread he missed your next post. Other workers, seeing that he was helping you, simply passed over it and went on to other logs. Unfortunately there are MANY MORE logs than helpers, and things like that can happen. We try to watch every log, but it's just impossible to catch this every time.

Get us that new log, and we'll see what can be done to help you. (I'll be watching THIS THREAD for a reply.)
Logfile of HijackThis v1.97.7
Scan saved at 4:28:34 PM, on 5/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\QuickCut Launcher\quickcut.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.exe
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
C:\Program Files\Trend Micro\Internet Security\pccguide.exe
C:\Program Files\QuickCut Launcher\quickcut.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\Program Files\Active CPU guage\acpu.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\MYIE2\MyIE.exe
C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
C:\Program Files\Kazaa Lite K++\KazaaLite.kpp
C:\Program Files\Free Downloads Accelerator\fdaagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MYIE2\MyIE.exe
C:\Program Files\NotesBrowser\IC3.EXE
C:\PROGRA~1\INFOSE~1\is.exe
C:\Program Files\GIANT Company Software\Spam Inspector\siMain.exe
C:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.ca/advanced_search?hl=en
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WebBlinds - {4F92B827-1E56-4E30-A978-A17A7861A606} - C:\Program Files\Object Desktop\WebBlinds\WebBlinds.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: (no name) - {98DE779A-2364-4293-AB71-2B97C61C4640} - C:\PROGRA~1\FREEDO~1\fdahlp99.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\System & Internet Washer\pkext.dll
O2 - BHO: (no name) - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\PROGRA~1\SECRET~1\smiehlp.dll
O2 - BHO: (no name) - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: StumbleUpon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [QuickCut Launcher] C:\Program Files\QuickCut Launcher\quickcut.exe /startup
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\System32\wweb32.dll/lookup.html
O8 - Extra context menu item: Add to Ad Hunter - C:\Program Files\MYIE2\config/blacklist.htm
O8 - Extra context menu item: Add To Net Snippets - C:\PROGRA~1\NETSNI~1\Res\Clipper.htm
O8 - Extra context menu item: Clear Fields &0 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComClearFields.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Download with Free Downloads Accelerator - C:\Program Files\Free Downloads Accelerator\fdaie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill && Submit &8 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillSubmit.html
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Fill Without Asking &9 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillWithoutAsking.html
O8 - Extra context menu item: Passcards &. - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
O8 - Extra context menu item: Reset Fields &- - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComResetFields.html
O8 - Extra context menu item: RF Toolbar &2 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Set Fields &= - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSetFields.html
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL/blogimage
O8 - Extra context menu item: Subscribe in NewsGator - c:\progra~1\newsga~1\addref.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Fill Id (HKLM)
O9 - Extra 'Tools' menuitem: Fill from Identity &; (HKLM)
O9 - Extra button: Fill Pass (HKLM)
O9 - Extra 'Tools' menuitem: Fill from Passcard &' (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &[ (HKLM)
O9 - Extra button: Go Fill (HKLM)
O9 - Extra 'Tools' menuitem: Go && Fill &6 (HKLM)
O9 - Extra button: Login (HKLM)
O9 - Extra 'Tools' menuitem: Login &7 (HKLM)
O9 - Extra button: Options (HKLM)
O9 - Extra 'Tools' menuitem: Rf Options &O (HKLM)
O9 - Extra button: Customize (HKLM)
O9 - Extra 'Tools' menuitem: Customize Menu &4 (HKLM)
O9 - Extra button: Generate (HKLM)
O9 - Extra 'Tools' menuitem: Password Generator &3 (HKLM)
O9 - Extra button: TaskBar (HKLM)
O9 - Extra 'Tools' menuitem: Robo TaskBar Icon &1 (HKLM)
O9 - Extra button: Set Fields (HKLM)
O9 - Extra 'Tools' menuitem: Set Fields &= (HKLM)
O9 - Extra button: Reset Fields (HKLM)
O9 - Extra 'Tools' menuitem: Reset Fields &- (HKLM)
O9 - Extra button: Clear Fields (HKLM)
O9 - Extra 'Tools' menuitem: Clear Fields &0 (HKLM)
O9 - Extra button: Logoff (HKLM)
O9 - Extra 'Tools' menuitem: Logoff &5 (HKLM)
O9 - Extra button: Fill Submit (HKLM)
O9 - Extra 'Tools' menuitem: Fill && Submit &8 (HKLM)
O9 - Extra button: Fill NoAsk (HKLM)
O9 - Extra 'Tools' menuitem: Fill Without Asking &9 (HKLM)
O9 - Extra button: ATI TV (HKLM)
O9 - Extra button: Identities (HKLM)
O9 - Extra 'Tools' menuitem: Identities &, (HKLM)
O9 - Extra button: Passcards (HKLM)
O9 - Extra 'Tools' menuitem: Passcards &. (HKLM)
O9 - Extra button: Safenotes (HKLM)
O9 - Extra 'Tools' menuitem: SafeNotes &/ (HKLM)
O9 - Extra button: Snippets (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Subscribe in NewsGator (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: ICQ 4.0 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: System & Internet Washer (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://ql1.quicklaw.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {08C818C3-2F1E-11D0-9223-00A0244D2920} (ChartFX IE Client Object) - http://www.fundlibrary.com/download/cfxax.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4B55FE21-325E-48D5-9B39-9B430D639EE8} (ScanFile.FileScan) - http://www.contentpurity.com/ScanFile.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25c34c0e601c58839523/…ip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {763C10EE-E4C6-49AA-9325-F15ABF1C52B0} (X1 DownloadControl Class) - http://www.x1.com/download/X1WebInstall.cab
O16 - DPF: {90918C20-FB99-495A-BD79-CB91ACF44887} - http://www.typingmaster.com/contents/tm200…ick/TMSetup.cab
O16 - DPF: {95844941-7934-4693-92D9-8202EA7B20ED} - http://www.stumbleupon.com/stumble.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7950.4803356482
O16 - DPF: {B817734E-046C-11D3-B674-00104BA25195} (PSNQuerySystem Class) - http://pmb001.3m.com/pub/psnotes/psnudate.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.dll
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} (Ppinstall Control) - http://www.163.com/wwwimages/sms/ppinstall22.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://timematters.webex.com/client/latest…bex/ieatgpc.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Hi Ray,

