|  | 
 
															
															
	
			
			
				| w32.myzor.fk@yf HOMEPAGE OVERTAKEN by www.syssecuritysystem.com |  |  
					
					
				 
						| Junior Member 
   | 27. June 2006 @ 19:35 |  Link to this message   |  
						| 
							
							I have been dealing with this problem. It overtook my homepage yahoo.com.  Everytime I type the www.yahoo.com a www.syssystemsecurity.com web page takes over and it is advertising  PEST TRAP; MALWARE WIPE; SPY GUARD; BRAVE SENTRY; AD PROTECT;  Any help with getting rid of this problem will be greatly appreciated.  This is my HjT log:
Logfile of HijackThis v1.99.1
 Scan saved at 9:30:33 PM, on 6/27/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Nothing - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/...
 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/m...
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 |  
						| Advertisement   |   |  
						|  |  
						| Senior Member 
   | 28. June 2006 @ 03:20 |  Link to this message   |  
						| 
							
							Hi mibarbo,
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 
 |  
						| BochersNewbie 
   | 28. June 2006 @ 15:37 |  Link to this message   |  
						| 
							
							Jurppis,
 I am new to this, hope it is ok to jump in on this thread??
 
 I have exactly the same problem as mibarbo.
 
 I have been reading what other people have done with this problem and tryed to fix it. I have the read file reports for:
 
 SmitfraudFix : search (option 1) & clean (option 2)
 I also have a report from Panda ActiveScan and HijackThis.
 
 Are you able to advise???
 
 __________________
 SmitFraudFix v2.65
 
 Scan done at  0:00:04.95, Thu 29/06/2006
 Run from C:\Documents and Settings\Leo\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\atmclk.exe FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\ts.ico FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Leo\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Leo\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{af3fd9a8-1287-4159-9212-9a5b4494af70}"="ecosystems"
 
 [HKEY_CLASSES_ROOT\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32]
 @="C:\WINDOWS\system32\guxxa.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32]
 @="C:\WINDOWS\system32\guxxa.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 ___________________
 SmitFraudFix v2.65
 
 Scan done at  0:06:43.57, Thu 29/06/2006
 Run from C:\Documents and Settings\Leo\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{af3fd9a8-1287-4159-9212-9a5b4494af70}"="ecosystems"
 
 [HKEY_CLASSES_ROOT\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32]
 @="C:\WINDOWS\system32\guxxa.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32]
 @="C:\WINDOWS\system32\guxxa.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 C:\WINDOWS\system32\guxxa.dll -> Missing File
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\atmclk.exe Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\hp???.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\1024\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 PANDA ACTIVESCAN:
 ________________
 Incident                                                                        Status                        Location                                                                                                                                 Spyware:Cookie/Falkag                                                           Not disinfected               C:\Documents and Settings\Leo\Cookies\leo@as-us.falkag[2].txt
 Spyware:Cookie/Doubleclick                                                      Not disinfected               C:\Documents and Settings\Leo\Cookies\leo@doubleclick[1].txt
 Spyware:Cookie/SpyLog                                                           Not disinfected               C:\Documents and Settings\Leo\Cookies\leo@spylog[1].txt
 Potentially unwanted tool:Application/Processor                                 Not disinfected               C:\Documents and Settings\Leo\Desktop\SmitfraudFix\Process.exe
 Potentially unwanted tool:Application/Processor                                 Not disinfected               C:\Documents and Settings\Leo\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
 Potentially unwanted tool:Application/MyWay                                     Not disinfected               C:\Program Files\MyWay\myBar\1.bin\MY2NS.EXE
 Potentially unwanted tool:Application/MyWay                                     Not disinfected               C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 Potentially unwanted tool:Application/MyWay                                     Not disinfected               C:\Program Files\MyWay\myBar\1.bin\NPMYWAY.DLL
 Adware:Adware/KeenValue                                                         Not disinfected               C:\Program Files\PerfectNav\BHO\PerfectNav150c.dll
 Adware:Adware/KeenValue                                                         Not disinfected               C:\WINDOWS\browserxtras\pn\remove.exe
 Adware:adware/gator                                                             Not disinfected               C:\WINDOWS\GatorPdpSetup.log
 Potentially unwanted tool:application/bestoffer                                 Not disinfected               C:\WINDOWS\smdat32a.sys
 Virus:Trj/Qhost.AD                                                              Renamed                       C:\WINDOWS\system32\drivers\etc\hosts
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\adm.exe
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\adm25.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\adm4.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\admdata.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\admdloader.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\admfdi.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\admprog.dll
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\dmfiles.cab
 Potentially unwanted tool:Application/MyWay                                     Not disinfected               C:\WINDOWS\Temp\Altnet\mysearch.cab
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\pmexe.cab
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\pmfiles.cab
 Potentially unwanted tool:Application/Altnet                                    Not disinfected               C:\WINDOWS\Temp\Altnet\Setup.exe
 
 
 ___________________________
 Logfile of HijackThis v1.99.1
 Scan saved at 8:45:32 AM, on 29/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\ACS.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\WINDOWS\System32\DVDRAMSV.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
 C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
 C:\Program Files\EzButton\EzButton.EXE
 C:\Program Files\Apoint2K\Apoint.exe
 C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
 C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
 C:\WINDOWS\system32\dla\tfswctrl.exe
 C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe
 C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
 C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
 C:\Program Files\Apoint2K\Apntex.exe
 C:\WINDOWS\system32\RAMASST.exe
 c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\MROUTE~2.EXE
 C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE
 C:\Documents and Settings\Leo\Desktop\HijackThis_v1.99.1.exe
 
 O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
 O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
 O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
 O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
 O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
 O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
 O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe"
 O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [rcuemgdnopkqyyz] C:\WINDOWS\system32\jnyfkzkrcfxy.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 O4 - Global Startup: Phone Connection Monitor.lnk = ?
 O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: PC-cillin Personal firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
 O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
 
 
 Cheers, Bochers
 |  
						| Junior Member 
   | 28. June 2006 @ 15:58 |  Link to this message   |  
						| 
							
							Thanks Jurppis.  It worked but I am completely clean.  I did what you told me Desktop SMITFRAUD. Press 1 and this is my report from that 
 SmitFraudFix v2.65
 
