Its clear why MS Antispy is having problems, There is
alot of malware on this system including a Trojan running
as a Windows service and alot of malicious BHO's and
registered dll files.
Ive addressed most of this with you Tom through email and
with you saying Hijack This is giving errors messages
when its run I will need to see a new Hijack This log
after you follow the steps Ive sent, Ive covered all the
area's except the BHO's for now untill we can get a log
without error's to be sure all these really do exist on
your system.
For anyone else thats interested in this here is the
Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 12:38:13 PM, on 9/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft
Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\mobile PhoneTools\WatchDog.exe
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\edspfkvq.exe
C:\WINDOWS\System32\gkijotgg.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\vptray.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\BacsTray.exe
C:\WINDOWS\System32\LVComS.exe
C:\WINDOWS\System32\atwtusb.exe
C:\Program Files\Roxio\Easy CD Creator 5
\DirectCD\DirectCD.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Zinio\ZINIOD~2.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Search Bar =
http://g.msn.com/0SEENUS/SAOS10
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/ycomp_wave/defau
lts/sp/*
http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local
Page = \blank.htm
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00000000-0000-0000-0000-
000000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-09F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-18F5-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-46F5-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-6CF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-83F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C0C-89F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C1C-09F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C1C-6CF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C1C-C0F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C1C-F8F4-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C2C-7CF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C2C-8EF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C2C-94F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C2C-FCF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C3C-0EF5-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C3C-7BF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C3C-C0F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C3C-E9F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C4C-1EF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C4C-2DF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C4C-30F6-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C4C-83F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C4C-B7F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C5C-82F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C5C-86F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C5C-CFF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C5C-D4F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C6C-70F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C7C-3FF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C7C-89F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C7C-95F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C7C-C4F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C8C-4DF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C8C-56F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C8C-A4F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C8C-DBF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-09F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-0DF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