Thanks for the log. Now let's see what we can do with it. First, open your Control Panel and click on the "Add/Remove programs" icon. If there are any programs you DO NOT BOTH RECOGNIZE AND WANT, DELETE THEM! (DO NOT delete your Windows and Internet Explorer updates, which are listed with a "Q" and a bunch of numbers.) Then reboot your computer.

Now, download and run Spybot-Search&Destroy and Ad-Aware; they are the standard programs for finding and cleaning crapware off your system, and can also help prevent its downloading and installation in some cases. Here are links to both programs, and instructions for their use.

Get Spybot - Search & Destroy from http://security.kolla.de (This is the NEW Version 1.3) It will install right over an earlier version.
Get AdAware 6 from http://www.lavasoft.de/support/download

Download and install these programs in their own PERMANENT folders if you don't already have them. If you do have them, make sure they are UPDATED AND CONFIGURED AS DESCRIBED.

To run Spybot S&D:

After installing first press "Online", click on "Search for Updates", then select all updates. Next, press "Download Updates." Beside the download button is a little down-pointed arrow, which gives you a choice of several download sites; select one of the servers listed (usually it's best to choose the site nearest you). If that site doesn't work or you get an error message, try a different server.

When the updates are finished, close your browser and ALL WINDOWS EXCEPT THE ONE SPYBOT IS RUNNING IN, then press 'Check for Problems'; THE SCAN WILL TAKE SEVERAL MINUTES. Have SpyBot remove all it finds THAT ARE MARKED IN RED. When it's finished, reboot your system.

Then, Run ADAWARE:

Before you scan with AdAware, check for updates of the reference file by using the "webupdate" button at the lower right of the panel. The current ref file should read at least 01R310 23.05.2004 or a higher number/later date. Updates for this program come out frequently to keep up with new malware. THIS IS CRITICAL; updating is as important as installing these programs.

Then ……..