 Scan done at 17:41:51.39, Wed 06/28/2006
 Run from C:\Documents and Settings\Manny Ibarbo\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Manny Ibarbo\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MANNYI~1\FAVORI~1
 
 C:\DOCUME~1\MANNYI~1\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 C:\DOCUME~1\ALLUSE~1\DESKTOP\Online Security Guide.url FOUND !
 C:\DOCUME~1\ALLUSE~1\DESKTOP\Security Troubleshooting.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\Security Toolbar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{af3fd9a8-1287-4159-9212-9a5b4494af70}"="ecosystems"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 Thanks for all your help, Let me know if you suggest doing something else to clean my system completely.  But that worked great.  Pressed 2 and cleaned it up. No more HOMEPAGE TAKE OVER.  Thanks A bunch. I really appreciate your help.
 |  
						| Junior Member 
   | 28. June 2006 @ 16:01 |  Link to this message   |  
						| 
							
							BOchers try doing what I did. It helped me.  Hopefully you will have the same luck.  I can now have my homepage back.  Thanks again to Jurppis.
							
						 |  
						| Senior Member 
   | 29. June 2006 @ 02:54 |  Link to this message   |  
						| 
							
							@Bochers
 Uninstall this program via add / remove programs in control panel: MyWay or MyWay Searchbar
 
 Then open HijackThis, do a system scan only and check these:
 
 O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
 O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
 O4 - HKLM\..\Run: [rcuemgdnopkqyyz] C:\WINDOWS\system32\jnyfkzkrcfxy.exe
 
 Close all other open windows and click fix cheked.
 
 Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml
 
 Delete this file:
 
 C:\WINDOWS\system32\->jnyfkzkrcfxy.exe
 
 And this foolder:
 
 C:\Program Files\->MyWay
 
 Then open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 
 Tha log is saved to your local diskdrive, usually C:\rapport.txt. Post also a new HijackThis log
 
 
 |  
						| BochersNewbie 
   | 29. June 2006 @ 17:47 |  Link to this message   |  
						| 
							
							G'day Jurppis,
 I appreciate your help!
 
 I have followed your instructions. However, there was no MyWay or MyWay Searchbar in add / remove programs. There was "My Search Bar", so i deleted that.
 
 When I did a Hijack This scan only:
 O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
 was present from the list of items you told me to check. So i clicked fix checked for that item only.
 
 When i re-started in safe mode and searched the C drive for the two files you told me to delete only MyWay was there. I deleted that only.
 
 I then did the SmitfraudFix option 2 and the Hijack This log. the details follow:
 
 SmitFraudFix v2.65
 
 Scan done at 11:20:39.93, Fri 30/06/2006
 Run from C:\Documents and Settings\Leo\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 _______________________
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 11:27:18 AM, on 30/06/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\System32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\System32\ACS.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
 C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 C:\WINDOWS\System32\DVDRAMSV.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
 C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
 C:\Program Files\EzButton\EzButton.EXE
 C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
 C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
 C:\WINDOWS\system32\dla\tfswctrl.exe
 C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
 C:\WINDOWS\AGRSMMSG.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe
 C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe
 C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
 C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
 C:\WINDOWS\system32\RAMASST.exe
 c:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\MROUTE~2.EXE
 C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Leo\Desktop\HijackThis_v1.99.1.exe
 
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
 O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
 O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
 O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
 O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
 O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
 O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
 O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
 O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\pccguide.exe"
 O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\PCCClient.exe"
 O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2003\Pop3trap.exe"
 O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [rcuemgdnopkqyyz] C:\WINDOWS\system32\jnyfkzkrcfxy.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 O4 - Global Startup: Phone Connection Monitor.lnk = ?
 O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
 O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe
 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
 O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
 O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
 O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: PC-cillin Personal firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\PccPfw.exe
 O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\Tmntsrv.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\PC-cillin 2003\tmproxy.exe
 
 
 How did I go???
 
 Another little odd thing, the mouse pad on my laptop wont work?? I can plug a mouse in and that works but the inbuilt pad does nothing. It happended when i was trying to shut down and re-open in safe mode. Any tips??? Is it related to the original problem???
 
 Thanks again for your help.
 
 Cheers, Bochers
 |  
						| Junior Member 
   | 29. June 2006 @ 18:37 |  Link to this message   |  
						| 
							
							JURPPIS, 
 PLEASE CHECK MY LOG FROM SMITFRAUD LET ME KNOW WHAT YOU THINK.
 SmitFraudFix v2.65
 
 Scan done at 17:41:51.39, Wed 06/28/2006
 Run from C:\Documents and Settings\Manny Ibarbo\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Manny Ibarbo\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MANNYI~1\FAVORI~1
 
 C:\DOCUME~1\MANNYI~1\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 C:\DOCUME~1\ALLUSE~1\DESKTOP\Online Security Guide.url FOUND !
 C:\DOCUME~1\ALLUSE~1\DESKTOP\Security Troubleshooting.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\Security Toolbar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{af3fd9a8-1287-4159-9212-9a5b4494af70}"="ecosystems"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 Apparently this fix the problem with W32.myzor.fk@yf, but do you think I should do something else to make my computer clean.  Thanks in advance from the advice, I greatly appreciate this.  Thanks again.
 |  
						| Senior Member 
   | 30. June 2006 @ 05:16 |  Link to this message   |  
						| 
							
							@Bochers
 Fix this line with HijackThis
 
 O4 - HKLM\..\Run: [rcuemgdnopkqyyz] C:\WINDOWS\system32\jnyfkzkrcfxy.exe
 
 Download Killbox by Option^Explicit
 http://www.downloads.subratam.org/KillBox.zip
 
 *Extract the programme to your desktop and double-click on its folder, then double-click on Killbox.exe to start the programme.
 *In the Killbox programme, select the Delete on Reboot option.
 *Copy the file name below to the clipboard by highlighting them and pressing Control + C or right click -> copy
 
 C:\WINDOWS\system32\jnyfkzkrcfxy.exe
 
 *Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
 
 *Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "Yes" at the reboot now prompt..
 
