Unsolved

This post is more than 5 years old

374

August 7th, 2006 13:00

HiJackThis Log---- Please help!

I keep receiving messages from my McAfee antivirus that PUPs have been found(multiple, and constant). For example here are just a couple: C:WINDOWS\NDNunistall7_14.exe, C:\WINDOWS\SYSTEM32\WinStat10.dll.

I have also received a message stating something about a NAIL.exe file that I believe is a potentially dangerous file.

Below is the scan log from HiJackThis:

Logfile of HijackThis v1.99.1
Scan saved at 9:01:42 AM, on 8/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Documents and Settings\Debra\Local Settings\Temp\wz2e8b\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WinStat - {0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF} - C:\WINDOWS\System32\WinStat13.dll (file missing)
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154631122796
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab
O16 - DPF: {ACEFFC26-4628-11D1-B14A-105C01C13001} (WSpell Spelling Checker Control) - https://www.pdesigner.com/pd3/htmlEditor/wspell.cab
O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://classlive.ecollege.com/~sdk/SDK/paste/lsiw2k.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe

4 Apprentice

 • 

20.5K Posts

August 8th, 2006 16:00

Welcome :)

That sounds like a neededware infection.

Please print these instructions so you can refer to them easily.

Please download CCleaner:
CCleaner
1. Before first use, select Options > Advanced and UNCHECK " Only delete files in Windows Temp folder older than 48 hours"
2. Then select the items you wish to clean up.
In the Windows Tab:
o Clean all entries in the "Internet Explorer" section except Cookies.
o Clean all the entries in the "Windows Explorer" section.
o Clean all entries in the "System" section.
o Clean all entries in the "Advanced" section.
o Clean any others that you choose.

In the Applications Tab:
o Clean all except cookies in the Firefox/Mozilla section if you use it.
o Clean all in the Opera section if you use it.
o Clean Sun Java in the Internet Section.
o Clean any others that you choose.

Exit CCleaner. Do not run it yet.

Download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program

  1. Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  2. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right click on ewido in the system tray and uncheck "Start with Windows".
  3. Go to Start > Run and type: services.msc
  4. Press "OK".
  5. In Services, click the "Extended tab" and scroll down the list to find ewido anti-spyware 4.0 guard.
  6. When you find the guard service, double-click on it.
  7. In the Properties Window > General Tab that opens, click the "Stop" button.
  8. From the drop-down menu next to "Startup Type", click on "Manual".
  9. Now click "Apply", then "OK" and close the Services window
  10. Once the setup is complete you will need run ewido and update the definition files.
  11. On the main screen select the icon "Update". Tthen select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • If you are having problems with the updater, manually update with the Ewido Full database installer from here.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
      • Close Ewido anti-spyware, Do Not run a scan just yet, we will shortly. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.
        Once in Safe Mode:

        Open CCleaner

        . Click the " Run Cleaner" button.
        A pop up box will appear advising this process will permanently delete files from your system.
        . Click " OK" and it will scan and clean your system.
        . Click " exit" when done.



        Open Ewido
        • Click on scanner
        • Click Complete System Scan
        • Let the program scan the machine
        While the scan is in progress you will be prompted to clean the first infected file it finds. Choose "remove", then put a check next to "Perform action on all infections" in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.
        Once the scan has completed, there will be a button located on the bottom of the screen named Save report
        • Click Save report
        • Save the report to your desktop
        • Exit Ewido
        Reboot into normal mode.
        Then, please run this online virus scan:
        ActiveScan
        You need to use Internet Explorer for this scan.
        Once you get to the Panda site, scroll down a bit and click on Scan your PC
        A new window will appear; click on Check Now!
        A new window will appear; fill in the boxes (Country, State, email addy)
        Click on Scan Now! >
        If you have never used ActiveScan before, you will be prompted to install an ActiveX control ( asinst.cab) : click on Install. Panda will install the component, and then install the latest signature files.
        From " Select a device to scan...", choose " My Computer"
        Allow the scan to run. It'll take a while.
        When complete,
        *Save the results from ActiveScan! Click on " See Report", and then on " Save report"; save it to a convenient location.

