Stupid ads234

I can barely do anything without ads234 screwing up my computer


Logfile of HijackThis v1.98.2
Scan saved at 7:58:10 PM, on 11/13/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\windows\system\hpsysdrv.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\WINDOWS\system32\S3apphk.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
C:\documents and settings\owner\local settings\temp\PlKFXR.exe
C:\documents and settings\owner\local settings\temp\Wr2.exe
C:\documents and settings\owner\local settings\temp\O.exe
C:\documents and settings\owner\local settings\temp\7.exe
C:\WINDOWS\system32\adsldp50.exe
C:\WINDOWS\system32\bitsprx2.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\PROGRA~1\COMMON~1\LapLink\SCHEDU~1\LLSchEng.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\w?nspool.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\VTech\VTech Artificial Intelligence Learning TM Desktop Program\pclink.exe
C:\Palm\AlarmApp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Matt's work\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.sharempeg.com/find/
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.sharempeg.com/find/
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.sharempeg.com/find/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\homepage.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = C:\WINDOWS\homepage.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {69FF1505-EE66-7491-D151-66550483781E} - C:\WINDOWS\system32\ovtqpeyc.dll (file missing)
O2 - BHO: (no name) - {6FAF1459-E965-2A9F-8600-66550482731B} - C:\WINDOWS\system32\thdirpy.dll
O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Owner\Local Settings\Temp\Rk.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\mcafee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\mcafee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\Program Files\mcafee.com\Agent\mcupdate.exe /embedding
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [PlKFXR] C:\documents and settings\owner\local settings\temp\PlKFXR.exe
O4 - HKLM\..\Run: [rtMKoH] C:\documents and settings\owner\local settings\temp\rtMKoH.exe
O4 - HKLM\..\Run: [dl1Ux6JY] C:\documents and settings\owner\local settings\temp\dl1Ux6JY.exe
O4 - HKLM\..\Run: [n2lnr] C:\documents and settings\owner\local settings\temp\n2lnr.exe
O4 - HKLM\..\Run: [aSqou9] C:\documents and settings\owner\local settings\temp\aSqou9.exe
O4 - HKLM\..\Run: [6Obyt] C:\documents and settings\owner\local settings\temp\6Obyt.exe
O4 - HKLM\..\Run: [qUGo] C:\documents and settings\owner\local settings\temp\qUGo.exe
O4 - HKLM\..\Run: [ICFhu] C:\documents and settings\owner\local settings\temp\ICFhu.exe
O4 - HKLM\..\Run: [xB3e] c:\documents and settings\owner\local settings\temp\xB3e.exe
O4 - HKLM\..\Run: [CJ] C:\documents and settings\owner\local settings\temp\CJ.exe
O4 - HKLM\..\Run: [xVyck6I2f] C:\documents and settings\owner\local settings\temp\xVyck6I2f.exe
O4 - HKLM\..\Run: [tiHo] C:\documents and settings\owner\local settings\temp\tiHo.exe
O4 - HKLM\..\Run: [WQLM] C:\documents and settings\owner\local settings\temp\WQLM.exe
O4 - HKLM\..\Run: [W] C:\documents and settings\owner\local settings\temp\W.exe
O4 - HKLM\..\Run: [LVod9rWXU] C:\documents and settings\owner\local settings\temp\LVod9rWXU.exe