 If your computer doesn't restart, do it yourself. After restart, post a new HijackThis log.
 
 
 @mibarbo
 
 Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml
 
 Then open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 
 Tha log is saved to your local diskdrive, usually C:\rapport.txt. Post also a new HijackThis log
 
 
 |  
						| Junior Member 
   | 30. June 2006 @ 15:34 |  Link to this message   |  
						| 
							
							JURPPIS
I RAN ANOTHER REPORT FROM SMITFRAUD AND HERE IT IS:
 SmitFraudFix v2.65
 
 Scan done at 17:23:05.40, Fri 06/30/2006
 Run from C:\Documents and Settings\Manny Ibarbo\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 AND HERE IS MY HTJ LOG:
 Logfile of HijackThis v1.99.1
 Scan saved at 5:25:15 PM, on 6/30/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\explorer.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 LET ME KNOW WHAT MY NEXT STEP SHOULD BE:  THANKS FOR YOU HELP...
 |  
						| huck199Newbie 
   | 2. July 2006 @ 06:09 |  Link to this message   |  
						| 
							
							Help! Guys, I have read your thread and went through the same steps for the same problem. Now MSN is my default home page and I cannot change it.....What am I doing wrong??? Thanks for any advice anyone can provide!
 Huck
 |  
						| Senior Member 
   | 2. July 2006 @ 08:50 |  Link to this message   |  
						| 
							
							@mirabo
 Fix this with HijackThis
 
 O20 - AppInit_DLLs: nslookup.dll netdde.dll C:\WINDOWS\system32\netdde.dll
 
 Then download pocket killbox
 http://www.downloads.subratam.org/KillBox.zip
 Save it to desktop and run the program.
 Check: "delete on reboot"
 And click the "All files" option
 Then copy the text below by first "painting" it and then ctrl + c or right click -> copy
 
 C:\WINDOWS\system32\nslookup.dll
 C:\WINDOWS\system32\netdde.dll
 
 Then go back to killbox and click File -> Paste from clipboard
 After that click on the delete file (red and white button)
 Your computer should now reboot, if not, please do it manually.
 
 
 
 |  
						| Junior Member 
   | 2. July 2006 @ 10:03 |  Link to this message   |  
						| 
							
							JURPPIS, 
 DID EXACTLY WHAT YOU SAID TO DO.  DELETE THOSE TWO FILES USING KILLBOX.  THIS IS MY HjT LOG, WHAT DO YOU THINK:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 12:01:40 PM, on 7/2/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 THIS IS MY LOG, LET ME KNOW WHAT YOU THINK.  AGAIN YOU'VE BEEN A GREAT HELP.  THANK YOU.
 |  
						| Senior Member 
   | 3. July 2006 @ 04:23 |  Link to this message   |  
						| 
							
							Download Avenger by Swandog, and unzip it to your desktop or somewhere you can find it. (Do not run it yet). 
http://swandog46.geekstogo.com/avenger.zip
 
 Note: This programme is for use on Windows XP 32 bit systems only, and must be run from an account with Administor priviledges. If yours is a 64 bit version, do not use it, let me know.
 
 Open a Notepad file by clicking Start > Run and typing Notepad.exe in the box, click OK.
 
 Click Format, and ensure Word Wrap is unchecked.
 Copy and Paste all the text inside the quote below into Notepad.
 
 Quote:Now save the file as RemoveFiles.txt in a location where you can find it.Files to delete:
 C:\WINDOWS\system32\nslookup.dll
 C:\WINDOWS\system32\netdde.dll
 
 
 Start Avenger by double clicking on Avenger.exe.
 
 Check Load script from file:
 
 Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
 
 Double click it to enter it into Avenger.
 
 Click the green traffic light symbol.
 
 You will be asked if you want to execute the script, answer Yes.
 
 At this point you may get prompts from your protection systems, allow them please.
 
 Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
 
 Answer Yes, and allow your computer to re-boot.
 
 Upon re-boot a command window will briefly appear on screen (this is normal).
 
 A Notepad text file will be created C:\avenger.txt.
 
 Copy and Paste it into your next post please, along with a new HjT log.
 
 
 This message has been edited since posting. Last time this message was edited on 3. July 2006 @ 04:23 |  
						| Junior Member 
   | 3. July 2006 @ 05:25 |  Link to this message   |  
						| 
							
							JURPPIS, 
 THIS IS MY AVENGER LOG:
 Logfile of The Avenger version 1, by Swandog46
 Running from registry key:
 \Registry\Machine\System\CurrentControlSet\Services\ieqpngcp
 
 *******************
 
 Script file located at: \??\C:\Documents and Settings\klpee^ru.txt
 Script file opened successfully.
 
 Script file read successfully
 
 Backups directory opened successfully at C:\Avenger
 
 *******************
 
 Beginning to process script file:
 
 
 
 File C:\WINDOWS\system32\nslookup.dll not found!
 Deletion of file C:\WINDOWS\system32\nslookup.dll failed!
 
 Could not process line:
 C:\WINDOWS\system32\nslookup.dll
 Status: 0xc0000034
 
 
 
 File C:\WINDOWS\system32\netdde.dll not found!
 Deletion of file C:\WINDOWS\system32\netdde.dll failed!
 
 Could not process line:
 C:\WINDOWS\system32\netdde.dll
 Status: 0xc0000034
 
 
 Completed script processing.
 
 *******************
 
 Finished!  Terminate.
 
 AND THIS IS MY HjT LOG:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 7:24:22 AM, on 7/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 THANKS
 |  
						| Senior Member 
   | 4. July 2006 @ 08:33 |  Link to this message   |  
						| 
							
							Download WinPFind
http://www.bleepingcomputer.com/files/winpfind.php
 Right Click the Zip Folder and Select "Extract All"
 Extract it somewhere you will remember like the Desktop
 Doubleclick WinPFind.exe
 Click "Start Scan"
 It will scan the entire System, so please be patient!
 Once the Scan is Complete
 Go to the WinPFind folder
 Locate WinPFind.txt and post the contents here
 
 
 |  
						| Junior Member 
   | 5. July 2006 @ 04:01 |  Link to this message   |  
						| 
							
							JURPPIS,
 THIS IS WHAT'S SHOWING ON THAT REPORT:
 
 WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
 
 If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
 
 »»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
 Internet Explorer Version: 6.0.2900.2180
 
 »»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
 
 Checking %SystemDrive% folder...
 