        Please delete your copy of HijackThis. It is running from a temp folder and that is not the best situation.
        Click HERE to download a self-extractable version of HijackThis.
        • Double click on hijackthis.exe to extract hijackthis to folder c:\hijackthis.
        • It will extract it to that folder and open the folder for you.
        • It will also create a shortcut on your desktop to HijackThis.

        • It will scan and the log should open in notepad.Click on "Edit > Select
        • All" then click on "Edit > Copy" to copy the entire contents of the
        • log.

        Come back here to this thread and paste the HijackThis log in your next reply. Also please copy the results from ActiveScan and paste them here along the report from Ewido.
        DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

        You will probably need several posts if your 3 logs are long because the forum software takes a limited amount of text.

      August 8th, 2006 20:00

      ewido anti-spyware - Scan Report
      ---------------------------------------------------------

      + Created at: 2:34:36 PM 8/8/2006

      + Scan result:



      C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP693\A0047813.dll -> Adware.Agent : Cleaned with backup (quarantined).
      C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP698\A0048204.exe -> Adware.Casino : Cleaned with backup (quarantined).
      C:\Documents and Settings\William R. Payne\Local Settings\Temp\ClrSch\FNuninstaller.EXE -> Adware.ClearSearch : Cleaned with backup (quarantined).
      C:\Program Files\Lycos\IEagent\CSBIINST.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined).
      HKLM\SOFTWARE\Classes\CLSID\{0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF} -> Adware.CreatrixMedia : Cleaned.
      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BAE99AF-A9F7-4f7e-9C72-2C1CC81BE0FF} -> Adware.CreatrixMedia : Cleaned.
      HKU\S-1-5-21-2280878977-2982371374-1583507531-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BAE99AF-A9F7-4F7E-9C72-2C1CC81BE0FF} -> Adware.CreatrixMedia : Cleaned.
      C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP698\A0048205.dll -> Adware.SpywareStorm : Cleaned with backup (quarantined).
      :mozilla.10:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.11:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.13:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.15:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.16:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.17:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.18:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
      :mozilla.19:C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).


      Incident Status Location

      Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\Debra\Application Data\Sskcwrd.dll
      Adware:adware/dealhelper Not disinfected c:\windows\dsearch1.bin
      Adware:adware/beginto Not disinfected c:\windows\system32\b2s_cache
      Adware:adware/sidesearch Not disinfected c:\program files\Lycos
      Adware:adware/bookedspace Not disinfected c:\windows\bsx32
      Adware:adware/transponder Not disinfected Windows Registry
      Adware:adware/ieplugin Not disinfected Windows Registry
      Spyware:spyware/clearsearch Not disinfected Windows Registry
      Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Debra\Application Data\Netscape\NSB\Profiles\6zgib336.default\cookies.txt[.atwola.com/]
      Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\Debra\Cookies\debra@anm.co[2].txt
      Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Debra\Cookies\debra@atwola[2].txt
      Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Debra\Cookies\debra@belnk[1].txt
      Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Debra\Cookies\debra@c2.gostats[2].txt
      Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Debra\Cookies\debra@cgi-bin[3].txt
      Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Debra\Cookies\debra@cgi-bin[4].txt
      Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Debra\Cookies\debra@ct.360i[2].txt
      Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Debra\Cookies\debra@did-it[1].txt
      Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Debra\Cookies\debra@dist.belnk[2].txt
      Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Debra\Cookies\debra@media.adrevolver[3].txt
      Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Debra\Cookies\debra@offeroptimizer[1].txt
      Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Debra\Cookies\debra@realmedia[1].txt
      Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Debra\Cookies\debra@toplist[1].txt
      Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\William R. Payne\Cookies\william r. payne@belnk[1].txt
      Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\William R. Payne\Cookies\william r. payne@winfixer[1].txt
      Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\William R. Payne\Local Settings\Temp\ClrSch\FNuninstaller.EX_
      Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\William R. Payne\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\CSTMINST[1].DL_[C:\Documents and Settings\William R. Payne\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\CSTMINST[1].DLl]