-49F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-58F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-82F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-9BF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8C9C-B1F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CAC-1EF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CAC-59F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CAC-BDF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CAC-DBF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CBC-14F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CBC-2AF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CBC-5EF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CBC-7DF6-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CBC-86F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CCC-49F6-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CCC-FCF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-3BF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-58F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-5DF3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-64F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-7CF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-C2F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CDC-EEF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-04F5-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-1EF3-86B8-
4F8000000000} - C:\WINDOWS\System32\elbsbwzm.dll
O2 - BHO: (no name) - {00000000-8CEC-2EF5-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-57F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-7DF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-81F6-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-99F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-A6F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-ACF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CEC-E7F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CFC-05F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CFC-18F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CFC-46F3-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CFC-7FF2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {00000000-8CFC-86F2-86B8-
4F8000000000} - (no file)
O2 - BHO: (no name) - {02A9B1AF-FA78-8F55-E813-
79AC63E93DAC} - (no file)
O2 - BHO: (no name) - {02ED3B71-C797-B4DB-35AC-
290173BB8B57} - C:\WINDOWS\System32\jcybrrfc.dll
O2 - BHO: (no name) - {045B6D0E-1643-A457-3E41-
BA7DBEF2FA05} - C:\WINDOWS\System32\ivqqyjgh.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-
784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0
\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0D716366-6E08-3A36-1B74-
C78B359375F7} - C:\WINDOWS\System32\nzohzogs.dll
O2 - BHO: (no name) - {0F7A4037-9717-A9A2-AB67-
E4F974F0A0AC} - (no file)
O2 - BHO: (no name) - {12E67A3D-9521-3435-1D18-
F5F08CFDED59} - C:\WINDOWS\System32\dfqdlqvl.dll
O2 - BHO: (no name) - {1474E082-F626-659A-4FF1-
53ED5D1A1B36} - C:\WINDOWS\System32\mkkqwzir.dll
O2 - BHO: (no name) - {1613A562-4F61-2E49-8DE7-
6CD55AD2BFFE} - C:\WINDOWS\System32\pvipeeso.dll
O2 - BHO: (no name) - {173135B1-7554-F07E-C040-
2464F3EEE741} - (no file)
O2 - BHO: (no name) - {18300A05-DE93-90DB-B33A-
1E67C389EFF8} - C:\WINDOWS\System32\vpiqfvbn.dll
O2 - BHO: (no name) - {18F79A1D-752E-E30E-34FF-
9B561E48D0BD} - C:\WINDOWS\System32\iowkmzgu.dll
O2 - BHO: (no name) - {1DD7BD3D-8C68-9A7C-4E0D-
218601867084} - C:\WINDOWS\System32\jmdirnpr.dll
O2 - BHO: (no name) - {1E7B20FF-3879-E219-D882-
639D3E862924} - C:\WINDOWS\System32\pzgmlavc.dll
O2 - BHO: (no name) - {1F19F7E9-40F9-8984-CD59-
6E71B0373047} - C:\WINDOWS\System32\hjmtmaff.dll
O2 - BHO: (no name) - {285BFA91-4B57-3163-93D6-
620B195A7F19} - C:\WINDOWS\System32\lcemwkni.dll
O2 - BHO: (no name) - {3214CC72-FA7B-5FAB-3EC6-