Make sure the following settings are made and on ——-"ON=GREEN"
From main window :Click "Start" then " Activate in-depth scan"

then……

click "Use custom scanning options>Customize" and have these options ON: "Scan within archives" ,"Scan active processes","Scan registry", "Deep scan registry" ,"Scan my IE Favorites for banned URL" and "Scan my host-files"

then………

go to settings(the gear icon on top of AdAware)>Tweak>Scanning engine and click "Unload recognized processes during scanning" ………..then…….."Cleaning engine" and "Let windows remove files in use at next reboot"

then…… click "proceed" to save your settings.

To scan, click NEXT. This scan will also take several minutes.

When the scan is finished, mark everything for removal and get rid of it. (Right-click the window and choose"select all" from the drop down menu) then press "next" and then say yes to the prompt, "do you want to remove all these entries?" Reboot again.

After you have run them, run HijackThis. CLOSE YOUR BROWSER AND ALL WINDOWS EXCEPT THE ONE IT'S RUNNING IN, and put a check in the box at the left end of ONLY the lines below. (Some of them may not still be there if you have run those programs. If they're gone, go on to the next item.) Then click on FIX CHECKED and let it run.


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - Default URLSearchHook is missing

(Stumbleupon is not well regarded; you may want to remove it. IT IS YOUR CHOICE.)
O2 - BHO: (no name) - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL

(SAME COMMENT)
O3 - Toolbar: StumbleUpon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL

(If YOU locked Internet Explorer, this is OK. If you DID NOT, then mark this for removal.)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm

(SAME COMMENT AS ABOVE)
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL/blogimage

(This is associated with GATOR spyware)
O8 - Extra context menu item: Subscribe in NewsGator - c:\progra~1\newsga~1\addref.htm

O9 - Extra button: Subscribe in NewsGator (HKLM)

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

(SAME COMMENT AS ABOVE)
O16 - DPF: {95844941-7934-4693-92D9-8202EA7B20ED} - http://www.stumbleupon.com/stumble.cab



When the program finishes, reboot into SAFE MODE (tap F8 after the BIOS loads, or use whatever other procedure your computer may require). Be sure you are configured to SHOW ALL FILES AND FOLDERS, including System and Hidden Files. If you don't know how to do that, follow this link http://www.xtra.co.nz/help/0,,4155-1916458,00.html and follow the step-by-step directions for your Windows version.

Now find and DELETE the following folders (if they are still there):

C:\PROGRAM FILES\DAP\
c:\program files\newsgator\
C:\PROGRAM FILES\STUMBLEUPON\<—-DELETE THIS IF YOU REMOVED THE PROGRAM


REBOOT into Normal Mode and post a fresh log so we can see what else may be needed.
Thank you very much for your time and attention to my problem.

I followed your instructions regarding Adaware and Spybot.

Here is the log, right after completing your instructions.