      Logfile of HijackThis v1.99.1
      Scan saved at 4:20:30 PM, on 8/8/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5450.0004)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\WINDOWS\System32\hkcmd.exe
      C:\WINDOWS\System32\igfxpers.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      C:\Program Files\McAfee.com\VSO\oasclnt.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\HJT\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      O2 - BHO: (no name) - SOFTWARE - (no file)
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
      O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
      O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
      O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
      O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
      O11 - Options group: [INTERNATIONAL] International*
      O15 - Trusted Zone: http://www.neededware.com
      O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
      O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
      O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} - http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154631122796
      O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.opentopia.com/support/activex/AxisCamControl.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {ACEFFC26-4628-11D1-B14A-105C01C13001} (WSpell Spelling Checker Control) - https://www.pdesigner.com/pd3/htmlEditor/wspell.cab
      O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://classlive.ecollege.com/~sdk/SDK/paste/lsiw2k.cab
      O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe

      4 Apprentice

       • 

      20.5K Posts

      August 8th, 2006 22:00

      Good job! We're getting there....

      We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.

      * Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
      * Click on Tools, General Settings
      * Under Real-time protection options, unselect the Turn on real-time protection check box
      * Click Save

      After ALL of the fixes are complete it is very important that you enable Real-time Protection again.

      Please download Brute Force Uninstaller to your desktop.
      http://www.merijn.org

      * Right-click the BFU folder on your desktop, and choose Extract All
      * Click "Next"
      * In the box to choose where to extract the files to,
      * Click "Browse"
      * Click on the + sign next to "My Computer"
      * Click on "Local Disk ( C: ) or whatever your primary drive is
      * Click "Make New Folder"
      * Type in BFU
      * Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

      RIGHT-CLICK HERE:
      http://downloads.subratam.org/Lon/sidekickFix.bat

      Choose "Save As" ( in IE it's "Save Target As" ) in order to download SideKickFix by LonnyRJones.
      Save it in the same folder you made earlier (c:\BFU).

      Please close ALL other open windows & explorer folder's, then double-click on sidekickFix.bat.
      Click YES and follow the prompts, when prompted to restart the PC please do so.

      Please launch HijackThis and place a check next to these:
      O2 - BHO: (no name) - SOFTWARE - (no file)
      O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
      O15 - Trusted Zone: http://www.neededware.com
      O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab


      Close all windows except HijackThis and click "Fix Checked".

      Reboot into Safemode:
      Turn on the computer.
      Immediately begin tapping the F8 key
      Use the arrow keys to highlight Safe Mode and press the Enter key.

      Configure to show all files/folders:
      Go to Start>Search and at the top select Tools>Folder Options
      Select the View tab
      Display the contents of system folders
      Show hidden files and folders
      Uncheck: Hide protected operating system files
      Click on Apply.
      Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
      Be sure the first three boxes are selected:
      Search System folders
      Search Hidden Files and folders
      Search SubFolders

      Delete the following files if they still exist:

      C:WINDOWS\ NDNunistall7_14.exe --file
      C:\WINDOWS\SYSTEM32\ WinStat10.dll --file
      c:\windows\ dsearch1.bin --file
      c:\windows\system32\ b2s_cache --file
      c:\program files\ Lycos -- FOLDER (Edited typo)
      c:\windows\ bsx32 --file

      Run CCleaner again.

      Reboot into Safemode again.

      Go back and rehide files:
      Go to Start>Search and at the top select Tools>Folder Options
      Select the View tab
      Display the contents of system folders
      Show hidden files and folders
      Check: Hide protected operating system files
      Click on Apply.