A620AB1EBD05} - (no file)
O2 - BHO: (no name) - {3555F295-1BDD-87B4-6F74-
895D78B51515} - (no file)
O2 - BHO: (no name) - {3B3DAEF0-B223-FD4F-C4BF-
BAC89AF7D1F3} - C:\WINDOWS\System32\onlpdjnc.dll
O2 - BHO: (no name) - {4082DC47-CA2D-5E99-ACC9-
31C4D58DEAB1} - C:\WINDOWS\System32\nfejface.dll
O2 - BHO: (no name) - {42622627-5992-E8BB-DE14-
8962715BE6F1} - (no file)
O2 - BHO: (no name) - {4642ED85-462D-6CC0-0BA4-
3F0D985F31E3} - C:\WINDOWS\System32\nfyfttnp.dll
O2 - BHO: (no name) - {475B27B5-E655-6D17-C110-
97436CD11403} - C:\WINDOWS\System32\mvmucyff.dll
O2 - BHO: (no name) - {49CA0B1C-4AD5-06F3-8291-
9E4C03A1AE03} - C:\WINDOWS\System32\szdbszau.dll
O2 - BHO: (no name) - {5D71F9A3-FEB6-7293-FD31-
DE62D1746A9E} - C:\WINDOWS\System32\mvzrekpg.dll
O2 - BHO: (no name) - {61CA28E7-0159-2254-D876-
532B6E4FD806} - C:\WINDOWS\System32\evlsdxit.dll
O2 - BHO: (no name) - {63E52570-AF1D-D180-1049-
0B4E24C2C05B} - (no file)
O2 - BHO: (no name) - {6505D32A-30BE-BDE8-B359-
C55FDA22A9A4} - C:\WINDOWS\System32\iooyojyp.dll
O2 - BHO: (no name) - {71598069-6FB2-5528-C1B9-
4AA63672488B} - C:\WINDOWS\System32\rnemvglp.dll
O2 - BHO: (no name) - {71C6A408-D603-F1C8-1B9C-
FD7D58A24471} - (no file)
O2 - BHO: (no name) - {73F4697A-C267-74BB-A73B-
EA82515BFB3A} - C:\WINDOWS\System32\ccdowoid.dll
O2 - BHO: (no name) - {7494C5DC-4D7F-ABAA-7D45-
D986F10608CA} - C:\WINDOWS\System32\crhuqmst.dll
O2 - BHO: (no name) - {77E7FC8C-9EEF-D5FF-E2F9-
0E4B542805B1} - (no file)
O2 - BHO: (no name) - {78537AAF-71A7-6C09-C9F4-
5D117A9E043F} - (no file)
O2 - BHO: (no name) - {788FF0ED-A487-C883-7D5B-
ADBC6ACCB595} - (no file)
O2 - BHO: (no name) - {7FB5BA17-587A-69C9-D925-
745645DDC9F4} - (no file)
O2 - BHO: (no name) - {805E8F05-0FD5-1517-3232-
67D96BE18527} - (no file)
O2 - BHO: (no name) - {83C76515-CD6C-21C3-6DFC-
2019C31EF132} - (no file)
O2 - BHO: (no name) - {8609E8DF-14E1-5C1C-065D-
1878694A8F45} - C:\WINDOWS\System32\dwvrcvps.dll
O2 - BHO: (no name) - {863264D6-2C10-332A-85D5-
85F4D08A46B9} - C:\WINDOWS\System32\kcgvlrif.dll
O2 - BHO: (no name) - {87EEE9C1-94AC-FE1B-2C2F-
0DDAB72412AB} - C:\WINDOWS\System32\onpkgjsr.dll
O2 - BHO: (no name) - {8823ACD0-FCDA-5C76-35DA-
6B7B6D4EFE40} - C:\WINDOWS\System32\oapklyiw.dll
O2 - BHO: (no name) - {897A32D9-E4AC-85E9-B5E2-
7FFE068FC7CB} - C:\WINDOWS\System32\iveydvpi.dll
O2 - BHO: (no name) - {8BB558FC-602D-F399-6679-
7C068A4F352D} - C:\WINDOWS\System32\nnzaqidd.dll
O2 - BHO: (no name) - {8DC9C9E5-D24E-C6C9-3A88-
CEF90D2396FA} - C:\WINDOWS\System32\ipekltzs.dll
O2 - BHO: (no name) - {8E2F1A1E-7A3D-F761-325B-
08535B26FAFD} - C:\WINDOWS\System32\ebfbtgqj.dll
O2 - BHO: (no name) - {A01D539E-4F32-7547-8B23-
45285283B698} - C:\WINDOWS\System32\jbtsrguo.dll
O2 - BHO: (no name) - {A0E688B8-CF92-F164-F113-
B2E2A1D22DE1} - C:\WINDOWS\System32\ncsuussu.dll
O2 - BHO: (no name) - {AEEF4CAD-680F-72E4-0ED5-
BAF5E07AC2FE} - C:\WINDOWS\System32\wevmizcu.dll
O2 - BHO: (no name) - {B4A8F8AB-E3E0-7B31-15CE-
4F7728E698D7} - C:\WINDOWS\System32\qhzkhttx.dll
O2 - BHO: (no name) - {B4AEC008-1472-84E9-3AFA-
513CBD9842DC} - (no file)
O2 - BHO: (no name) - {B786E699-866C-4626-C5D4-
2B6F8FE20EA6} - (no file)
O2 - BHO: (no name) - {B7A7DB25-8FDA-7DE7-525F-
C3F024B42AA3} - C:\WINDOWS\System32\oqdvuilu.dll
O2 - BHO: (no name) - {B89F73B5-E9EA-22E5-5809-
C72283B74640} - C:\WINDOWS\System32\uujdzmol.dll (file
missing)
O2 - BHO: (no name) - {B8C5FC76-3F54-55B5-BEF6-
0D13E44B2B1C} - C:\WINDOWS\System32\eqgshdok.dll
O2 - BHO: (no name) - {B9CCF110-D3A1-BF96-F0B0-
812C29093517} - C:\WINDOWS\System32\qchxzqub.dll
O2 - BHO: (no name) - {BA43817B-F38D-5430-08F9-
53BEC4858163} - C:\WINDOWS\System32\zvmdfwab.dll
O2 - BHO: (no name) - {BA726186-E62C-7051-996A-
069F01BF5C34} - C:\WINDOWS\System32\cgujlnpl.dll
O2 - BHO: (no name) - {BB08CAB5-1703-6BE0-298D-
C845C96E3CF0} - C:\WINDOWS\System32\oygwtson.dll
O2 - BHO: (no name) - {BC4FDB86-0B48-5534-D67D-
