I've read and followed the instructions in the "You Must Read This Before Posting Hijack logs" section. Problem still persists.
My log files posted as instructed in the above section.
Any assistance will be very much appreciated.
Gregga
Logfile of HijackThis v1.99.1
Scan saved at 11:37:15 PM, on 14/08/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\D-Link\DSL-200\dslstat.exe
C:\Program Files\D-Link\DSL-200\dslagent.exe
C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0803NetInstaller.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Gomez\GomezPEER\bin\GomezPEER.exe
C:\Program Files\IDETOOL\IDETOOL.EXE
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\YacsMon.exe
C:\PROGRA~1\Gomez\GOMEZP~1\jre\bin\java.exe
C:\Program Files\Caere\OmniPagePro90\EREG\REMIND32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\My Documents\MARS\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/My%20Documents/Bookmark.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.1.5.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\D-Link\DSL-200\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\D-Link\DSL-200\dslagent.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0803] "C:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0803NetInstaller.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\Caere\OmniPagePro90\EREG\REMIND32.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Gomez PEER.lnk = C:\Program Files\Gomez\GomezPEER\bin\GomezPEER.exe
O4 - Global Startup: IDETool.lnk = C:\Program Files\IDETOOL\IDETOOL.EXE
O4 - Global Startup: YacsMon.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE (file missing)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} (VacPro.internazionale_ver15) - http://advnt01.com/d...onale_ver15.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{F12B98EE-84FB-443A-8904-CC3738464B9A}: NameServer = 203.194.27.57 203.194.56.150
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:38:17 PM, 14/08/2005
+ Report-Checksum: A41EBCC7
+ Scan result:
:mozilla.6:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.15:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.16:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.17:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.18:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.21:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.91:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.92:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.93:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.94:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.95:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Paypopup : Cleaned with backup
:mozilla.100:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.101:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.102:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.103:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.104:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.105:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.106:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.107:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.108:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.109:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.110:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.111:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.112:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.113:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.117:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.118:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.120:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.121:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.122:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.123:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.124:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.127:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Weborama : Cleaned with backup
:mozilla.128:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Weborama : Cleaned with backup
:mozilla.129:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Weborama : Cleaned with backup
:mozilla.135:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.159:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.160:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.161:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.162:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.163:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.169:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.195:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.197:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.198:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.224:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.225:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.226:C:\Documents and Settings\mars\Application Data\Mozilla\Firefox\Profiles\71m4po67.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\mars\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\mars\Cookies\mars@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\mars\Cookies\mars@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\mars\Cookies\mars@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\My Documents\MARS\Website\a-files\asc-progs\plug&earn\KEYKEY.exe/\Vprotkkd._vx -> TrojanSpy.KeyKey2000.125.b : Cleaned with backup
::Report End