      Run your McAfee. If it finds those files again, make a note of their location and let me know.

      Reboot into normal mode after McAfee's scan and rescan with HijackThis.
      Please post a fresh log and let me know how things are running. Thanks :)

      Message Edited by Bugbatter on 08-09-200601:49 PM

      August 9th, 2006 15:00

      I just completed the last steps that you gave me. When I ran the McAffe scan it did not detect anything, but it never did to begin with.

      I always received messages from McAfee when I had my internet explorer open that said those files were trying to access my computer or were "PUPs". I would click to remove them, but immediatley after they would reappear with the same message from McAfee.

      I have not had any problems with the files since I completed these last steps and I hope that is the end of it. However, I have received a new error message during start up. It says " Windows Media Player- An internal application error has occured." I have tried going to the Windows website and reinstalling the Media Player, but I still get the same message.

      I am not sure if this error message has anything to do with the problems that I was having before. Should I contact someone else on this matter?


      Below is my latest HiJackThis scan:

      Logfile of HijackThis v1.99.1
      Scan saved at 11:50:02 AM, on 8/9/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5450.0004)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
      C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\WINDOWS\System32\hkcmd.exe
      C:\WINDOWS\System32\igfxpers.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
      C:\HJT\HijackThis.exe
      C:\WINDOWS\system32\wuauclt.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

      http://www.dell4me.com/myway
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

      http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

      http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

      http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

      http://go.microsoft.com/fwlink/?LinkId=56626&homepage=http://go.microsoft.com/fwlink/?LinkI

      d=55245&clcid={SUB_CLCID}
      O2 - BHO: (no name) - SOFTWARE - (no file)
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program

      Files\Yahoo!\Companion\Installs\cpn1\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

      Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} -

      c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
      O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} -

      c:\program files\mcafee.com\mps\popupkiller.dll
      O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program

      files\mcafee\spamkiller\mcapfbho.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

      Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -

      C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

      Files\Java\jre1.5.0_07\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

      files\google\googletoolbar2.dll
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -

      c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

      files\google\googletoolbar2.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

      Files\Yahoo!\Companion\Installs\cpn1\yt.dll
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
      O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
      O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
      O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM

      Toolbar\AIMBar.dll/aimsearch.htm
      O8 - Extra context menu item: &Google Search - res://c:\program

      files\google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://c:\program

      files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program

      Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Backward Links - res://c:\program

      files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

      files\google\GoogleToolbar2.dll/cmcache.html
      O8 - Extra context menu item: E&xport to Microsoft Excel -

      res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://c:\program

      files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://c:\program

      files\google\GoogleToolbar2.dll/cmtrans.html
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program

      Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program

      Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program

      Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

      Files\Java\jre1.5.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

      C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program

      files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter -

      {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

      Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

      C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network

      Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583}

      - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

      Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

      C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program

      Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation

      Tool) - http://go.microsoft.com/fwlink/?linkid=58813
      O16 - DPF: {09C6CAC0-936E-40A0-BC26-707480103DC3} -

      http://www.uproar.com/applets/activex/shizmoo/flipside_web18.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation

      Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program

      Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

      http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1154

      631122796
      O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -

      http://www.opentopia.com/support/activex/AxisCamControl.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

      http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {ACEFFC26-4628-11D1-B14A-105C01C13001} (WSpell Spelling Checker Control) -

      https://www.pdesigner.com/pd3/htmlEditor/wspell.cab
      O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) -

      http://classlive.ecollege.com/~sdk/SDK/paste/lsiw2k.cab
      O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -

      http://download.abacast.com/download/files/abasetup152.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -

      "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

      C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program

      Files\ewido anti-spyware 4.0\guard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

      C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program

      files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. -

      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc -

      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc -

      C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation -

      C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
      O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. -

      C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe

      4 Apprentice

       • 

      20.5K Posts

      August 9th, 2006 17:00

      Good job, so far. The malware that put itself into your trusted zones seems to be gone.