 Checking %ProgramFilesDir% folder...
 
 Checking %WinDir% folder...
 UPX!                 10/5/2005 12:02:22 PM       38912      C:\WINDOWS\mtuninst.exe
 
 Checking %System% folder...
 UPX!                 10/5/2005 12:02:18 PM       136704     C:\WINDOWS\SYSTEM32\oins.exe
 PEC2                 6/9/2005 2:32:28 PM         692736     C:\WINDOWS\SYSTEM32\DivX.dll
 PECompact2           6/9/2005 2:32:28 PM         692736     C:\WINDOWS\SYSTEM32\DivX.dll
 Umonitor             8/4/2004 12:56:44 AM        657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
 PECompact2           6/8/2006 7:19:50 PM         5967776    C:\WINDOWS\SYSTEM32\MRT.exe
 aspack               6/8/2006 7:19:50 PM         5967776    C:\WINDOWS\SYSTEM32\MRT.exe
 aspack               8/4/2004 12:56:36 AM        708096     C:\WINDOWS\SYSTEM32\ntdll.dll
 PEC2                 8/18/2001 5:00:00 AM        41397      C:\WINDOWS\SYSTEM32\dfrg.msc
 PTech                5/17/2006 11:23:38 AM       579888     C:\WINDOWS\SYSTEM32\LegitCheckControl.dll
 winsync              8/18/2001 5:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\wbdbase.deu
 UPX!                 9/7/2001 11:06:18 AM        54784      C:\WINDOWS\SYSTEM32\XpBlock.dll
 
 Checking %System%\Drivers folder and sub-folders...
 PTech                8/3/2004 10:41:38 PM        1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys
 
 Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
 
 
 Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
 7/3/2006 7:21:10 AM       S 2048       C:\WINDOWS\bootstat.dat
 6/4/2006 11:55:32 PM     H  54156      C:\WINDOWS\QTFont.qfn
 7/4/2006 11:09:32 PM     H  1024       C:\WINDOWS\system32\config\system.LOG
 7/4/2006 11:19:38 PM     H  1024       C:\WINDOWS\system32\config\software.LOG
 7/4/2006 11:17:10 PM     H  1024       C:\WINDOWS\system32\config\default.LOG
 7/3/2006 7:21:14 AM      H  1024       C:\WINDOWS\system32\config\SAM.LOG
 7/4/2006 7:21:24 PM      H  1024       C:\WINDOWS\system32\config\SECURITY.LOG
 6/16/2006 12:07:40 AM    H  1024       C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
 5/18/2006 1:15:12 AM      S 10925      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB917344.cat
 6/1/2006 2:28:56 PM       S 11043      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB918439.cat
 5/17/2006 11:24:42 AM     S 7160       C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\WGA.cat
 5/29/2006 10:16:00 AM     S 23751      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB916281.cat
 5/14/2006 4:21:52 AM      S 13309      C:\WINDOWS\system32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB911280.cat
 5/17/2006 5:39:22 AM     HS 24         C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
 5/17/2006 5:39:22 AM     HS 388        C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\92aa2abf-8850-4ca9-a5ac-920ab930b00c
 7/3/2006 7:21:16 AM      H  6          C:\WINDOWS\Tasks\SA.DAT
 6/4/2006 3:42:28 PM      H  65536      C:\WINDOWS\Minidump\Mini060406-03.dmp
 6/4/2006 9:01:12 PM      H  65536      C:\WINDOWS\Minidump\Mini060406-04.dmp
 6/6/2006 4:52:10 PM      H  65536      C:\WINDOWS\Minidump\Mini060606-01.dmp
 6/18/2006 12:28:12 PM    H  65536      C:\WINDOWS\Minidump\Mini061806-01.dmp
 6/18/2006 11:34:14 PM    H  65536      C:\WINDOWS\Minidump\Mini061806-03.dmp
 
 Checking for CPL files...
 Squid Software OÜ              2/26/2005 10:30:54 AM       77312      C:\WINDOWS\SYSTEM32\P2P Networking v126.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
 Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        68608      C:\WINDOWS\SYSTEM32\access.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        148480     C:\WINDOWS\SYSTEM32\wscui.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        68608      C:\WINDOWS\SYSTEM32\joy.cpl
 Microsoft Corporation          8/18/2001 5:00:00 AM        187904     C:\WINDOWS\SYSTEM32\main.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
 Microsoft Corporation          8/18/2001 5:00:00 AM        35840      C:\WINDOWS\SYSTEM32\ncpa.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
 Microsoft Corporation          8/18/2001 5:00:00 AM        28160      C:\WINDOWS\SYSTEM32\telephon.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        94208      C:\WINDOWS\SYSTEM32\timedate.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        380416     C:\WINDOWS\SYSTEM32\irprops.cpl
 Sony Corporation               12/4/1999 4:11:30 AM        151552     C:\WINDOWS\SYSTEM32\UILib.cpl
 Sony Corporation               4/25/2001 5:36:14 PM        53248      C:\WINDOWS\SYSTEM32\VASetup.cpl
 Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        135168     C:\WINDOWS\SYSTEM32\desk.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        129536     C:\WINDOWS\SYSTEM32\intl.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        80384      C:\WINDOWS\SYSTEM32\firewall.cpl
 Microsoft Corporation          8/4/2004 12:56:58 AM        110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
 Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl
 
 »»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
 
 Checking files in %ALLUSERSPROFILE%\Startup folder...
 9/8/2001 11:07:12 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
 
 Checking files in %ALLUSERSPROFILE%\Application Data folder...
 9/8/2001 10:58:54 AM     HS 62         C:\Documents and Settings\All Users\Application Data\desktop.ini
 2/26/2005 8:11:46 AM        3085       C:\Documents and Settings\All Users\Application Data\hpzinstall.log
 
 Checking files in %USERPROFILE%\Startup folder...
 9/8/2001 11:07:12 AM     HS 84         C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\desktop.ini
 