O4 - HKLM\..\Run: [zrICa9uyM] C:\documents and settings\owner\local settings\temp\zrICa9uyM.exe
O4 - HKLM\..\Run: [oj42zENq] C:\documents and settings\owner\local settings\temp\oj42zENq.exe
O4 - HKLM\..\Run: [d] C:\documents and settings\owner\local settings\temp\d.exe
O4 - HKLM\..\Run: [m] C:\documents and settings\owner\local settings\temp\M.exe
O4 - HKLM\..\Run: [aIPIi] C:\documents and settings\owner\local settings\temp\aIPIi.exe
O4 - HKLM\..\Run: [5] C:\documents and settings\owner\local settings\temp\5.exe
O4 - HKLM\..\Run: [EWsEt] C:\documents and settings\owner\local settings\temp\EWsEt.exe
O4 - HKLM\..\Run: [6S] C:\documents and settings\owner\local settings\temp\6S.exe
O4 - HKLM\..\Run: [xe48EfD] C:\documents and settings\owner\local settings\temp\xe48EfD.exe
O4 - HKLM\..\Run: [PH2l] C:\documents and settings\owner\local settings\temp\PH2l.exe
O4 - HKLM\..\Run: [YESH] C:\documents and settings\owner\local settings\temp\YESH.exe
O4 - HKLM\..\Run: [5kr3] C:\documents and settings\owner\local settings\temp\5kr3.exe
O4 - HKLM\..\Run: [HfPeUIFQ] C:\documents and settings\owner\local settings\temp\HfPeUIFQ.exe
O4 - HKLM\..\Run: [zNLTcEuLR] C:\documents and settings\owner\local settings\temp\zNLTcEuLR.exe
O4 - HKLM\..\Run: [zDl4XBCI] C:\documents and settings\owner\local settings\temp\zDl4XBCI.exe
O4 - HKLM\..\Run: [sFYr] C:\documents and settings\owner\local settings\temp\sFYr.exe
O4 - HKLM\..\Run: [pFW4UTdT] C:\documents and settings\owner\local settings\temp\pFW4UTdT.exe
O4 - HKLM\..\Run: [RwUvhdtM] C:\documents and settings\owner\local settings\temp\RwUvhdtM.exe
O4 - HKLM\..\Run: [jcoI7ct] C:\documents and settings\owner\local settings\temp\jcoI7ct.exe
O4 - HKLM\..\Run: [MfFYA] C:\documents and settings\owner\local settings\temp\MfFYA.exe
O4 - HKLM\..\Run: [L] C:\documents and settings\owner\local settings\temp\L.exe
O4 - HKLM\..\Run: [K1W] C:\documents and settings\owner\local settings\temp\K1W.exe
O4 - HKLM\..\Run: [dI1S] C:\documents and settings\owner\local settings\temp\dI1S.exe
O4 - HKLM\..\Run: [ixQN27] C:\documents and settings\owner\local settings\temp\ixQN27.exe
O4 - HKLM\..\Run: [f] C:\documents and settings\owner\local settings\temp\f.exe
O4 - HKLM\..\Run: [Wr2] C:\documents and settings\owner\local settings\temp\Wr2.exe
O4 - HKLM\..\Run: [O] C:\documents and settings\owner\local settings\temp\O.exe
O4 - HKLM\..\Run: [7] C:\documents and settings\owner\local settings\temp\7.exe
O4 - HKLM\..\Run: [62da79f6cecf] C:\WINDOWS\system32\adsldp50.exe
O4 - HKLM\..\Run: [299db309d2cd] C:\WINDOWS\system32\bitsprx2.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [xs9U3nX] h32seng.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - HKCU\..\Run: [Popup Defender] "C:\Program Files\Popup Defender\pd.exe" Minimize
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [gBq8Rhb9l] sxstsub.exe
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [Phqg] C:\WINDOWS\system32\w?nspool.exe
O4 - Startup: Alarm Manager.LNK = C:\Palm\AlarmApp.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PC Connection Manager.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmtrans.html
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4400/mcfscan.cab
O19 - User stylesheet: C:\WINDOWS\sample.txt

