here is the info you requested b/c my internet explorer was hijacked by about:blank

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:25:22 PM 6/21/2006

+ Scan result:

C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
HKU\S-1-5-21-3696964677-1241534873-2123546022-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB} -> Adware.Generic : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.196:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.57:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.59:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.60:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.28:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.29:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.30:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.32:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.33:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.39:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Ryan\Cookies\ryan@adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Ryan\Cookies\juggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.19:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.114:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.115:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.12:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.51:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.24:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Ryan\Cookies\ryan@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.40:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.267:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.268:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.65:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.66:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.67:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.68:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.69:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.11:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Ryan\Cookies\ryan@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.180:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\b\Cookies\b@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.20:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.21:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.22:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.23:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.188:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.189:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.190:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.103:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.104:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.105:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.106:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.107:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.108:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.109:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.110:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.201:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.202:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.203:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.204:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.205:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.235:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.236:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\b\Cookies\b@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.209:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.210:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.211:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.212:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.213:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.214:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.215:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.216:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.217:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.218:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.219:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.220:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.232:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.233:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.234:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Guest\Cookies\eldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\b\Cookies\b@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.229:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.230:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.231:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\1rrmafkt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld45CF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld4B8C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld5187.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld5957.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ld7E07.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dcomcfg.exe -> Trojan.Small : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).
[2712] C:\WINDOWS\system32\dcomcfg.exe -> Trojan.Small : Error during cleaning.


::Report end

and here is my new hjt log::

Logfile of HijackThis v1.99.1
Scan saved at 8:29:06 PM, on 6/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1137290574\ee\AOLSoftware.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Dell Support\DSAgnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\3M\PSNLite\PsnLite.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\3M\PSNLite\PSNGive.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ryan\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137290574\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {FC0A65F2-8DFF-4F0F-B411-D4A50311628D} (XMRADIO.XM_SystemProfiler) -
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

please let me know what I need to do next. thanks

Dani AI

Generated

A short expert add-on to the thread that complements ’s scan output and ’s removal suggestion.

The logs indicate leftover adware/spyware fragments plus an orphaned browser-extension entry. Removing that extension entry and deleting the temporary file it points to is the right immediate move, but follow a safe, repeatable cleanup sequence so legitimate components aren't damaged and so any hidden components aren’t left behind.

Recommended cleanup workflow (ordered, repeatable):

  1. Boot the machine into Safe Mode (networking if an updated scanner is needed).
  2. Temporarily disable System Restore so the infection isn’t re-stored.
  3. Update and run a full scan with at least one well-known on-demand antimalware tool; follow that with a second independent scanner to catch anything missed.
  4. Re-run the startup/IE helper-object scan (the same tool that found the bad helper). Use that tool’s “fix” option only for the specific helper-hook/startup entries already identified.
  5. If the helper’s backing file cannot be removed while Windows is running, delete it from Safe Mode or from an offline environment (rescue disk). To clear common file attributes first, use the standard attribute/ delete sequence (replace the placeholder path accordingly):
attrib -s -h -r <suspicious-file-path>
del <suspicious-file-path>

After file removal, reboot and re-scan. Re-enable System Restore only after a clean scan confirms no reinfections.

Follow-up steps and cautions: verify browser settings (homepage, add-ons, proxy/LAN settings), run sfc /scannow to check core system files, and create a fresh restore point. Any quarantined system executable that could not be cleaned warrants an extra rootkit/offline scan. Finally, once the system is clean, update all software and change important passwords since browser hijacks can capture credentials.

Recommended Answers

All 5 Replies

In the future just reply to the previous posts don't Start a new thread. Don't know who was helping this person so I'll just get out of your way.

Don't know who was helping this person so I'll just get out of your way.

I'm stupid I forgot i was helping you in my busyness ill get back to you right away

Ok a few things to do first open HJT and check the following.

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp

Close all other windows and click fix checked.

Now we have to delete the following file.
C:\WINDOWS\system32\hp100.tmp

After doing both steps reboot and post back with any problems you still have.

how do i delete this file?
do i do it from hijack this?

Now we have to delete the following file.
C:\WINDOWS\system32\hp100.tmp

No just use My Computer and navagate to the file.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.