Okay, I just got done with all of the steps that you gave me and ran the online virus and spyware programs and they did find quite a bit of spyware and infected files. however I am still getting the offer optimizer pop ups. not sure from where but its getting frustrating. here is the current Log that i just ran.
Logfile of HijackThis v1.99.1
Scan saved at 11:52:19 PM, on 2/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Bell28\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.iastate.edu/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.iastate.edu/
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: iupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary -
file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search -
file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partypoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by19fd.bay19.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
here is what housecall found when i ran that program.
TROJ ISTBAR.AJ
TROJ STUBBY.D
TROJ DLDR.DLL
TROJ ISTBAR.AC
TROJ AGENT.BP
TROJ AGENT.AAB
and this is what Activescan found.
Incident Status Location
Adware:Adware/MultiMPP No disinfected C:\WINDOWS\dlmax.dll
Adware:Adware/SaveNow No disinfected C:\Program Files\Save
Adware:Adware/nCase No disinfected C:\WINDOWS\FLEOK
Spyware:Spyware/Dyfuca No disinfected Windows Registry
Spyware:Spyware/ISTbar No disinfected C:\DOCUME~1\Bell28\LOCALS~1\Temp\Shortcuts.txt
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan
Adware:Adware/CWS No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\conscorr.inf
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/MyDailyHoroscopeNo disinfected C:\DOCUME~1\Bell28\LOCALS~1\Temp\dummy.htm
Adware:Adware/TopRebates No disinfected C:\DOCUME~1\Bell28\LOCALS~1\Temp\djebmm*.exe
Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\inf\localNRD.inf
Adware:Adware/Twain-Tech No disinfected C:\DOCUME~1\Bell28\LOCALS~1\Temp\THI*.tmp
Adware:Adware/Zango No disinfected Windows Registry
Adware:Adware/CWS No disinfected C:\Documents and Settings\Bell28\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Counter.class-762d722b-29ed81c4.class
Adware:Adware/CWS No disinfected C:\Documents and Settings\Bell28\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\SecurityClassLoader.class-6fd9f626-760406f5.class
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\conscorr.inf
Adware:Adware/TopRebates No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\djtopr1150.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\bho_prob.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\mm_reco.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\pynupg.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\thnall1p.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\thnall2r.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\DrTemp\wupdsnff.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\iinstall58148.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\iinstall58149.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\ln_reco.exe
Spyware:Spyware/LocalNRD No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\localNRD.dll
Spyware:Spyware/LocalNRD No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\localNrd.inf
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI146E.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI1638.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI1638.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI1EC8.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI1EC8.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI23A7.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI23A7.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI2DA.tmp\clntm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI331F.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI371.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI371.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI3F5D.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI3F5D.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI46.tmp\remtm2.exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI4971.tmp\adremtm2.cab[remtm2.exe]
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI4971.tmp\remtm2.exe
Adware:Adware/MultiMPP No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI49E3.tmp\dlmax.cab[dlmax.dll]
Adware:Adware/MultiMPP No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI49E3.tmp\dlmax.dll
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI5229.tmp\remtm2.exe
Adware:Adware/MultiMPP No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI535.tmp\dlmax.cab[dlmax.dll]
Adware:Adware/MultiMPP No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI535.tmp\dlmax.dll
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Bell28\Local Settings\Temp\THI582.tmp\remtm2.exe
Adware:Adware/Transponder No disinfected C:\Documents and Settings\Bell28\Local Settings\Temporary Internet Files\Content.IE5\SHCVK3GT\thnall2r[1].exe
Adware:Adware/MultiMPP No disinfected C:\WINDOWS\dlmax.dll
Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\conscorr.inf
Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\INF\localNrd.inf
Virus:Trj/Downloader.GK Disinfected C:\WINDOWS\INF\polall1r.inf
Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\localNRD.dll
Virus:Trj/Imiserv.D Disinfected C:\WINDOWS\systb.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\SYSTEM32\randreco.exe
I hope that this can help. Thank you with all of your help and patience. Hopefully we can get this thing figured out. thanks.
Brian