Ray



Logfile of HijackThis v1.97.7
Scan saved at 8:08:24 PM, on 5/26/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\Program Files\QuickCut Launcher\quickcut.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Trend Micro\Internet Security\pccguide.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.exe
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\QuickCut Launcher\quickcut.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Free Downloads Accelerator\fdaagent.exe
C:\Program Files\HiJackThis\HijackThis.exe
C:\Program Files\MYIE2\MyIE.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/advanced_search?hl=en
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.google.ca/advanced_search?hl=en
F2 - REG:system.ini: UserInit=E:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\userinit.exe,
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: (no name) - {98DE779A-2364-4293-AB71-2B97C61C4640} - C:\PROGRA~1\FREEDO~1\fdahlp99.dll
O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\System & Internet Washer\pkext.dll
O2 - BHO: (no name) - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\PROGRA~1\SECRET~1\smiehlp.dll
O2 - BHO: (no name) - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: StumbleUpon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore - The Search Accelerator Toolbar - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [QuickCut Launcher] C:\Program Files\QuickCut Launcher\quickcut.exe /startup
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: UCmore XP - The Search Accelerator.lnk = ?
O4 - Startup: MarketBrowser.lnk = C:\Program Files\MarketBrowser\lmt\mktbrws.exe
O4 - Global Startup: UCmore XP - The Search Accelerator.lnk = ?
O4 - Global Startup: MarketBrowser.lnk = C:\Program Files\MarketBrowser\lmt\mktbrws.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\System32\wweb32.dll/lookup.html
O8 - Extra context menu item: Add to Ad Hunter - C:\Program Files\MYIE2\config/blacklist.htm
O8 - Extra context menu item: Add To Net Snippets - C:\PROGRA~1\NETSNI~1\Res\Clipper.htm
O8 - Extra context menu item: Clear Fields &0 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComClearFields.html
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Download with Free Downloads Accelerator - C:\Program Files\Free Downloads Accelerator\fdaie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill && Submit &8 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillSubmit.html
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Fill Without Asking &9 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillWithoutAsking.html
O8 - Extra context menu item: Passcards &. - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditPass.html
O8 - Extra context menu item: Reset Fields &- - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComResetFields.html
O8 - Extra context menu item: RF Toolbar &2 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Set Fields &= - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSetFields.html
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\PROGRA~1\STUMBL~1\STUMBL~1.DLL/blogimage
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: MktBrowser (HKLM)
O9 - Extra 'Tools' menuitem: MarketBrowser (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Fill Id (HKLM)
O9 - Extra 'Tools' menuitem: Fill from Identity &; (HKLM)
O9 - Extra button: Fill Pass (HKLM)
O9 - Extra 'Tools' menuitem: Fill from Passcard &' (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &[ (HKLM)
O9 - Extra button: Go Fill (HKLM)
O9 - Extra 'Tools' menuitem: Go && Fill &6 (HKLM)
O9 - Extra button: Login (HKLM)
O9 - Extra 'Tools' menuitem: Login &7 (HKLM)
O9 - Extra button: Options (HKLM)
O9 - Extra 'Tools' menuitem: Rf Options &O (HKLM)
O9 - Extra button: Customize (HKLM)
O9 - Extra 'Tools' menuitem: Customize Menu &4 (HKLM)
O9 - Extra button: Generate (HKLM)
O9 - Extra 'Tools' menuitem: Password Generator &3 (HKLM)
O9 - Extra button: TaskBar (HKLM)
O9 - Extra 'Tools' menuitem: Robo TaskBar Icon &1 (HKLM)
O9 - Extra button: Set Fields (HKLM)
O9 - Extra 'Tools' menuitem: Set Fields &= (HKLM)
O9 - Extra button: Reset Fields (HKLM)
O9 - Extra 'Tools' menuitem: Reset Fields &- (HKLM)
O9 - Extra button: Clear Fields (HKLM)
O9 - Extra 'Tools' menuitem: Clear Fields &0 (HKLM)
O9 - Extra button: Logoff (HKLM)
O9 - Extra 'Tools' menuitem: Logoff &5 (HKLM)
O9 - Extra button: Fill Submit (HKLM)
O9 - Extra 'Tools' menuitem: Fill && Submit &8 (HKLM)
O9 - Extra button: Fill NoAsk (HKLM)
O9 - Extra 'Tools' menuitem: Fill Without Asking &9 (HKLM)
O9 - Extra button: UCmore Info (HKLM)
O9 - Extra button: Identities (HKLM)
O9 - Extra 'Tools' menuitem: Identities &, (HKLM)
O9 - Extra button: Passcards (HKLM)
O9 - Extra 'Tools' menuitem: Passcards &. (HKLM)
O9 - Extra button: Safenotes (HKLM)
O9 - Extra 'Tools' menuitem: SafeNotes &/ (HKLM)
O9 - Extra 'Tools' menuitem: UCmore help (HKLM)
O9 - Extra button: Snippets (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: System & Internet Washer (HKCU)
O15 - Trusted Zone: http://ql1.quicklaw.com
O16 - DPF: {08C818C3-2F1E-11D0-9223-00A0244D2920} (ChartFX IE Client Object) - http://www.fundlibrary.com/download/cfxax.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4B55FE21-325E-48D5-9B39-9B430D639EE8} (ScanFile.FileScan) - http://www.contentpurity.com/ScanFile.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25c34c0e601c58839523/…ip/RdxIE601.cab
O16 - DPF: {607DF741-7D0A-11D4-9EDC-005004189684} - http://www.ucmore.com/download/UCmoreIEx.cab
O16 - DPF: {763C10EE-E4C6-49AA-9325-F15ABF1C52B0} (X1 DownloadControl Class) - http://www.x1.com/download/X1WebInstall.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://vs03-us.protier.com/SupportFiles/client/msrdp.cab
O16 - DPF: {90918C20-FB99-495A-BD79-CB91ACF44887} - http://www.typingmaster.com/contents/tm200…ick/TMSetup.cab
O16 - DPF: {95844941-7934-4693-92D9-8202EA7B20ED} - http://www.stumbleupon.com/stumble.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8132.6300462963
O16 - DPF: {B817734E-046C-11D3-B674-00104BA25195} (PSNQuerySystem Class) - http://pmb001.3m.com/pub/psnotes/psnudate.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.dll
O16 - DPF: {CF051549-EDE1-40F5-B440-BCD646CF2C25} (Ppinstall Control) - http://www.163.com/wwwimages/sms/ppinstall22.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
Hi Ray,