      When you reported: "I keep receiving messages from my McAfee antivirus that PUPs have been found(multiple, and constant). For example here are just a couple: C:WINDOWS\NDNunistall7_14.exe, C:\WINDOWS\SYSTEM32\WinStat10.dll."
      I thought you meant that McAfee was finding those on your computer. You did have some of it on there.

      We did not remove any WMP files, so I'm not sure why you are having a problem with WMP.
      Give this a try: http://www.bleepingcomputer.com/forums/topic54694.html

      If you have tried removing your WMP and reinstalling a fresh copy and that has not worked, post on the XP forum and see if they have any suggestions.
      If you absolutely cannot get rid of that WMP error, update ewido and run it again to see if it will clean any additional problems in System Restore. Then do a System Restore and start again with removal of the infection if it shows up (and it may return if your Restore Point is from when you were infected).
      ** Remember that Defender may prevent you from making changes to the Registry so disable Defender or work in Safemode when you are cleaning.

      There is just one more thing we still need to fix with HijackThis. Please boot into Safemode.
      Then launch HijackThis and place a check next to this:
      O2 - BHO: (no name) - SOFTWARE - (no file)

      Close all windows except HijackThis and click "Fix Checked".

      Reboot normally.

      Once you get WMP working, it would be good to flush System Restore so that you have clean Restore Points.
      If everything is running well....
      To flush the XP System Restore Points:
      (Using XP, you must be logged in as Administrator to do this.)
      Go to Start>Run and type msconfig Press enter.
      When msconfig opens, click the Launch System Restore Button.
      On the next page, click the System Restore Settings Link on the left.
      Check the box labeled Turn Off System Restore.

      Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

      Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

      You may have already taken some of these steps:
      1. Visit Windows Update:
      Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
      Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

      2. Adjust your security settings for ActiveX:
      Go to Internet Options/Security/Internet, press 'default level', then OK.
      Now press "Custom Level."
      In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

      3. Download and install the following free programs:
      a. SpywareBlaster:
      http://www.javacoolsoftware.com/spywareblaster.html
      Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
      b. SpywareGuard:
      http://www.javacoolsoftware.com/spywareguard.html
      Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
      Periodically check for updates in both programs.

      4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
      Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads
      Sunbelt Kerio has a free version: http://www.kerio.com/kpf_download.html

      5. You might consider installing Mozilla / Firefox.
      http://www.mozilla.org/

      6. Install spyware detection and removal programs:
      You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.

      a. Ad-aware: http://www.lavasoft.de/software/adaware/

      b. SpyBot S&D: http://safer-networking.org/en/news/2005-05-31.html

      I would check for updates in SpyBot once a week or so.
      Check for updates in Ad-aware frequently.

      If you have recently installed Ewido, it is a free trial product for 30 days. After that you can purchase it for full features OR you can also keep the free version to use as an on-demand scanner (recommended).
      You will still be able to manually update Ewido using the *update* button

      7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List.
      Here is the link:
      http://www.spywarewarrior.com/rogue_anti-spyware.htm
      If you want to know just how effective your anti-spyware program is, or how well any of the "rogue" programs listed at the above link work, check this for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm

      8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
      ** UNcheck the option to install the Yahoo toolbr.

      9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 7.08. It would be best to remove prior versions before updating to a new version.
      Info here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
      If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html


      10. Make sure you are using the most udpated version of Java.
      If you need to update, remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
      You can go here to download the latest version: Sun Java and click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.
      Proceed with reinstalling Java. Reboot.

      11. Here are some helpful articles:
      "So how did I get infected in the first place?"
      http://computercops.biz/postlite7736-.html

      "I'm not pulling your leg, honest"
      by Sandi Hardmeier
      http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

      Let us know if we have not resolved your problem.
      No Events found!

      Top