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    This is going to take a long time, due to all of the garbage in your log. I will be doing this in steps, so don't think that this will be solved after the first instructions.

    O4 - HKLM\..\Run: [PlKFXR] C:\documents and settings\owner\local settings\temp\PlKFXR.exe
    O4 - HKLM\..\Run: [rtMKoH] C:\documents and settings\owner\local settings\temp\rtMKoH.exe
    O4 - HKLM\..\Run: [dl1Ux6JY] C:\documents and settings\owner\local settings\temp\dl1Ux6JY.exe
    O4 - HKLM\..\Run: [n2lnr] C:\documents and settings\owner\local settings\temp\n2lnr.exe
    O4 - HKLM\..\Run: [aSqou9] C:\documents and settings\owner\local settings\temp\aSqou9.exe
    O4 - HKLM\..\Run: [6Obyt] C:\documents and settings\owner\local settings\temp\6Obyt.exe
    O4 - HKLM\..\Run: [qUGo] C:\documents and settings\owner\local settings\temp\qUGo.exe
    O4 - HKLM\..\Run: [ICFhu] C:\documents and settings\owner\local settings\temp\ICFhu.exe
    O4 - HKLM\..\Run: [xB3e] c:\documents and settings\owner\local settings\temp\xB3e.exe
    O4 - HKLM\..\Run: [CJ] C:\documents and settings\owner\local settings\temp\CJ.exe
    O4 - HKLM\..\Run: [xVyck6I2f] C:\documents and settings\owner\local settings\temp\xVyck6I2f.exe
    O4 - HKLM\..\Run: [tiHo] C:\documents and settings\owner\local settings\temp\tiHo.exe
    O4 - HKLM\..\Run: [WQLM] C:\documents and settings\owner\local settings\temp\WQLM.exe
    O4 - HKLM\..\Run: [W] C:\documents and settings\owner\local settings\temp\W.exe
    O4 - HKLM\..\Run: [LVod9rWXU] C:\documents and settings\owner\local settings\temp\LVod9rWXU.exe
    O4 - HKLM\..\Run: [zrICa9uyM] C:\documents and settings\owner\local settings\temp\zrICa9uyM.exe
    O4 - HKLM\..\Run: [oj42zENq] C:\documents and settings\owner\local settings\temp\oj42zENq.exe
    O4 - HKLM\..\Run: [d] C:\documents and settings\owner\local settings\temp\d.exe
    O4 - HKLM\..\Run: [m] C:\documents and settings\owner\local settings\temp\M.exe
    O4 - HKLM\..\Run: [aIPIi] C:\documents and settings\owner\local settings\temp\aIPIi.exe
    O4 - HKLM\..\Run: [5] C:\documents and settings\owner\local settings\temp\5.exe
    O4 - HKLM\..\Run: [EWsEt] C:\documents and settings\owner\local settings\temp\EWsEt.exe
    O4 - HKLM\..\Run: [6S] C:\documents and settings\owner\local settings\temp\6S.exe
    O4 - HKLM\..\Run: [xe48EfD] C:\documents and settings\owner\local settings\temp\xe48EfD.exe
    O4 - HKLM\..\Run: [PH2l] C:\documents and settings\owner\local settings\temp\PH2l.exe
    O4 - HKLM\..\Run: [YESH] C:\documents and settings\owner\local settings\temp\YESH.exe
    O4 - HKLM\..\Run: [5kr3] C:\documents and settings\owner\local settings\temp\5kr3.exe
    O4 - HKLM\..\Run: [HfPeUIFQ] C:\documents and settings\owner\local settings\temp\HfPeUIFQ.exe
    O4 - HKLM\..\Run: [zNLTcEuLR] C:\documents and settings\owner\local settings\temp\zNLTcEuLR.exe
    O4 - HKLM\..\Run: [zDl4XBCI] C:\documents and settings\owner\local settings\temp\zDl4XBCI.exe
    O4 - HKLM\..\Run: [sFYr] C:\documents and settings\owner\local settings\temp\sFYr.exe
    O4 - HKLM\..\Run: [pFW4UTdT] C:\documents and settings\owner\local settings\temp\pFW4UTdT.exe
    O4 - HKLM\..\Run: [RwUvhdtM] C:\documents and settings\owner\local settings\temp\RwUvhdtM.exe
    O4 - HKLM\..\Run: [jcoI7ct] C:\documents and settings\owner\local settings\temp\jcoI7ct.exe
    O4 - HKLM\..\Run: [MfFYA] C:\documents and settings\owner\local settings\temp\MfFYA.exe
    O4 - HKLM\..\Run: [L] C:\documents and settings\owner\local settings\temp\L.exe
    O4 - HKLM\..\Run: [K1W] C:\documents and settings\owner\local settings\temp\K1W.exe
    O4 - HKLM\..\Run: [dI1S] C:\documents and settings\owner\local settings\temp\dI1S.exe
    O4 - HKLM\..\Run: [ixQN27] C:\documents and settings\owner\local settings\temp\ixQN27.exe
    O4 - HKLM\..\Run: [f] C:\documents and settings\owner\local settings\temp\f.exe
    O4 - HKLM\..\Run: [Wr2] C:\documents and settings\owner\local settings\temp\Wr2.exe
    O4 - HKLM\..\Run: [O] C:\documents and settings\owner\local settings\temp\O.exe
    O4 - HKLM\..\Run: [7] C:\documents and settings\owner\local settings\temp\7.exe
    O4 - HKLM\..\Run: [62da79f6cecf] C:\WINDOWS\system32\adsldp50.exe
    O4 - HKLM\..\Run: [299db309d2cd] C:\WINDOWS\system32\bitsprx2.exe

    Fix those entries then find and delete the files listed above, reboot and post a new log.
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    Just to make it easier, unhide your hidden files\folders by going to folder options, then delete the entire contents of this folder to rid most of that stuff;

    C:\documents and settings\owner\local settings\temp<<<<<<<<
  • edited November 2004
    I went to delete the temp files and two of them wouldn't delete, they said that they were being used by another person or another computer. These files are ~DF21E5.tmp and INMEM000.REM