 Checking files in %USERPROFILE%\Application Data folder...
 3/27/2006 11:47:04 PM       1406       C:\Documents and Settings\Manny Ibarbo\Application Data\AdobeDLM.log
 9/8/2001 10:58:52 AM     HS 62         C:\Documents and Settings\Manny Ibarbo\Application Data\desktop.ini
 2/28/2005 10:30:56 PM       0          C:\Documents and Settings\Manny Ibarbo\Application Data\dm.ini
 7/17/2005 11:23:34 PM       21232      C:\Documents and Settings\Manny Ibarbo\Application Data\GDIPFONTCACHEV1.DAT
 4/9/2006 11:23:18 PM        6055       C:\Documents and Settings\Manny Ibarbo\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
 
 »»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
 SV1	 =
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 
 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
 
 [HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\BriefcaseMenu
 {85BBD920-42A0-1069-A2E4-08002B30309D}	 = syncui.dll
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
 {750fdf0e-2a26-11d1-a3ea-080036587f03}	 = %SystemRoot%\System32\cscui.dll
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
 {09799AFB-AD67-11d1-ABCD-00C04FC30936}	 = %SystemRoot%\system32\SHELL32.dll
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
 {A470F8CF-A1E8-4f65-8335-227475AA5C46}	 = %SystemRoot%\system32\SHELL32.dll
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
 {5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}	 = C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
 Start Menu Pin	 = %SystemRoot%\system32\SHELL32.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\BriefcaseMenu
 {85BBD920-42A0-1069-A2E4-08002B30309D}	 = syncui.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
 {5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}	 = C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
 {A470F8CF-A1E8-4f65-8335-227475AA5C46}	 = %SystemRoot%\system32\SHELL32.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
 {750fdf0e-2a26-11d1-a3ea-080036587f03}	 = %SystemRoot%\System32\cscui.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
 {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}	 = ntshrui.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
 = %SystemRoot%\system32\SHELL32.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
 = %SystemRoot%\system32\SHELL32.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
 = %SystemRoot%\system32\SHELL32.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
 = %SystemRoot%\system32\SHELL32.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{F9DB5320-233E-11D1-9F84-707F02C10627}
 = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
 