AEE57B75570C} - C:\WINDOWS\System32\rkhgswtr.dll
O2 - BHO: (no name) - {BC6B6C36-BFBA-6B88-A4B1-
F50330C97894} - C:\WINDOWS\System32\pmnzzntn.dll
O2 - BHO: (no name) - {BE4566C3-089B-9E7E-6CC7-
98DE1AD4C97B} - C:\WINDOWS\System32\cdhidwxt.dll
O2 - BHO: (no name) - {BFAEEDFF-4F2B-667A-8E42-
8A2D8B29C8CF} - C:\WINDOWS\System32\bimdglxq.dll
O2 - BHO: (no name) - {C04D419E-7A56-C63F-3912-
9DC9E99FE70E} - C:\WINDOWS\System32\xvtdycxy.dll
O2 - BHO: (no name) - {C095BEA3-0479-D922-495B-
BCFCD192DEA2} - C:\WINDOWS\System32\xtxbchxk.dll
O2 - BHO: (no name) - {C7B435C1-0976-7DEE-7446-
1C25E646B2A9} - C:\WINDOWS\System32\nvqzrnye.dll
O2 - BHO: (no name) - {C854A979-38D2-1617-FA78-
1DD0370F70AB} - C:\WINDOWS\System32\ufoqarya.dll
O2 - BHO: (no name) - {C880D186-6E56-6A80-D714-
2A2117BC1CA7} - C:\WINDOWS\System32\nhkggwah.dll
O2 - BHO: (no name) - {CA083A0B-AFBD-0D3F-EE4D-
66D506ADC5EB} - (no file)
O2 - BHO: (no name) - {CCBAF492-78E4-8029-207B-
3B13DC7FEFC4} - C:\WINDOWS\System32\khvruaal.dll
O2 - BHO: (no name) - {CCE369AA-9EE0-A0D9-647B-
5093115A3BA6} - C:\WINDOWS\System32\fuljtgcj.dll
O2 - BHO: (no name) - {D0770B02-7C53-055E-10F2-
9AC005377967} - C:\WINDOWS\System32\yjdasrog.dll
O2 - BHO: (no name) - {D137D368-22A6-FC25-70AF-
92461CF31AB3} - C:\WINDOWS\System32\bsytsqrj.dll
O2 - BHO: (no name) - {D21603CE-D656-4079-2B04-
51337AC509F7} - C:\WINDOWS\System32\vwkskhqd.dll
O2 - BHO: (no name) - {D5CAC08D-5774-D832-17CD-
1F8F8FE43BE9} - (no file)
O2 - BHO: (no name) - {D724DCA2-E957-F707-B4C3-
2518696874C3} - C:\WINDOWS\System32\rlnaitba.dll
O2 - BHO: (no name) - {D8C23904-74ED-AEF5-89CD-
941C8A1301D2} - C:\WINDOWS\System32\rsypcrtq.dll
O2 - BHO: (no name) - {DC2EBB02-51F6-1E98-68D0-
7DBE87B3CD48} - C:\WINDOWS\System32\nzhsuhmd.dll
O2 - BHO: (no name) - {DE7DA19C-815E-B8D8-A1F3-
C6C2B321935C} - C:\WINDOWS\System32\qcwkdshy.dll
O2 - BHO: (no name) - {DE897551-F44C-91FA-8ACD-
EEC5D9CAD5B2} - (no file)
O2 - BHO: (no name) - {DF71111A-DA89-614E-0BDE-
BB6685E21212} - C:\WINDOWS\System32\zeucwera.dll
O2 - BHO: (no name) - {DFC09B61-47FE-B672-D012-
465E5E09C113} - C:\WINDOWS\System32\wrviyhcy.dll
O2 - BHO: (no name) - {E0F7289A-D079-78B2-3377-
A389D4184A3A} - C:\WINDOWS\System32\hddufhhs.dll
O2 - BHO: (no name) - {E2E62109-8C90-5A41-BD84-
CA6B131343A1} - (no file)
O2 - BHO: (no name) - {F1C5ECF5-F915-7DB7-95E9-
A3192B37C279} - C:\WINDOWS\System32\osmespdn.dll
O2 - BHO: (no name) - {F2431834-9950-FBC7-7290-
BEA9A75EA0ED} - C:\WINDOWS\System32\txosopue.dll
O2 - BHO: (no name) - {F4A9D0A3-C5F5-B783-8735-
7350678402CB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common
Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32
\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile
PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [Apoint] C:\Program
Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program
Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program
Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [edspfkvq] C:\WINDOWS\System32
\edspfkvq.exe
O4 - HKLM\..\Run: [gkijotgg] C:\WINDOWS\System32
\gkijotgg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [vptray] C:\Program
Files\Symantec_Client_Security\Symantec
AntiVirus\vptray.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program
Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program
Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32
\DSentry.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program
Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan
Remover\Trjscan.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN
Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Zinio DLM] C:\PROGRA~1
\Zinio\ZINIOD~2.EXE /hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32
\ctfmon.exe
O4 - Startup: GatherPlace Launcher.lnk = C:\Program
Files\GatherWorks\OmniView\GPAgent.exe
