Some Crazy Virus I Cant Get Rid Of...help Please

Hey Guys/Gals,


I have read through the posts you guys have supplied as I am having the same problems as some others on here. As soon as I log on to the internet i begin getting pop ups. They dont seem to be triggered by any certain website I go to. I downloaded a few programs to watch tv on the interenet and it seems the problem began after I unistalled them. The only other thing I remember doing in the time frame was to install Windows Messenger Live, which I now cant get rid of. I have downloaded the Hijack I have downloaded the Rogueremover as well and it doesnt detect anything. I also have and run AVG Antivirus, AVG AntiSpyware, CCleaner, Spyblaster, none of them seem to be resolving the problem...if you guys would look over the Hijack report i would appreciate it...i havent got a clue about this stuff. Really appreciate you help...thanks so much


JD


mtfireguyjd@aol.com


Logfile of Trend Micro HijackThis v2.0.2


Scan saved at 12:46:19 PM, on 11/30/2007


Platform: Windows XP SP2 (WinNT 5.01.2600)


MSIE: Internet Explorer v7.00 (7.00.6000.16544)


Boot mode: Normal


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\Ati2evxx.exe


C:\WINDOWS\system32\svchost.exe


C:\Program Files\Windows Defender\MsMpEng.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\System32\WLTRYSVC.EXE


C:\WINDOWS\System32\bcmwltry.exe


C:\WINDOWS\system32\spoolsv.exe


C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE


C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe


C:\WINDOWS\system32\HPZipm12.exe


C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\system32\SearchIndexer.exe


C:\WINDOWS\system32\Ati2evxx.exe


C:\WINDOWS\Explorer.EXE


C:\Program Files\Canon\CAL\CALMAIN.exe


C:\WINDOWS\system32\ctfmon.exe


C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


C:\WINDOWS\system32\WLTRAY.exe


C:\WINDOWS\stsystra.exe


C:\WINDOWS\system32\dla\tfswctrl.exe


C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe


C:\Program Files\Common Files\AOL\ACS\AOLDial.exe


C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe


C:\Program Files\Windows Defender\MSASCui.exe


C:\Program Files\NetWaiting\NetWaiting.exe


C:\Program Files\Messenger\msmsgs.exe


C:\Program Files\Digital Line Detect\DLG.exe


C:\Program Files\Google\Google Updater\GoogleUpdater.exe


C:\Program Files\Windows Desktop Search\WindowsSearch.exe


C:\Program Files\Netscape ISP Dialer\LiteDialer.exe


C:\WINDOWS\system32\wuauclt.exe


C:\Program Files\Netscape ISP Dialer\aoltpsdL.exe


C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE


C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE


C:\Documents and Settings\Hoosurcowboy\Local Settings\Temporary Internet Files\Content.IE5\CFRCX55G\Windows-KB890830-V1.35[1].exe


c:\2d774feb4682b8515600c1d901ea\mrtstub.exe


C:\WINDOWS\system32\MRT.exe


C:\Program Files\Internet Explorer\IEXPLORE.EXE


c:\program files\winamp toolbar\WinampTbServer.exe


C:\WINDOWS\system32\mmc.exe


C:\WINDOWS\system32\SearchProtocolHost.exe


C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


C:\WINDOWS\system32\SearchProtocolHost.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gacc.nifc.gov/


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/


R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:11535


R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1:11535;update.microsoft.com;*windowsupdate.microsoft.com;*win


owsupdate.com;download.microsoft.com;codecs.microsoft.com;activex.microsoft.com;


iveupdate.symantecliveupdate.com;liveupdate.symantec.com;service1.symantec.com;*


nai.com;*.networkassociates.com;*mcafee.com;*.mapquest.com;*.phobos.apple.com;up


ate.adobe.com;admin.isp.netscape.com


R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll


O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll


O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll


O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll


O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe


O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe


O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe


O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe"


O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide


O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto


O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\NetWaiting.exe


O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


O4 - Global Startup: Digital Line Detect.lnk = ?


O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe


O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL


O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204


O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab


O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll


O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab


O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal...nosticsxp2k.cab


O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab


O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab


O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab


O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab


O16 - DPF: {DF1C8E21-4045-4D67-B528-335F1A4F0DE9} - http://us2-scripts.dlv4.com/binaries/egacc..._1073_em_XP.cab


O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - http://www.plaxo.com/activex/plx_upldr-2k-xp.cab


O17 - HKLM\System\CCS\Services\Tcpip\..\{4661F9C9-B569-4EC3-A81C-C7E8E9EAFE1A}: NameServer = 205.188.146.145


O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe


O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


--


End of file - 11408 bytes