 [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
 Adobe PDF Reader Link Helper = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
 = D:\Spybot - Search & Destroy\SDHelper.dll
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
 Google Toolbar Helper = c:\program files\google\googletoolbar2.dll
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}
 CNavExtBho Class = C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
 &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
 http://www.sony.com/vaiopeople = C:\WINDOWS\System32\Shdocvw.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
 {BA52B914-B692-46c4-B683-905236F6F655}	 = 	:
 {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}	 = Norton AntiVirus	: C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 {2318C2B1-4965-11d4-9B18-009027A5CD4F}	 = &Google	: c:\program files\google\googletoolbar2.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
 ButtonText	 = Real.com	:
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
 ButtonText	 = Messenger	: C:\Program Files\Messenger\msmsgs.exe
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{21569614-B795-46B1-85F4-E737A8DC09AD}
 Shell Search Band = %SystemRoot%\system32\browseui.dll
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
 =
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
 Favorites Band = %SystemRoot%\System32\shdocvw.dll
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
 {339BB23F-A864-48C0-A59F-29EA915965EC} = 	:
 {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} = Norton AntiVirus	: C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 {2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google	: c:\program files\google\googletoolbar2.dll
 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
 {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address	: %SystemRoot%\System32\browseui.dll
 {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links	: %SystemRoot%\system32\SHELL32.dll
 {EF99BD32-C1FB-11D2-892F-0090271D4F88} = &Yahoo! Toolbar	:
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 TkBellExe	"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
 IMAIL	Installed = 1
 MAPI	Installed = 1
 MSFS	Installed = 1
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
 backup	C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE
 item	Adobe Reader Speed Launch
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
 backup	C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE
 item	Adobe Reader Speed Launch
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
 backup	C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup
 location	Common Startup
 command	C:\Palm\HOTSYNC.EXE
 item	HotSync Manager
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
 backup	C:\WINDOWS\pss\HotSync Manager.lnkCommon Startup
 location	Common Startup
 command	C:\Palm\HOTSYNC.EXE
 item	HotSync Manager
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
 backup	C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
 item	HP Digital Imaging Monitor
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
 backup	C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
 item	HP Digital Imaging Monitor
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
 backup	C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe -s
 item	HP Image Zone Fast Start
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
 backup	C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe -s
 item	HP Image Zone Fast Start
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
 backup	C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l
 item	Microsoft Office
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
 backup	C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l
 item	Microsoft Office
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VAIO Action Setup (Server).lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VAIO Action Setup (Server).lnk
 backup	C:\WINDOWS\pss\VAIO Action Setup (Server).lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\Sony\VAIOAC~1\VAServ.exe
 item	VAIO Action Setup (Server)
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VAIO Action Setup (Server).lnk
 backup	C:\WINDOWS\pss\VAIO Action Setup (Server).lnkCommon Startup
 location	Common Startup
 command	C:\PROGRA~1\Sony\VAIOAC~1\VAServ.exe
 item	VAIO Action Setup (Server)
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
 backup	C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
 location	Common Startup
 command	C:\Program Files\WinZip\WZQKPICK.EXE
 item	WinZIP Quick Pick
 path	C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
 backup	C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
 location	Common Startup
 command	C:\Program Files\WinZip\WZQKPICK.EXE
 item	WinZIP Quick Pick
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Manny Ibarbo^Start Menu^Programs^Startup^Alarm Manager.LNK
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Alarm Manager.LNK
 backup	C:\WINDOWS\pss\Alarm Manager.LNKStartup
 location	Startup
 command	C:\Palm\AlarmApp.exe
 item	Alarm Manager
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Alarm Manager.LNK
 backup	C:\WINDOWS\pss\Alarm Manager.LNKStartup
 location	Startup
 command	C:\Palm\AlarmApp.exe
 item	Alarm Manager
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Manny Ibarbo^Start Menu^Programs^Startup^Norton Disk Doctor.lnk
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Norton Disk Doctor.lnk
 backup	C:\WINDOWS\pss\Norton Disk Doctor.lnkStartup
 location	Startup
 command	C:\PROGRA~1\NORTON~1\NORTON~1\NDD32.EXE /q
 item	Norton Disk Doctor
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Norton Disk Doctor.lnk
 backup	C:\WINDOWS\pss\Norton Disk Doctor.lnkStartup
 location	Startup
 command	C:\PROGRA~1\NORTON~1\NORTON~1\NDD32.EXE /q
 item	Norton Disk Doctor
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^Manny Ibarbo^Start Menu^Programs^Startup^Webshots.lnk
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Webshots.lnk
 backup	C:\WINDOWS\pss\Webshots.lnkStartup
 location	Startup
 command	C:\PROGRA~1\Webshots\Launcher.exe  /t
 item	Webshots
 path	C:\Documents and Settings\Manny Ibarbo\Start Menu\Programs\Startup\Webshots.lnk
 backup	C:\WINDOWS\pss\Webshots.lnkStartup
 location	Startup
 command	C:\PROGRA~1\Webshots\Launcher.exe  /t
 item	Webshots
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aqnz
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	MDTC~1
 hkey	HKCU
 command	C:\WINDOWS\system32\MDTC~1.EXE
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	MDTC~1
 hkey	HKCU
 command	C:\WINDOWS\system32\MDTC~1.EXE
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ccApp
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	ccApp
 hkey	HKLM
 command	"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	ccApp
 hkey	HKLM
 command	"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CHotkey
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	mHotkey
 hkey	HKLM
 command	mHotkey.exe
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	mHotkey
 hkey	HKLM
 command	mHotkey.exe
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ctfmon.exe
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	ctfmon
 hkey	HKCU
 command	C:\WINDOWS\system32\ctfmon.exe
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	ctfmon
 hkey	HKCU
 command	C:\WINDOWS\system32\ctfmon.exe
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Component Manager
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	hpcmpmgr
 hkey	HKLM
 command	"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	hpcmpmgr
 hkey	HKLM
 command	"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HP Software Update
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	HPWuSchd2
 hkey	HKLM
 command	C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	HPWuSchd2
 hkey	HKLM
 command	C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Iinl
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	winspool
 hkey	HKCU
 command	"C:\DOCUME~1\MANNYI~1\APPLIC~1\SSTEM~1\winspool.exe" -vt mtx
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	winspool
 hkey	HKCU
 command	"C:\DOCUME~1\MANNYI~1\APPLIC~1\SSTEM~1\winspool.exe" -vt mtx
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\KernelFaultCheck
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	dumprep 0 -k
 hkey	HKLM
 command	%systemroot%\system32\dumprep 0 -k
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	dumprep 0 -k
 hkey	HKLM
 command	%systemroot%\system32\dumprep 0 -k
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ledpointer
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	CNYHKey
 hkey	HKLM
 command	CNYHKey.exe
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	CNYHKey
 hkey	HKLM
 command	CNYHKey.exe
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MalwareWipe
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	MalwareWipe
 hkey	HKLM
 command	C:\Program Files\MalwareWipe\MalwareWipe.exe /h
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	MalwareWipe
 hkey	HKLM
 command	C:\Program Files\MalwareWipe\MalwareWipe.exe /h
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	msmsgs
 hkey	HKCU
 command	"C:\Program Files\Messenger\msmsgs.exe" /background
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	msmsgs
 hkey	HKCU
 command	"C:\Program Files\Messenger\msmsgs.exe" /background
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Norton SystemWorks
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	cfgwiz
 hkey	HKCU
 command	"C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	cfgwiz
 hkey	HKCU
 command	"C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NvCplDaemon
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	RUNDLL32
 hkey	HKLM
 command	RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	RUNDLL32
 hkey	HKLM
 command	RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PCTAVApp
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	PCTAV
 hkey	HKCU
 command	"D:\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	PCTAV
 hkey	HKCU
 command	"D:\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	qttask
 hkey	HKLM
 command	"C:\Program Files\QuickTime\qttask.exe" -atboottime
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	qttask
 hkey	HKLM
 command	"C:\Program Files\QuickTime\qttask.exe" -atboottime
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Registry Cleaner
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	RegClean
 hkey	HKCU
 command	"C:\Program Files\Registry Cleaner Trial\RegClean.exe"
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	RegClean
 hkey	HKCU
 command	"C:\Program Files\Registry Cleaner Trial\RegClean.exe"
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\REGSHAVE
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	REGSHAVE
 hkey	HKLM
 command	C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	REGSHAVE
 hkey	HKLM
 command	C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SpywareQuake.com
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	Spyware-Quake
 hkey	HKLM
 command	C:\Program Files\SpywareQuake.com\Spyware-Quake.exe /h
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	Spyware-Quake
 hkey	HKLM
 command	C:\Program Files\SpywareQuake.com\Spyware-Quake.exe /h
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Symantec NetDriver Monitor
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	SNDMon
 hkey	HKLM
 command	C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	SNDMon
 hkey	HKLM
 command	C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\TkBellExe
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	realsched
 hkey	HKLM
 command	"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	realsched
 hkey	HKLM
 command	"C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Trickler
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 hkey	HKLM
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 hkey	HKLM
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ZTgServerSwitch
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	server
 hkey	HKLM
 command	c:\program files\support.com\client\lserver\server.vbs
 inimapping	0
 key	SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 item	server
 hkey	HKLM
 command	c:\program files\support.com\client\lserver\server.vbs
 inimapping	0
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state
 system.ini	0
 win.ini	0
 bootini	0
 services	0
 startup	1
 
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
 {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
 {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
 {0DF44EAA-FF21-4412-828E-260A8728E7F1} =
 
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
 dontdisplaylastusername	0
 legalnoticecaption
 legalnoticetext
 shutdownwithoutlogon	1
 undockwithoutlogon	1
 
 
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
 
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
 
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 NoDriveTypeAutoRun	0
 
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
 
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall
 
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
 PostBootReminder               	{7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
 CDBurn                         	{fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
 WebCheck                       	{E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
 SysTray                        	{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
 UserInit	= C:\WINDOWS\system32\userinit.exe,
 Shell		= Explorer.exe
 System		=
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
 = crypt32.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
 = cryptnet.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
 = cscdll.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
 = wlnotify.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
 = wlnotify.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
 = sclgntfy.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
 = WlNotify.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
 = wlnotify.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
 = wlnotify.dll
 
