I have Ad-Aware SE and Spybot S&D
I tried the bitdefender, but it seemed to me in infect me more
and none of them seemed to be able to get it all.
used some of the online scans. some froze, others only found problems and then asked for money(couldn't do without some type of testimonial or other guarentee)
alot of pop ups, Everytime a new explorer is opened, it resets the Privacy value to accept all cookies.. I usually have it prompt me when a cookie wants on my system.
any help from you would be very grateful
anyhow, on with the show:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 2:29:18 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\WINDOWS\system32\fhbddeat.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\b\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sinfulrum.sinnerz.org/cgi-bin/ik ... bd30d873d&
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {11D4DF68-827F-4061-3F8F-8EA6C38EC557} - C:\Program Files\WindowsUpdate\quzakew.dll (file missing)
O2 - BHO: (no name) - {3914CAA4-6BD5-419D-8ACC-8E78E1848071} - C:\Program Files\Common Files\menoq4444.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\fqrvqaib.dll
O2 - BHO: BndDrive2 BHO Class - {8FB5B012-E8CB-46cd-B6D2-ED428FAE9043} - C:\Program Files\ISM\BndDrive5.dll (file missing)
O2 - BHO: (no name) - {90B6A8D8-F962-4A3C-B577-2C45F6748025} - C:\WINDOWS\system32\pmkhi.dll (file missing)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\dhhuwvll.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C9E79ED9-D2CF-4CC9-9C4E-2EEA7C3F2E24} - C:\WINDOWS\system32\pmnlm.dll
O2 - BHO: (no name) - {E2EF984C-F4ED-4221-856F-A13B9BDEF2D2} - C:\Program Files\Common Files\menoq83122.dll
O2 - BHO: (no name) - {FF8CD237-A972-40B8-873C-12CD7F06AE69} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\dhhuwvll.dll
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P35 "EPSON Stylus CX4600 Series (Copy 1)" /O6 "USB003" /M "Stylus CX4600"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] I:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\etfbswtg.dll",sitypnow
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA2006] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFF7A4.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3152] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFF7A4.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4108] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFAAF1.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2089] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFAAF1.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1592] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF9814.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC561] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF9814.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5296] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF77A4.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9533] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF77A4.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8513] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF755B.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1931] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF755B.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9574] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF649C.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7185] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF649C.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2623] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF61A1.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6141] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF61A1.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1609] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF5C80.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC966] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF5C80.tmp"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe"
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB8210] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFF7A4.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3663] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFF7A4.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3241] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFAAF1.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8237] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DFAAF1.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9278] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF9814.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2993] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF9814.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9613] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF77A4.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD477] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF77A4.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB786] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF755B.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5615] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF755B.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5370] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF649C.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8232] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF649C.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB557] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF61A1.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2158] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF61A1.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1300] command /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF5C80.tmp"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4550] cmd /c del "C:\Documents and Settings\b\Local Settings\Temp\~DF5C80.tmp"
O4 - HKLM\..\Policies\Explorer\Run: [none] C:\Program Files\Video ActiveX Object\pmsngr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - ?p=ZRxdm429YYUS
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6dbd71fa876342cb84595ba0fcda57d8
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6dbd71fa876342cb84595ba0fcda57d8
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.deviantart.com
O15 - Trusted Zone: http://www.ebay.com
O15 - Trusted Zone: http://www.letsplaychess.com
O15 - Trusted Zone: *.msn.com
O15 - Trusted Zone: *.passport.net
O15 - Trusted Zone: *.xfire.com
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O16 - DPF: {0C7F3F20-8BAB-11D2-9432-00C04F8EF48F} (Downloadable Speech API) - http://activex.microsoft.com/activex/co ... pchapi.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Downl ... e-c283.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200 ... taller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex ... 0-3-18.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microso ... 8245011437
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 8245003734
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/fil ... nstall.cab
O16 - DPF: {B8F2846E-CE36-11D0-AC83-00C04FD97575} (Lernout & Hauspie TruVoice American English TTS Engine) - http://activex.microsoft.com/activex/co ... v_enua.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/p ... der_v5.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - mk:@MSITStore:C:\DOCUME~1\b\LOCALS~1\Temp\winfix.chm::/SystemDoctor2006FreeInstall.cab
O18 - Filter hijack: text/html - {BA576CDE-9949-4473-A8F7-6C17C2A7E600} - (no file)
O20 - Winlogon Notify: dhhuwvll - C:\WINDOWS\SYSTEM32\dhhuwvll.dll
O20 - Winlogon Notify: hgghhif - C:\WINDOWS\SYSTEM32\hgghhif.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\fhbddeat.exe
O23 - Service: Card Adapter (NETDown) - Unknown owner - C:\WINDOWS\smss.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\WindowsUpdate\rtejexaq.html
--
End of file - 14666 bytes