O4 - Global Startup: Venturi 2.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth -
C:\Program Files\Dell\Bluetooth
Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Program Files\Java\jre1.5.0_04
\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-
4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-
3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: ATLApplicationLocatorAXInstall -
http://24.123.240.54/LaunchVCPC.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623}
(AlternaTIFF ActiveX) -
http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
(Windows Genuine Advantage) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD}
(Stamps.com Secure Postal Account Registration) -
https://secure.stamps.com/download/us/registration/3_0_0_8
34/sdcregie.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo!
Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yac
scom.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}
(MiniBugTransporterX Class) -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/Mini
BugTransporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB}
(YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yins
t20040510.cab
O16 - DPF: {324FDCCE-2C0B-41F8-8EB0-6263A24A8323} -
http://support.gatherworks.com/client/omniview.cab
O16 - DPF: {52A5CD24-64C6-4BAF-A4EC-4D13F451763F} (CU
LiveUpdate Control) -
http://ctmexpress.fvc.com/ctmexpress/runtime/pic/inner_pic
/packages/liveupdate.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE
Class) -
http://software-
dl.real.com/28a63e026ab488531d20/netzip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en
/x86/client/wuweb_site.cab?1121976293913
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
(MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloa
der.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
(iTunesDetector Class) -
http://ax.phobos.apple.com.edgesuite.net/detection/ITDetec
tor.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
(GpcContainer Class) -
https://vbricksupport.webex.com/client/v_mywebex-
t20/webex/ieatgpc.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6}
(McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/vso/en-
us/tools/mcfscan/2,0,0,4571/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
westcoast.fvc.com
O17 - HKLM\Software\..\Telephony: DomainName =
westcoast.fvc.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C70C263-09DA-
4E87-B32B-C60311667373}: NameServer =
213.166.0.210,213.166.0.218
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
westcoast.fvc.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
westcoast.fvc.com
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-
E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32
\NavLogon.dll
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM,
Inc. - C:\Program Files\Dell\Bluetooth
Software\bin\btwdins.exe
O23 - Service: DefWatch - Symantec Corporation -
C:\Program Files\Symantec_Client_Security\Symantec
AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple
Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Miscrosoft Updates Service 6 (MsUpdate6) -
Unknown owner - C:\WINDOWS\System32\msupd6.exe
023 - Service: Symantec AntiVirus Client (Norton
AntiVirus Server) - Symantec Corporation - C:\Program
Files\Symantec_Client_Security\Symantec
AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) -
NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Venturi2 Client (Venturi2) - Fourelle
Systems, Inc - C:\Program Files\Venturi2\Client\ventc.exe
The trojan is called Microsoft Updates Service 6 and
there is probably Qoologic here as well but hopefully the
Ewido scanner will identify exactly what these random
files and random BHO's are as NameShifter doesnt explain
much

)
Let me know how you get on Tom and send me a new log
after completing them steps I emailed so we can address
the BHO entries.
Regards
Andy