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier
 = WRLogonNTF.dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
 Debugger = ntsd -d
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 AppInit_DLLs	nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
 WinPFind v1.4.1	- Log file written to "WinPFind.Txt" in the WinPFind folder.
 Scan completed on 7/4/2006 11:21:37 PM
 
 LET ME KNOW WHAT YOU THINK.
 |  
						| csun31Newbie 
   | 5. July 2006 @ 22:45 |  Link to this message   |  
						| 
							
							I'm having the same problem. Below is my log from HijackThis. Please let me know what to do next.
 Logfile of HijackThis v1.99.1
 Scan saved at 11:05:49 PM, on 7/5/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Symantec AntiVirus\DefWatch.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
 C:\Program Files\Write DVD!\saimon.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\PROGRA~1\SYMANT~1\VPTray.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Messenger\MSMSGS.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
 C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
 C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
 C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
 C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Hijackthis\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
 O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_3_12_0.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_4982.dll
 O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
 O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
 O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_3_12_0.dll
 O3 - Toolbar: (no name) - {5AA06644-BC46-4220-A460-47A6EB47C96D} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
 O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [Write DVD-R!] C:\Program Files\Write DVD!\saimon.exe
 O4 - HKLM\..\Run: [Popup Defence Updater] regsvr32 /s C:\WINDOWS\System32\pdfupd.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [vuxlzecvvjd] C:\WINDOWS\System32\oniyas.exe
 O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_4982.dll"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
 O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
 O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
 O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
 O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg_4982.dll"
 O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
 O4 - Startup: PowerReg Scheduler.exe
 O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: hp psc 1000 series.lnk = ?
 O4 - Global Startup: hpoddt01.exe.lnk = ?
 O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
 O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at1_x.cab
 O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
 O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
 O16 - DPF: {2F1CE98A-BB12-05EF-667A-506E5F6BE20D} - http://85.255.113.214/1/gdnUS2218.exe
 O16 - DPF: {30A3CCA5-F34C-4E87-BB57-5A2F2C935E14} (AMI DicomDir TreeView Control 2.0) - file://R:\cdviewer\CdViewer.cab
 O16 - DPF: {3659040C-8A9A-1CF5-7F35-539E4C742AEE} - http://85.255.113.214/1/gdnUS2218.exe
 O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple...
 O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
 O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/27a655ab0209567abd17/netzip/RdxIE601.cab
 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicr...
 O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\Documents and Settings\USER\Local Settings\Temp\EI40_\msxml4.cab
 O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yauto...
 O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
 O16 - DPF: {DADE1C2F-5A48-445C-82B5-3A5F102E84DF} (LifePicsUploader.UserControl1) - http://expressdigi.lifepics.com/common/UserUpload/LifePicsUploader.CAB
 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 |  
						| Senior Member 
   | 6. July 2006 @ 03:16 |  Link to this message   |  
						| 
							
							@mirabo
 First fix this again
 
 O20 - AppInit_DLLs: nslookup.dll netdde.dll C:\WINDOWS\system32\netdde.dll
 
 Then follow the instructios found here:
 http://www.outerinfo.com/howto.html
 
 Then delete these folders:
 
 C:\Program Files\MalwareWipe
 C:\Program Files\SpywareQuake.com
 
 Download and install Ewido Anti-Spyware 4.0 -> http://www.ewido.net/en/download/
 
 -> Open Ewido Anti-Spyware
 -> Click the Update icon at the top of the window
 -> Click the Start update button
 -> Wait for the update to download and install
 -> Click the Scanner icon at the top of the window
 -> Click the Settings tab then select Recommended Options and choose Quarantine
 -> Click the Scan tab
 -> Select Complete System Scan. The scanning begins.
 -> When the scan has completed, click on the Save Scan Report button and save the scan to your Desktop.
 -> Copy and paste the scan results into your next post
 Post also a new HijackThis log
 
 
 |  
						| Junior Member 
   | 6. July 2006 @ 20:05 |  Link to this message   |  
						| 
							
							JURPPIS 
 THIS IS MY EWIDO REPORT.
 
 --------------------------------------------------------
 ewido anti-spyware - Scan Report
 ---------------------------------------------------------
 
 + Created at:	9:59:48 PM 7/6/2006
 
 + Scan result:
 
 
 
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094097.exe -> Adware.ClickSpring : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_0\Seqn_1068 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_0\Seqn_1074 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_0\Level_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4492 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4496 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_0\Seqn_4543 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_2 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_3 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_1\Level_4 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_0\Seqn_1068 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_0\Seqn_1074 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_2\Level_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_0\Seqn_1068 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_0\Seqn_1074 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_3\Level_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_0 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1116 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1524 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1553 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_0\Seqn_1641 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_1 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_2 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Loct_4\Level_4 -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Queue -> Adware.Cydoor : No action taken.
 HKU\S-1-5-21-329068152-926492609-725345543-1004\Software\Kazaa\Promotions\Cydoor\Adwr_329\Services\Status -> Adware.Cydoor : No action taken.
 C:\WINDOWS\mtuninst.exe -> Adware.MediaTickets : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094094.dll -> Adware.PurityScan : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094095.dll -> Adware.PurityScan : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP271\A0095235.DLL -> Adware.PurityScan : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP271\A0095242.DLL -> Adware.PurityScan : No action taken.
 HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : No action taken.
 HKLM\SOFTWARE\Classes\Common.Buttons -> Adware.WebSearch : No action taken.
 HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : No action taken.
 HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Adware.WebSearch : No action taken.
 HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Adware.WebSearch : No action taken.
 C:\WINDOWS\system32\oins.exe -> Downloader.PurityScan.au : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094096.exe -> Downloader.PurityScan.co : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094130.exe -> Downloader.Zlob.jc : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094128.exe -> Downloader.Zlob.uz : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP265\A0094093.dll -> Downloader.Zlob.vn : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP264\A0093835.DLL -> Not-A-Virus.Hoax.Win32.Renos.du : No action taken.
 C:\System Volume Information\_restore{8357CB77-1DBD-43BC-B2F8-E849AAB0887F}\RP264\snapshot\MFEX-1.DAT -> Not-A-Virus.Hoax.Win32.Renos.du : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cratebarrel.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@entrepreneur.122.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@centrport[1].txt -> TrackingCookie.Centrport : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cz5.clickzs[1].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cz5.clickzs[3].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cz6.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cz7.clickzs[1].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@cz9.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@vip.clickzs[1].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@vip.clickzs[3].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@vip2.clickzs[1].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@vip2.clickzs[2].txt -> TrackingCookie.Clickzs : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@com[2].txt -> TrackingCookie.Com : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@sales.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@paycounter[2].txt -> TrackingCookie.Paycounter : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@paypopup[1].txt -> TrackingCookie.Paypopup : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@ads.pointroll[1].txt -> TrackingCookie.Pointroll : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@ads.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@sexlist[1].txt -> TrackingCookie.Sexlist : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@counter1.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@counter15.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@counter6.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@counter7.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@sextracker[2].txt -> TrackingCookie.Sextracker : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@starware[2].txt -> TrackingCookie.Starware : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@www.web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
 C:\Documents and Settings\Manny Ibarbo\Cookies\manny ibarbo@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
 
 
 ::Report end
 
 
 AND THIS IS MY HjT REPORT.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 10:03:57 PM, on 7/6/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\Program Files\ewido anti-spyware 4.0\guard.exe
 C:\Program Files\ewido anti-spyware 4.0\ewido.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 THANKS FOR ALL YOUR HELP.  THIS IS LIKE CHINESE TO ME.  CAN YOU EXPLAIN THE PROCESS WE ARE DOING.  WHAT ARE WE ACTUALLY LOOKING FOR??? THANKS AGAIN
 |  
						| Senior Member 
   | 8. July 2006 @ 02:16 |  Link to this message   |  
						| 
							
							Let's use avenger again, so open a notepad and copy the text below to notepad:
 Registry values to replace with dummy:
 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
 
 Now save the file as RemoveKeys.txt in a location where you can find it.
 
 Start Avenger by double clicking on Avenger.exe.
 
 Check Load script from file:
 
 Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
 
 Double click it to enter it into Avenger.
 
 Click the green traffic light symbol.
 
 You will be asked if you want to execute the script, answer Yes.
 
 At this point you may get prompts from your protection systems, allow them please.
 
 Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
 
 Answer Yes, and allow your computer to re-boot.
 
 Upon re-boot a command window will briefly appear on screen (this is normal).
 
 A Notepad text file will be created C:\avenger.txt.
 
 Copy and Paste it into your next post please, along with a new HjT log.
 
 @csun31
 
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 
 This message has been edited since posting. Last time this message was edited on 8. July 2006 @ 06:22 |  
						| Junior Member 
   | 9. July 2006 @ 16:03 |  Link to this message   |  
						| 
							
							I RECEIVED AN ERROR WHEN I DID THIS AVENGER AGAIN 
THIS IS WHAT I GOT.
 
 //////////////////////////////////////////
 Avenger Pre-Processor log
 //////////////////////////////////////////
 
 Error:  selected file does not appear to be a valid script.
 Error code: 1813
 
 THIS IS MY HjT REPORT
 
 Logfile of HijackThis v1.99.1
 Scan saved at 6:00:42 PM, on 7/9/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\ewido anti-spyware 4.0\guard.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\Program Files\ewido anti-spyware 4.0\ewido.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - AppInit_DLLs: nslookup.dll netdde.dll      C:\WINDOWS\system32\netdde.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 ALSO, I CAN'T REMOVE KAZAA FROM THE ADD REMOVE PROGRAM SECTION ANY SUGGESTIONS.  GIVES ME THIS
 
 INSTALLSHEILD (R) SETUP LAUNCHER HAS ENCOUNTERED A PROBLEM AND NEEDS TO CLOSE.  WE ARE SORRY FOR THE INCONVENIENCE.
 
 AND THAT'S ALL IT GIVE ME FOR DOES NOT LET ME REMOVE THE PROGRAM.  ANY SUGGESTIONS?????  THANKS
 |  
						| Senior Member 
   | 10. July 2006 @ 10:37 |  Link to this message   |  
						| 
							
							Open notepad and copy the text on the quote there
 Quote:Save the file to your desktop as Fix.Reg and make sure you save the file type as "all files" (*.*)Windows Registry Editor Version 5.00
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
 "AppInit_DLLs"=-
 
 
 Now, double click the "Fix.Reg" file (on your desktop) and answer YES to all the prompts.
 
 Then restart your computer and then post a new HijackThis log
 
 
 |  
						| Junior Member 
   | 10. July 2006 @ 19:33 |  Link to this message   |  
						| 
							
							THIS IS MY HjT LOG
 Logfile of HijackThis v1.99.1
 Scan saved at 9:32:33 PM, on 7/10/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\ewido anti-spyware 4.0\ewido.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\System32\cisvc.exe
 C:\Program Files\ewido anti-spyware 4.0\guard.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\cidaemon.exe
 C:\Documents and Settings\Manny Ibarbo\Desktop\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
 O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.c...
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
 O23 - Service: Norton AntiVirus firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
 O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
 O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 |  
						| Advertisement   |   |  
						| 
 |  
						| csun31Newbie 
   | 10. July 2006 @ 20:45 |  Link to this message   |  
						| 
							
							Jurppis
 Here's the output from SmitFraudFix
 
 
 SmitFraudFix v2.67
 
 Scan done at 21:40:40.25, Mon 07/10/2006
 Run from C:\Documents and Settings\USER\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\atmclk.exe FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\USER\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\USER\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\Security Toolbar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{6af69c4d-420a-4c95-b34f-e4635f84f53b}"="forevouched"
 
 [HKEY_CLASSES_ROOT\CLSID\{6af69c4d-420a-4c95-b34f-e4635f84f53b}\InProcServer32]
 @="C:\WINDOWS\system32\viwpzla.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{6af69c4d-420a-4c95-b34f-e4635f84f53b}\InProcServer32]
 @="C:\WINDOWS\system32\viwpzla.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 |  
					
					
				 |