| I have a spyware problem |  | 
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 26. April 2006 @ 14:51 |  Link to this message   | 
					
					
					
						| 
							
							I have checked my pc with smitfraud, and hijack. I keep getting this annoying virus infection notice im my lower tool bar. My homepage keeps going to  safety defender. Please Someone help me.. i will post my logs..
Logfile of HijackThis v1.99.1
 Scan saved at 6:47:30 PM, on 4/26/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 C:\WINDOWS\system32\dcomcfg.exe
 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
 C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\Program Files\BigFix\BigFix.exe
 C:\Program Files\FinePixViewer\QuickDCF.exe
 C:\PROGRA~1\Webshots\webshots.scr
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
 C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\HijackThis_v1.99.1.exe
 
 O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\system32\hp9149.tmp
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
 O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
 O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
 O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
 O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
 O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
 O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
 O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
 O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
 O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
 O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll (file missing)
 O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll (file missing)
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTran...
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
 O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
 O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
 O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
 
 SmitFraudFix v2.34
 
 Scan done at 18:47:48.36, Wed 04/26/2006
 Run from C:\Program Files\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\hp????.tmp FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
 
 [HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
 @="%SystemRoot%\system32\browseui.dll"
 
 [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
 @="%SystemRoot%\system32\browseui.dll"
 
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
 
 [HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
 @="%SystemRoot%\system32\browseui.dll"
 
 [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
 @="%SystemRoot%\system32\browseui.dll"
 
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}"="Twain"
 
 [HKEY_CLASSES_ROOT\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}\InProcServer32]
 @="C:\WINDOWS\system32\twain32.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}\InProcServer32]
 @="C:\WINDOWS\system32\twain32.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						|  | 
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 26. April 2006 @ 15:15 |  Link to this message   | 
					
					
					
						| 
							
							Sorry if i didnt ask, but please someone help me out i know this has happened to many others. Please any assistance would be greatly appreciated. Thank you.
							
						 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 27. April 2006 @ 00:53 |  Link to this message   | 
					
					
					
						| 
							
							Hi cattfx
 I have first one thing that I'd like to do. It'd help also others :)
 
 Go here -> http://www.thespykiller.co.uk/forum/index.php?board=1.0
 and make a new topic. Name it eg. smitfraud/dcomcfg.exe. Then search and upload this file there, if found -> C:\WINDOWS\system32\dcomcfg.exe
 
 Put this as text:
 
 http://forums.afterdawn.com/thread_view.cfm/335923
 
 After that:
 
 * Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
 * Delete this file -> C:\WINDOWS\system32\dcomcfg.exe
 * Open Smitfraudfix folder and double-click smitfraudfix.cmd
 * Select 2 and hit Enter to delete infect files.
 * You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
 * The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
 * A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt
 
 Reboot, send a fresh HjT log and contents of c:\rapport.txt
 | 
				
				
			
				
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 27. April 2006 @ 02:14 |  Link to this message   | 
					
					
					
						| 
							
							Thank you so very much for the help. here are my new logs.
 Logfile of HijackThis v1.99.1
 Scan saved at 6:12:29 AM, on 4/27/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
 C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\Program Files\BigFix\BigFix.exe
 
 
 SmitFraudFix v2.35
 
 Scan done at  6:01:37.86, Thu 04/27/2006
 Run from C:\Program Files\SmitfraudFix\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\hp????.tmp Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 It is gone now!! A thousand thank yous!!
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 27. April 2006 @ 02:18 |  Link to this message   | 
					
					
					
						| 
							
							HjT log isn´t complete. Resend it.
 I asked you to upload that file to spykiller,  but you only posted HjT log and smitfraudfix log :(
 
 Or did you also upload that file to spykiller?
 
 Did you delete this already ? ->
 
 C:\WINDOWS\system32\dcomcfg.exe
 This message has been edited since posting. Last time this message was edited on 27. April 2006 @ 02:22 | 
				
				
			
				
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 27. April 2006 @ 15:54 |  Link to this message   | 
					
					
					
						| 
							
							I will post it all in there sorry, and i deleted what you told me and it worked. I cannot thank you enough.
							
						 | 
				
				
			
				
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 27. April 2006 @ 16:04 |  Link to this message   | 
					
					
					
						| 
							
							Logfile of HijackThis v1.99.1
Scan saved at 8:03:30 PM, on 4/27/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\WINDOWS\system32\igfxpers.exe
 C:\Program Files\McAfee.com\VSO\oasclnt.exe
 C:\PROGRA~1\mcafee.com\agent\mcagent.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
 C:\WINDOWS\RTHDCPL.EXE
 C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 c:\program files\mcafee.com\agent\mcdetect.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
 c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
 C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe
 C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
 c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 C:\Program Files\BigFix\BigFix.exe
 C:\Program Files\FinePixViewer\QuickDCF.exe
 C:\PROGRA~1\Webshots\webshots.scr
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
 C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
 C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
 C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
 O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe"
 O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
 O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
 O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
 O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
 O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
 O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
 O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
 O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
 O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
 O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
 O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
 O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
 O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\Samsung Media Studio\SamsungMediaStudioAgent.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
 O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
 O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
 O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
 O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll (file missing)
 O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll (file missing)
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTran...
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
 O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
 O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
 O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
 O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
 O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
 O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
 O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
 O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 27. April 2006 @ 22:56 |  Link to this message   | 
					
					
					
						| 
							
							You're welcome :)
 But your log isn't clean
 
 Open HjT, click do a system scan only, checkmark these and press fix checked:
 
 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
 O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTran...
 
 Also, I highly recommend to uninstall WeatherBug via add/remove programs in control panel, but it's optional
 
 If you decide to do it, fix that line too:
 
 O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
 
 And delete this folder:
 
 C:\PROGRA~1\AWS
 
 Reboot and send a fresh HjT log
 | 
				
				
			
				
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 28. April 2006 @ 02:11 |  Link to this message   | 
					
					
					
						| 
							
							is having weatherbug bad? or can i still use it?
							
						 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 28. April 2006 @ 02:24 |  Link to this message   | 
					
					
					
						| 
							
							Well, it's open to debate. You decide whether or not to remove it.
 Here is more about it:
 
 Quote:]WeatherBug is a system tray icon that offers weather information and includes built-in ads. WeatherBug is controlled by AWS Convergence Technologies (weatherbugmedia.com).
 There is some controversy over whether WeatherBug should be targeted by anti-parasite software. AWS strongly deny their software is ?spyware?, and by the definition used here,
 it is not, as it does not leak information back to its controlling servers.However, WeatherBug has in the past been silently installed by the FavoriteMan parasite and Freeze.com
 screensavers, and more recently has been bundled by software such as AIM and Blubster. This makes it ?unsolicited?, and since it is installed to raise money for its creators through
 the built-in ads it is certainly ?commercial?. So it does meet the definition for ?parasite?: unsolicited commercial software. It is nonetheless listed as a borderline case because
 it is not overtly harmful and many people do install it deliberately.WeatherBug bundles the MySearch parasite in its standalone distribution and has in the past, installed Gator and SVAPlayer.
 
 | 
				
				
			
				
				
				
				
				
					
						| cattfxSuspended due to non-functional email address 
   | 28. April 2006 @ 02:29 |  Link to this message   | 
					
					
					
						| 
							
							Is there any other problems you see with my pc? It is working much better now.
							
						 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						| 
 | 
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 28. April 2006 @ 02:32 |  Link to this message   | 
					
					
					
						|  |