now i have what appears to be a popup window, before the actual windows logon screen, and have several errors crashing my windows logon , and every time i reboot .exe .com.lnk etc, are unassigned so they dont run.
Logfile of HijackThis v1.99.1
Scan saved at 8:56:22 AM, on 8/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O1 - Hosts: 207.68.172.246 msn.com
O2 - BHO: SDWin32 Class - {28C9E0EE-0E21-4406-A4DE-986C1466032A} - C:\WINDOWS\system32\vrqpx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [vrqpxc] C:\WINDOWS\system32\vrqpxc.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123809163546
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.35/ttinst.cab
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\hlzcon05.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
as well as my Ewido
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:46:06 AM, 8/16/2005
+ Report-Checksum: 35B09089
+ Scan result:
HKLM\SOFTWARE\DKSoftware -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\istsvc -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9EB320CE-BE1D-4304-A081-4B4665414BEF} -> Spyware.PurityScan : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -> Spyware.ComLoad : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\istsvc -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WCPR -> Spyware.WebRebates : Cleaned with backup
HKU\.DEFAULT\Software\Coulomb -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-19\Software\Coulomb -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-20\Software\Coulomb -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Coulomb -> Dialer.Generic : Cleaned with backup
[492] C:\WINDOWS\system32\hlzcon05.dll -> Spyware.Look2Me : Error during cleaning
[1100] C:\WINDOWS\system32\mbdtcprx.dll -> Spyware.Look2Me : Error during cleaning
[1220] C:\WINDOWS\system32\mbdtcprx.dll -> Spyware.Look2Me : Error during cleaning
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\97HRP5O4\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I1KXM16J\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I1KXM16J\AppWrap[4].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I54Z4JGX\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I54Z4JGX\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KFS80JKC\AppWrap[1].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KFS80JKC\AppWrap[2].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\KFS80JKC\AppWrap[3].exe -> TrojanDropper.Agent.pb : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\P6PT43DZ\!update-2214[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\P6PT43DZ\!update-2264[1].0000 -> Spyware.MediaTickets : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5OREFMH\!update-2204[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5OREFMH\!update-2224[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5OREFMH\!update-2234[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5OREFMH\!update-2254[1].0000 -> TrojanDownloader.PurityScan.y : Cleaned with backup
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\U5OREFMH\!update-2274[1].0000 -> Spyware.MediaTickets : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\070C58E6-6411-472B-99C6-2B154A\EE652BBF-33B8-4C44-A697-520AA8 -> Spyware.BookedSpace : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\240B74F2-5AF2-41E2-97A7-C08D23\7E00758E-EC34-4FE5-B539-AE9FF6 -> Spyware.BookedSpace : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\38574F20-5463-4983-A79B-8583FB\BFD0FE49-9959-467F-9F1C-E36B06 -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\7DEB117A-54C4-4F3C-B0A0-2B4CB2\01F3833A-18B4-47F7-BB6C-266C4C -> Adware.eZula : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\7DEB117A-54C4-4F3C-B0A0-2B4CB2\0D9E4D4A-0484-49A8-99EA-FF280A -> TrojanDownloader.OneClickSearch.k : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\7DEB117A-54C4-4F3C-B0A0-2B4CB2\C83F6F1E-8C06-4EB0-99CC-9C6FB9 -> Adware.eZula : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\87686875-C4FC-49C9-84BF-C4F557\02EFDC9E-D455-4711-AE5F-E36CC7 -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD : Cleaned with backup
:mozilla.15:C:\Program Files\support.com\backup\Co\cookies.txt\1173_5ff64a9f0_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.38:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.39:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.40:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.41:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.42:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.43:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.44:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.45:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.46:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.47:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.92:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Statcounter : Error during cleaning
:mozilla.106:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.107:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.108:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.109:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.158:C:\Program Files\support.com\backup\Co\cookies.txt\14909_51f03718e_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.55:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.56:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.57:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.58:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.59:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.60:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.93:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Statcounter : Error during cleaning
:mozilla.107:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.108:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.109:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.110:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.159:C:\Program Files\support.com\backup\Co\cookies.txt\15112_53410e2d7_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.47:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Googleadservices : Error during cleaning
:mozilla.85:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.86:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.87:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.88:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.89:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.90:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.117:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Statcounter : Error during cleaning
:mozilla.129:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.130:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.131:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.132:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.Yieldmanager : Error during cleaning
:mozilla.179:C:\Program Files\support.com\backup\Co\cookies.txt\17207_5733cea81_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.34:C:\Program Files\support.com\backup\Co\cookies.txt\2836_57fac3112_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.59:C:\Program Files\support.com\backup\Co\cookies.txt\6583_5d3aa3e66_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.74:C:\Program Files\support.com\backup\Co\cookies.txt\7940_511d93933_/cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\SYSTEM32\AUNPS2.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\dgcprop2.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\SYSTEM32\spe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\administrator@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
::Report End
Help if you can,
Thank You