    I fixed/deleted the items in HijackThis and here is my new post

    Logfile of HijackThis v1.98.2
    Scan saved at 9:09:43 PM, on 11/14/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\windows\system\hpsysdrv.exe
    C:\Windows\system32\HpSrvUI.exe
    C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
    C:\WINDOWS\system32\S3apphk.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\System Soap Pro\soap.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Documents and Settings\Owner\Application Data\eber.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\w?nspool.exe
    C:\PROGRA~1\COMMON~1\LapLink\SCHEDU~1\LLSchEng.exe
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\VTech\VTech Artificial Intelligence Learning TM Desktop Program\pclink.exe
    C:\Palm\AlarmApp.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\Matt's work\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.sharempeg.com/find/
    R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.sharempeg.com/find/
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.sharempeg.com/find/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\homepage.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = C:\WINDOWS\homepage.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {69FF1505-EE66-7491-D151-66550483781E} - C:\WINDOWS\system32\ovtqpeyc.dll (file missing)
    O2 - BHO: (no name) - {6FAF1459-E965-2A9F-8600-66550482731B} - C:\WINDOWS\system32\thdirpy.dll
    O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
    O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
    O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\mcafee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\mcafee.com\Agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\Program Files\mcafee.com\Agent\mcupdate.exe /embedding
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [xs9U3nX] h32seng.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
    O4 - HKCU\..\Run: [Popup Defender] "C:\Program Files\Popup Defender\pd.exe" Minimize
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [gBq8Rhb9l] sxstsub.exe
    O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill.exe /startup
    O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
    O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
    O4 - HKCU\..\Run: [Phqg] C:\WINDOWS\system32\w?nspool.exe
    O4 - Startup: Alarm Manager.LNK = C:\Palm\AlarmApp.exe
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: PC Connection Manager.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page - res://c:\program files\google\GoogleToolbar_en_2.0.95-deleon.dll/cmtrans.html
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4400/mcfscan.cab
    O19 - User stylesheet: C:\WINDOWS\sample.txt
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    Download CWShredder from here and run it. Select the fix button & it will fix everything related to CoolWebSearch that is stored in it's database. Close ALL windows, including Internet Explorer, before running CWShredder. Reboot.

    To help prevent this from happening again, install the patches for the vulnerabilities that this hijacker exploits by going here for your critical updates.

    Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://1-se.com/srchasst.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\homepage.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://1-se.com/srchasst.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchv.com/w/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://1-se.com/srchasst.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = C:\WINDOWS\homepage.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)

    O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
    O2 - BHO: (no name) - {69FF1505-EE66-7491-D151-66550483781E} - C:\WINDOWS\system32\ovtqpeyc.dll (file missing)
    O2 - BHO: (no name) - {6FAF1459-E965-2A9F-8600-66550482731B} - C:\WINDOWS\system32\thdirpy.dll
    O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\System32\IETie.dll (file missing)

    O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL

    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [xs9U3nX] h32seng.exe
    O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
    O4 - HKCU\..\Run: [gBq8Rhb9l] sxstsub.exe
    O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
    O4 - HKCU\..\Run: [Phqg] C:\WINDOWS\system32\w?nspool.exe
    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe

    O19 - User stylesheet: C:\WINDOWS\sample.txt

    Reboot into safe mode by tapping f8 whilst starting your PC and delete these;

    C:\Program Files\MyWay< folder
    C:\Program Files\Viewpoint\Viewpoint Manager< folder
    C:\Program Files\System Soap Pro< folder

    C:\Documents and Settings\Owner\Application Data\eber.exe< file
    C:\WINDOWS\system32\w?nspool.exe< file

    Search for and delete these two; h32seng.exe, sxstsub.exe

    Reboot normally after doing this & post another log please.
  • edited November 2004
    Couldn't find these two: C:\Documents and Settings\Owner\Application Data\eber.exe< file and C:\WINDOWS\system32\w?nspool.exe< file
    Also, h32seng.exe and sxstsub.exe weren't found either.

    There were a few entries you listed that weren't there when i scanned and fixed/deleted the entries above.

    Logfile of HijackThis v1.98.2
    Scan saved at 8:28:24 PM, on 11/15/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\windows\system\hpsysdrv.exe
    C:\Windows\system32\HpSrvUI.exe
    C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
    C:\WINDOWS\system32\S3apphk.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
    C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\VTech\VTech Artificial Intelligence Learning TM Desktop Program\pclink.exe
    C:\PROGRA~1\COMMON~1\LapLink\SCHEDU~1\LLSchEng.exe
    C:\Palm\AlarmApp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Matt's work\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.east.cox.net/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar_en_2.0.95-deleon.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
    O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\mcafee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\mcafee.com\Agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\Program Files\mcafee.com\Agent\mcupdate.exe /embedding
  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    Your log looks okay now. Are you still having any problems?
  • edited November 2004
    So far, so good
  • edited November 2004
    oh-- thanx guys :thumbsup:
This discussion has been closed.