That log looks a LOT better. I see you decided to keep Stumbleupon; that's fine, but be aware that it does have a hijacker component to it. At any rate, your computer should be acting much more normally now- that was a big load of crapware you took out of there. :D

There are still a frew stragglers to clean up, so start HijackThis and close your browser and all windows except the one it's running in. Put a mark beside ONLY the items listed below, click FIX CHECKED and let 'er rip!

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O3 - Toolbar: UCmore - The Search Accelerator Toolbar - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll

O16 - DPF: {4B55FE21-325E-48D5-9B39-9B430D639EE8} (ScanFile.FileScan) - http://www.contentpurity.com/ScanFile.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/25c34c0e601c58839523/…ip/RdxIE601.cab
O16 - DPF: {607DF741-7D0A-11D4-9EDC-005004189684} - http://www.ucmore.com/download/UCmoreIEx.cab
O16 - DPF: {763C10EE-E4C6-49AA-9325-F15ABF1C52B0} (X1 DownloadControl Class) - http://www.x1.com/download/X1WebInstall.cab


This should complete the cleanup. When it finishes, reboot and post a final log so we can be sure nothing remains. I'll also have a bit of advice about avoiding getting infected again.
Thank you K3dc. You have increased my happiness and reduced my suffering. You have earned much merit. What the hell did I have? Viruses? Performance is much better. The computer would crash and reboot at random, problem was there for weeks, now more steady. Thanks again. Much merit. Good karma.
UCmore seems useful to me. Is there some problem with it that is not obvious? What would I remove if wanted to keep UCmore. Thanks again for your time and attention. My computer is running much better. Ray
Hi Ray,

OK, I'm glad your compouter is behaving itself again. :D

Now that your log is clean, the trick is to KEEP IT THAT WAY! To increase your security, I recommend several things; I'll go over them one by one (they're painless, I assure you).

First, KEEP YOUR WINDOWS AND BROWSER UPDATED. As new security problems are found, Microsoft issues UPDATES to plug the holes that have been found. The top entry on your START menu should be "Windows Update," so this one is as easy as falling off a log. :weee:

Next, I recommend installing SpywareBlaster. It "inoculates" your computer against literally THOUSANDS of known malware items, and it works in such a way that it DOES NOT need to be running (and consuming system resources) to protect you. The program sets a "Kill-Bit" for each malware item, and then that thing can't download to your computer, or run if it's there. I don't know just how it works, but I can assure you IT DOES! Once the protection is set, all you have to do is check for updates about once a week, install them and run SB to set protection against the new items on the list. Once a Kill-Bit is set, you have PERMANENT protection from that item unless you remove it. Best of all, this is FREEWARE. Follow this link to download it: http://www.javacoolsoftware.com/spywareblaster.html

For a good overview of basic Internet security, this is a good article: http://boards.cexx.org/viewtopic.php?t=957 If I can leave you with one thought, it's this: Security is NOT a destination, it's an endless journey.
Glad we could help :D

As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI