This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Newbie - Need Help Deciphering Hijackthis Log File

48 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me decipher my HijackThis log. My computer has many problems - popups, sloooow startup, redirected browser when trying to search the web, etc. I'm hoping this log file identifies problems.

Below is my log.

Thanks in advance.

Alyluna

Logfile of HijackThis v1.98.0
Scan saved at 9:01:59 PM, on 7/30/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\WINDOWS UPDATE SETUP FILES\SVRWEB.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\MY DOCUMENTS\ALY'S STUFF\SPYWARE REMOVAL APPS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.astound.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.astound.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Astound High Speed Internet
R3 - URLSearchHook: IncrediFindBHO Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing)
R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7960230792F1} - C:\WINDOWS\SYSTEM\CDSM32.DLL
R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O1 - Hosts: 217.116.231.7 aimtoday.aol.com
O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\WINDOWS\TEMP\BEWRVS.DAT
O2 - BHO: (no name) - {25F7FA20-3FC3-11D7-B487-00D05990014C} - C:\WINDOWS\SYSTEM\MSEGGO.GIF
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [System Service] C:\WINDOWS\SYSTEM\MSREXE.EXE
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [SysUpd] C:\WINDOWS\SYSUPD.EXE
O4 - HKLM\..\Run: [SVRWEB] C:\WINDOWS\WINDOWS UPDATE SETUP FILES\SVRWEB.EXE
O4 - HKLM\..\RunOnce: [RegTLib] C:\WINDOWS\RegTLib.exe C:\WINDOWS\SYSTEM\StdOle2.Tlb
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\SYSTEM\msgked.exe
O4 - HKCU\..\Run: [\IEService.exe] C:\WINDOWS\ALLUSE~1\APPLIC~1\IESERV~1\IEService.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - Startup: VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\SYSTEM\IEDriver\TD.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\SYSTEM\IEDriver\TD.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.astound.net/
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/12e11311145049a92b02/netzip/RdxIE.cab
O16 - DPF: {02466323-75ED-11CF-A267-0020AF2546EA} (VivoActive Control) - http://player.vivo.com/ie/vvweb.cab
O16 - DPF: {BEF60E40-342F-4550-9935-AF7EAAF15E79} (Stsaudio Control) - http://www.dfluency.com/dfonline/stsaudio.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…ymmapi_0312.dll
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1500/…uditControl.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} (GigexCtrl ActiveX) - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} (Video Class) - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tukati/1.7.20.20/tukati.cab
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab
O21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-00C04F68105C} - C:\WINDOWS\SYSTEM\AUHOOK.DLL
First of all you have a file on your system that was dropped by the hijacker that our developers have been looking for. They need a copy of the file to identify it so that we can help you and others who have been attacked by the same hijacker, more effectively. (This is the way all spyware is identified and then placed into the current definitions for the appropriate application: anti-virus, anti-trojan, anti-spyware, so that they can be removed easily in the future)

Please Search for and Find
O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\WINDOWS\TEMP\BEWRVS.DAT
Then make a Zip file with it and send it by email as an attachment to :
"submit_stuff AT xs4all.nl" (replace AT with @ and remove the spaces in the email address please.) Please also include a link to this post in your email.


Next I would like you to go to The two Online AV scans listed at the bottom of this post and scan with them letting them fix what they find as I see evidence of a virus.


Now for the fair amount of Malware/Spyware on your computer.
1.Download the new version of 'Spybot: Search And Destroy' from the link at the bottom of this post.

2. Install it according to the instructions in 'How To Setup Spybot SD and Ad-Aware' from the link below.

3. Next, 'Search for Updates' as the definitions will not be up-to-date.

4. Close ALL windows except Spybot SD

5. Click the "Check for Problems" button

6. Click 'Fix Selected Problems' and fix only the RED items.

7. REBOOT to finish removing what it found and clear memory


Now for Ad-Aware:

1. Download 'Ad-Aware' from the link at the bottom of this post.

2. Install according to the instructions at this link "How To Setup Spybot SD and Ad-Aware"

3. Next, 'Check for Updates' by clicking on the 'world globe' second from the right at the top of your Ad-Aware window.

4. Install the updates.

5. Close ALL windows except Ad-Aware

6. Click on 'Start' and choose 'custom scan' for a full scan.

7. Quarantine anything that it finds and SAVE the log file.

8. REBOOT to finish removing what it has found and clear memory.

9. Scan again with HijackThis

10. POST a New HijackThis log here in this thread using 'Add Reply'.
Hello again, I emailed you the compressed file yesterday and I downloaded both SpyBot and Adaware. Ran Spybot and it found a bunch of items, all, with the exception of about 6 were deleted. Next I ran Adaware and it found over 300 items! Most were quarantined with the exception of a few. I then rebooted my computer and as it was rebooting, it got stuck on the Windows ME screen (no access to my deskstop). I performed a CTRL, ALT, Delete to reboot again and it again stalled at the ME screen. I tried several times and continued to get the same result. I finally gave up and went to bed, but left the computer on thinking that it might be OK by morning. Well, when I got up this morning, it was stilled stalled at the Windows ME screen. Again I tried CTRL, ALT, Delete and once again it stalled when it got to that screen. Any idea what may have happened? Fortunately, I am accessing the computer from work right now and am really hoping you will post before I go home. Thanks in advance. Alyluna
I am sorry for the delay - I doubt that you are still at work. This is a very unusual occurrence after only running Spbot SD and Ad-Aware. Did you delete anything else or use HijackThis to remove anything? Did you Reboot after running Spybot SD and before using adaware? Do you have a startup disk for Windows? 1. Boot into Safe Mode by Tapping on F8 as you boot the computer. It should bring you to a menu where you can choose safe mode. Let it boot into windows in Safe Mode and then 2. open AdAware 3. choose the middle item at the top of the adaware screen 'quarantined items' 4.Click on each entry and then click 'restore'. 5.Now close Ad-Aware. 6. Open Spybot SD 7. Click on 'Recovery' on the left hand side of the screen 8. In the recovery window 'select all' 9. 'Recover Selected Items' 10. Close Spybot SD If you made any changes with HijackThis the backups it made will help 1. Open HijackThis 2.Click on 'config' on the right hand side of the window 3. Click on 'backups' at the top of the screen 4. Select each backup in the window and click 'restore' 5. Close HijackThis Reboot . Your computer should have returned to the way it was prior to running any of the fixit programs. Please post a new HijackThis log file in this thread including the details of what has happened. I suggest that the first thing you do after posting is go to the Online AV scans listed at the bottom of this post and scan and let them fix anything they find. Then wait for me to post back with instructions.
Hello and thank you for the quick reply. In answer to your questions - No, I did not delete anything using HijackThis. Yes, I rebooted after running Spybot (before running Ad-aware). It was after I ran Ad-aware and quarantined the 300+ items that I rebooted and that's when the computer stalled. I do not have the windows start up disk but I do have the applications recovery disk. I did as you suggested and tried to reboot in Safe Mode. It took a long time but it finally got to a screen that read: Windows is bypassing your start up files. Wait while windows updates your configuration files. Windows could not upgrade the file %1 from %2 %1:%2. It has been stalled at this stage since last night. I'm not sure what to do at this point. I'm very tempted to use my system recovery disk for I fear my computer is in really bad shape, but of course that would mean a loss of many of my files. Anything else you can think of to at least get me out of the stalled mode into windows. Thanks. Alyluna
Hi Alyluna, I have asked for help from our Ad-Aware specialist here at the forum 'DieHard' so I would rather you not make any decisions until hearing from him How many times did you attempt to boot into safe mode? How much computer experience do you have and have you ever worked with DOS commands? A good thing that has happened is we have identified the file that you sent. We know what type of malware it is and it is a brand new variant of one that is difficult to remove. So your computer mess has done a very good thing for by identifying it so that the developers can make a fix for it. They are doing this as I write. Unfortunately at the moment that does not help you. Can you make a startup disk (boot disk) at work on a floppy disk? What OS are you using at work? OR Do you have a bootable CD or floppy like a Norton disk. I am not sure if the newer Norton AV disks are bootable but it is possible. I will keep an eye out for your response Good Luck!
another question: Which version of Norton do you have? Is it AV or one of the combined products? Is your subscription up to date and do you have the udated definitions? Can you download the updated definitions from Symantec to run from a floppy at work?

Hi Alyluna,

I have asked for help from our Ad-Aware specialist here at the forum 'DieHard' so I would rather you not make any decisions until hearing from him

How many times did you attempt to boot into safe mode? How much computer experience do you have and have you ever worked with DOS commands?

A good thing that has happened is we have identified the file that you sent. We know what type of malware it is and it is a brand new variant of one that is difficult to remove. So your computer mess has done a very good thing for by identifying it so that the developers can make a fix for it. They are doing this as I write. Unfortunately at the moment that does not help you.

Can you make a startup disk (boot disk) at work on a floppy disk? What OS are you using at work? OR Do you have a bootable CD or floppy like a Norton disk. I am not sure if the newer Norton AV disks are bootable but it is possible.

I will keep an eye out for your response

Good Luck!

Hello,

Well, the good new IS that you were able to identify the file I sent! Thank goodness.

In response to your questions - I attempted to reboot in safe mode about 5 times. Aside from the basics, I don't have a lot of knowledge about computes and I dont have much experience with DOS commands.

The OS at work is Windows 2000. If I create a windows startup can I use that even though my computer uses Windows ME?

Regarding Norton AV, I'm not sure what version, I believe basic ( I downloaded it off the Symantec website about 3 mos. ago. I updated my definitions this weekend.

I will be on vacation beginning Thursday, therefore, I will only have access to the internet until tomorrow, so I'm hoping we can resolve this. If not, I will be back on the forum when I return in two weeks.

Thank you for reading my posts and taking the time to help!

Alyluna
I have not had a reply from DieHard unfortuantely but I have a place that you can go to make a boot disk for ME. Make the OEM bootdisk from here for ME on a floppy
http://www.bootdisk.com/

We will try to get this fixed before you leave on vacation but we have to get you into windows before we can do anything.
I have some instructions which may help you get back into windows and fix the problem. They have been taken from information at Microsoft. You will need a boot disk which you can download from http://www.bootdisk.com


http://support.microsoft.com/default.aspx?kbid=279736

To start the System Restore tool when you cannot start your Windows Me-based computer normally or in Safe mode, you can temporarily change the Windows shell from Explorer.exe to Progman.exe:

1. Start your computer by using the Windows Me Startup disk.
2. At the Startup menu, choose Minimum Boot.
3. At the command prompt, type edit c:\windows\system.ini, and then press ENTER.
4. The Edit tool will open with the System.ini file in it
5. Edit the shell= line so that it looks like this:

shell=progman.exe

5. Press ALT+F, and then press S to save the changes to the System.ini file.
6. Press ALT+F, and then press X.
7. Remove your Windows Me Startup disk, and then restart your computer. When your computer restarts, Program Manager should start. If Program Manager does not start, repeat steps 1 through 7, being careful to follow these steps exactly, and then continue to the next step.
8. On the File menu, click Run, type msconfig in the Command Line box, and then press ENTER.
9. Click Launch System Restore to begin restoring your computer to a previous, functional state.

Notes

* After you configure your computer to start Program Manager (Progman.exe), you can also start the System Restore tool by typing c:\windows\system\restore\rstrui.exe at a command prompt, and then pressing ENTER.
* If you still cannot use System Restore, repeat steps 1 through 6. In step 4, change the shell= line so that it reads:

shell=explorer.exe

This sets the Windows shell back to Explorer.exe so that you can continue troubleshooting.




[URL=http://support.microsoft.com/default.aspx?kbid=283069

After you install a new program or update an existing program and then restart your computer, your computer may stop responding (hang), and you may receive the following error message:

Windows could not upgrade the file %1 from %2 %1: %2

Your computer may or may not continue to start after this error message.

CAUSE
This issue can occur if the Wininit.ini file is not processed correctly.

RESOLUTION
To resolve this issue, rename the Wininit.ini file:

1. Click Start, point to Search, and then click Files or Folders.
2. In the Named box, type wininit.ini.
3. In the Look in box, click Local Hard Drives.
4. Click Search Now.
5. Right-click the Wininit.ini file in the list of found items, and then click Rename.
6. Type Wininit.old, and then press ENTER.
7. Close the Search Results window.
8. Restart your computer.
9. Reinstall your program or update.

Hope this works for you!

When you get back into windows please scan with HijackThis and post a new log file
Hello there,

I've just returned from vacation and wanted to update you on my computer problems.

You might remember that after running Shredder, Spybot and Adawaree my computer would not boot up. You asked that I create a bootdisk and attempt to reboot my computer with it. I created the disk, but unfortunately, my floppy disk drive is not working (if money wasn't an issue, I would just get a new computer!) Anyway, I left for vacation without fixing the problem.

I got back on Thursday and decided to turn on my computer. Sure enough it got stuck on the Windows ME screen; however, this time when I went back to it an hour later it was back to my desktop! It seems to be working, internet and all, but I haven't turned it off since (just set it to hibernate) because I'm afraid if I turn it off, I will have problems with booting it up again.

I ran HijackThis again and here is the new log ( I did not ask it to fix anything). Please take a moment to look at my log and let me know if you find anything.

Thanks in adavance!

Alyluna

Logfile of HijackThis v1.98.0
Scan saved at 12:35:50 PM, on 8/21/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\VASERV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\WINDOWS UPDATE SETUP FILES\SVRWEB.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\ALY'S STUFF\SPYWARE REMOVAL APPS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.astound.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.astound.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Astound High Speed Internet
R3 - URLSearchHook: (no name) - {965A592F-8EFA-4250-8630-7960230792F1} - (no file)
O1 - Hosts: 217.116.231.7 aimtoday.aol.com
O2 - BHO: CATLEvents Object - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\WINDOWS\TEMP\BEWRVS.DAT
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [SVRWEB] C:\WINDOWS\WINDOWS UPDATE SETUP FILES\SVRWEB.EXE
O4 - HKLM\..\RunOnce: [*SVRWEB] C:\WINDOWS\WINDOWS UPDATE SETUP FILES\SVRWEB.EXE
O4 - Startup: VAIO Action Setup (Server).lnk = C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: LimeShop Preferences - file://C:\Program Files\LimeShop\System\Temp\limeshop_script0.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\WINDOWS\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0411.DLL (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\MSN Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.astound.net/
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.188.7.150/12e11311145049a92b02/netzip/RdxIE.cab
O16 - DPF: {02466323-75ED-11CF-A267-0020AF2546EA} (VivoActive Control) - http://player.vivo.com/ie/vvweb.cab
O16 - DPF: {BEF60E40-342F-4550-9935-AF7EAAF15E79} (Stsaudio Control) - http://www.dfluency.com/dfonline/stsaudio.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! WebCam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…ymmapi_0312.dll
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1500/…uditControl.cab
O16 - DPF: {50F65670-1729-11D2-A51F-0020AFE5D502} (ForumChat) - http://objects.compuserve.com/chat/RTCChat.cab
O16 - DPF: {6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} - http://www.gigex.com/tv/igor/gigexagent.dll
O16 - DPF: {1C955F3B-5B32-4393-A05D-24B4970CD2A1} - http://streamp.babenet.com/cabs/videox.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tukati/1.7.20.20/tukati.cab
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab
O21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-00C04F68105C} - C:\WINDOWS\SYSTEM\AUHOOK.DLL
Hi Alyluna, I just noticed your new post as I was about to sign off for the night. I am afraid I won't be able to help you tonight but I will get to you first thing tomorrow and see where you are at. The Forums are quite busy so I suspect no one would get to you before I will, but if someone starts to help you, the sooner it will be done. Hope you had a good holiday! all the best!
Ok I have reviewed what we did and think I remember that the problem started when you rebooted after running Ad-Aware and rebooting. Now that you have access to the desktop we have a lot more that we can do.

1) First I would like you to look for the Ad-Aware log file from that scan. Mine is in C:\Program Files\Lavasoft\AdAware 6\logs. Choose the log file that coinsides with approximately August 2, 2004. You will recognize it by it's size. Please copy and paste it here in this thread. You may have to use several posts as it is may be too long to fit in one Just keep posting making sure that you don't miss anything and try not to repeat anything. After I see the log file I may be able to track down which removal it was that caused the problem and we won't have to restore all of the junk. The quarantine will have backups of everything you changed and we can restore all of those items but we will reinfect you with everything so may be easier to check the log file and only restore what is necessary.

2) I would like you to open AdAware and click on the middle icon at the top right of the Ad-Aware window (this will open the quarantine area). Check to make sure that there are entries in the quarantine box and if only a few seem to be there or are all of them there.

Your HJT log is now showing many different infections that Spybot and Ad-Aware should take care of plus a few extras that will require small programs. However, it is imperative that we keep your desktop available so we will approach this with extreme caution.

Please post the Ad-Aware log file and we will go from there.

Good Luck!
Hello! Thanks for the quick response. Attached is the Ad-aware log I ran on August 1st. As you suggested, I've checked the quarantine option on Ad-aware and there are many items in quarantine. Thanks so much for taking the time to help me with this. Sincerely, Alyluna Lavasoft Ad-aware Personal Build 6.181 Logfile created on :Sunday, August 01, 2004 3:59:21 PM Created with Ad-aware Personal, free for private use. Using reference-file :01R334 24.07.2004 ______________________________________________________ Reffile status: ========================= Reference file loaded: Reference Number : 01R298 20.04.2004 Internal build : 229 File location : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\reflist.ref Total size : 1067557 Bytes Signature data size : 1049356 Bytes Reference data size : 18137 Bytes Signatures total : 23569 Target categories : 10 Target families : 455 8-1-2004 3:55:40 PM Performing Webupdate… Installing Update… Reference file loaded: Reference Number : 01R334 24.07.2004 Internal build : 268 File location : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\reflist.ref Total size : 1316091 Bytes Signature data size : 1295051 Bytes Reference data size : 20976 Bytes Signatures total : 28648 Target categories : 10 Target families : 528 8-1-2004 3:55:56 PM Success. Update successfully downlodaded and installed. Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium III Memory available:28 % Total physical memory:129532 kb Available physical memory:1968 kb Total page file size:1967616 kb Available on page file:1887572 kb Total virtual memory:2093056 kb Available virtual memory:2045696 kb OS:Windows (ME) Ad-aware Settings ========================= Set : Activate in-depth scan (Recommended) Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-aware Settings ========================= Set : Unload recognized processes during scanning Set : Include basic Ad-aware settings in logfile Set : Include additional Ad-aware settings in logfile Set : Automatically try to unregister objects prior to deletion Set : Let windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Always back up reference file, before updating Set : Play sound if scan produced a result 8-1-2004 3:59:21 PM - Scan started. (Custom mode) Listing running processes ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ #:1 [kernel32.dll] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4279186389 Threads : 8 Priority : High FileSize : 524 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright © Microsoft Corp. 1991-2000 CompanyName : Microsoft Corporation FileDescription : Win32 Kernel core component InternalName : KERNEL32 OriginalFilename : KERNEL32.DLL ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:2 [msgsrv32.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294966061 Threads : 1 Priority : Normal FileSize : 11 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright © Microsoft Corp. 1992-1998 CompanyName : Microsoft Corporation FileDescription : Windows 32-bit VxD Message Server InternalName : MSGSRV32 OriginalFilename : MSGSRV32.EXE ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:3 [spool32.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294959877 Threads : 2 Priority : Normal FileSize : 44 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright © Microsoft Corp. 1994 - 1998 CompanyName : Microsoft Corporation FileDescription : Spooler Sub System Process InternalName : spool32 OriginalFilename : spool32.exe ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:4 [mprexe.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294941233 Threads : 1 Priority : Normal FileSize : 28 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright © Microsoft Corp. 1993-2000 CompanyName : Microsoft Corporation FileDescription : WIN32 Network Interface Service Process InternalName : MPREXE OriginalFilename : MPREXE.EXE ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:5 [mmtask.tsk] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294894361 Threads : 1 Priority : Normal FileSize : 1 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright CompanyName : Microsoft Corporation FileDescription : Multimedia background task support module InternalName : mmtask.tsk OriginalFilename : mmtask.tsk ProductName : Microsoft Windows Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:6 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 4294737737 Threads : 30 Priority : Normal FileSize : 220 KB FileVersion : 5.50.4134.100 ProductVersion : 5.50.4134.100 Copyright : Copyright © Microsoft Corp. 1981-2000 CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer OriginalFilename : EXPLORER.EXE ProductName : Microsoft® Windows ® 2000 Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:7 [rpcss.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294730957 Threads : 5 Priority : Normal FileSize : 20 KB FileVersion : 4.71.3328 ProductVersion : 4.71.3328 Copyright : Copyright © Microsoft Corp. 1981-1998 CompanyName : Microsoft Corporation FileDescription : Distributed COM Services InternalName : rpcss.exe OriginalFilename : rpcss.exe ProductName : Microsoft® Windows NT™ Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:8 [systray.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294746493 Threads : 2 Priority : Normal FileSize : 36 KB FileVersion : 4.90.3000 ProductVersion : 4.90.3000 Copyright : Copyright © Microsoft Corp. 1993-2000 CompanyName : Microsoft Corporation FileDescription : System Tray Applet InternalName : SYSTRAY OriginalFilename : SYSTRAY.EXE ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:9 [symlcsvc.exe] FilePath : C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\ ProcessID : 4294671857 Threads : 1 Priority : Normal FileSize : 588 KB FileVersion : 1, 8, 50, 196 ProductVersion : 1, 8, 50, 196 Copyright : Copyright © 2003 CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc OriginalFilename : symlcsvc.exe ProductName : Symantec Core Component Created on : 4/25/2004 7:28:02 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/25/2004 7:28:02 PM #:10 [wmiexe.exe] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294679105 Threads : 3 Priority : Normal FileSize : 16 KB FileVersion : 4.90.2452.1 ProductVersion : 4.90.2452.1 Copyright : Copyright © Microsoft Corp. 1981-1999 CompanyName : Microsoft Corporation FileDescription : WMI service exe housing InternalName : wmiexe OriginalFilename : wmiexe.exe ProductName : Microsoft® Windows® Millennium Operating System Created on : 1/1/1601 Last accessed : 8/1/2004 7:00:00 AM Last modified : 6/9/2000 #:11 [svrweb.exe] FilePath : C:\WINDOWS\WINDOWS UPDATE SETUP FILES\ ProcessID : 4294673933 Threads : 6 Priority : Normal FileSize : 510 KB Created on : 7/29/2004 5:05:19 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 7/29/2004 5:05:32 AM #:12 [aim.exe] FilePath : C:\PROGRAM FILES\AIM95\ ProcessID : 4294601865 Threads : 2 Priority : Normal FileSize : 60 KB FileVersion : 5.2.3292 ProductVersion : 5.2.3292 Copyright : Copyright CompanyName : America Online, Inc. FileDescription : AOL Instant Messenger InternalName : AIM OriginalFilename : AIM.EXE ProductName : AOL Instant Messenger Created on : 10/28/2003 5:10:43 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 8/1/2003 2:31:06 PM #:13 [vaserv.exe] FilePath : C:\PROGRAM FILES\SONY\VAIO ACTION SETUP\ ProcessID : 4294608085 Threads : 1 Priority : Normal FileSize : 40 KB FileVersion : 1.3.01.10310 ProductVersion : 1.3.01.10310 Copyright : Copyright 2000,2001 Sony Corp. CompanyName : Sony Corporation FileDescription : VAServ Application InternalName : VAServ OriginalFilename : VAServ.EXE ProductName : VAIO Action Setup Created on : 1/5/2001 8:46:43 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 11/1/2000 4:19:52 AM #:14 [ad-aware.exe] FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\ ProcessID : 4294628429 Threads : 2 Priority : Normal FileSize : 668 KB FileVersion : 6.0.1.181 ProductVersion : 6.0.0.0 Copyright : Copyright CompanyName : Lavasoft Sweden FileDescription : Ad-aware 6 core application InternalName : Ad-aware.exe OriginalFilename : Ad-aware.exe ProductName : Lavasoft Ad-aware Plus Created on : 8/5/2003 3:32:36 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 7/13/2003 4:00:20 AM Memory scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 0 Objects found so far: 0 Started registry scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ AdDestroyer Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : software\vb and vba program settings\addestroyer AdLogix Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : swin32.sdwin32.1 AdLogix Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : swin32.sdwin32 AdLogix Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{5fa6752a-c4a0-4222-88c2-928ae5ab4966} AdLogix Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{4d84a744-c3dd-4bff-b119-ac08f54714d7} AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{34EF5B1C-52CB-400b-8B7C-F787018B3826} AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{E9D8697E-BEA9-4170-84F3-509AD2A11951} AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Mwsvm AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\slmss AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TypeLib\{3CD9D85E-1FF2-4BF7-A113-6669B8D1E676} AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : urllauncher.urllaunchercontrol AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : urllauncher.urllaunchercontrol.1 AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{965a592f-8efa-4250-8630-7960230792f1} AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{69db5061-ff0a-418b-ada6-68ac77d69e44} ClickSpring Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\ClickSpring ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_USERS Object : .default\Software\iPend ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : AppID\C22A6AF2-C946-4EBF-861C-62252458827F ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : AppID\{026E4B83-1BF7-41CB-8233-4AF35341BC69} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{00A0A40C-F432-4C59-BA11-B25D142C7AB7} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{0982868C-47F0-4EFB-A664-C7B0B1015808} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{0BA1C6EB-D062-4E37-9DB5-B07743276324} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{25F7FA20-3FC3-11D7-B487-00D05990014C} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{94927A13-4AAA-476A-989D-392456427688} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{CC916B4B-BE44-4026-A19D-8C74BBD23361} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : dnsrep.dnsrepobj ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : dnsrep.dnsrepobj.1 ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{A679DB3C-6A3C-49D7-9D03-5D2F88715DB7} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{A7370377-E217-4467-8448-9845270CD4A3} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : Software\iPend ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A0A40C-F432-4C59-BA11-B25D142C7AB7} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0982868C-47F0-4EFB-A664-C7B0B1015808} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ba1c6eb-d062-4e37-9db5-b07743276324} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{25F7FA20-3FC3-11D7-B487-00D05990014C} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94927a13-4aaa-476a-989d-392456427688} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC916B4B-BE44-4026-A19D-8C74BBD23361} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TypeLib\{026E4B83-1BF7-41CB-8233-4AF35341BC69} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TypeLib\{C22A6AF2-C946-4EBF-861C-62252458827F} ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : urlcli.UrlCliObj ClientMan Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : urlcli.UrlCliObj.1 CoolWebSearch Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{cc905ff6-b553-496c-9dfa-cff65adcd0fc} CoolWebSearch Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : searchrep.searchreppp CoolWebSearch Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : searchrep.searchreppp.1 CoolWebSearch Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{8dbd1ce8-2720-4774-8cc6-32737958ac4b} Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{cabd7099-6b04-471d-8371-9fde9c2e6bea} Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : girlcontrolcom.girlcom Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : girlcontrolcom.girlcom.1 Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{271D7D74-8E6D-4E6C-86F5-66C064CFB74D} Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{89161220-A3D9-464F-848C-4EBE0546697D} Dialer-Offline Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{b0acf771-f0f7-461f-bef3-5b1a3ba42f51} eUniverse Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{4fc95edd-4796-4966-9049-29649c80111d} GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : GigexAgent.GigexCtrl GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : GigexAgent.GigexCtrl.1 GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : Interface\{C3B2B2AF-E11C-4EC5-A9AC-6189992758D8} GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TypeLib\{AA66EECD-028D-4B11-8A9E-6287235644B0} istbar Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{8c752c5e-3c10-4076-af0a-ffc69fa20d1b} Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : sep.band.1 Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : sep.band Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{c5183abc-eb6e-4e05-b8c9-500a16b6cf94} Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3} Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : sep.search.1 Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : sep.search Lycos Sidesearch Object recognized! Type : RegKey Data : Category : Misc Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{c30793af-14b2-4300-8b5d-4bfa3987050e} MemoryWatcher Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\MemoryWatcher TurboDownload Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Internet Explorer\Extensions\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} TurboDownload Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} Virtumundo Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : AppID\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} Virtumundo Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} VX2 Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{0000607d-d204-42c7-8e46-216055bf9918} VX2 Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : mxtargetdll.mxtargetdllobj.1 WhenU Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : WUSE.1 Win32.Backdoor.Jeem Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : SYSTEM\CurrentControlSet\Services\Swartax eUniverse Object recognized! Type : RegValue Data : Category : Data Miner Comment : "{5D60FF48-95BE-4956-B4C6-6BB168A70310}" Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Internet Explorer\URLSearchHooks Value : {5D60FF48-95BE-4956-B4C6-6BB168A70310} Favoriteman Object recognized! Type : RegValue Data : Category : Data Miner Comment : "Counter" Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows Value : Counter Favoriteman Object recognized! Type : RegValue Data : Category : Data Miner Comment : "Server" Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows Value : Server Favoriteman Object recognized! Type : RegValue Data : Category : Data Miner Comment : "Object" Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows Value : Object Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "1c3943" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : 1c3943 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "4lkf83" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : 4lkf83 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "vk8593" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : vk8593 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "2340v93" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : 2340v93 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "4c34" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : 4c34 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "c0948273" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : c0948273 Win32.Backdoor.Jeem Object recognized! Type : RegValue Data : Category : Malware Comment : "398349873" Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\Welcome Value : 398349873 Registry scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 84 Objects found so far: 84 Started deep registry scan ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Data Miner Comment : c:\windows\downloaded program files\gigexagent.dll Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2} GigexAgent-SpeedDelivery Object recognized! Type : File Data : gigexagent.dll Category : Data Miner Comment : Object : c:\windows\downloaded program files\ FileSize : 113 KB FileVersion : 1, 0, 1, 1 ProductVersion : 1, 0, 1, 1 Copyright : Copyright 2001 CompanyName : Gigex.com, Inc FileDescription : GigexAgent Module InternalName : GigexAgent OriginalFilename : GigexAgent.DLL ProductName : GigexAgent Module Created on : 8/24/2002 9:31:37 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 8/24/2002 9:31:38 PM FastFind Object recognized! Type : RegKey Data : Category : Malware Comment : c:\windows\all users\application data\ieservice\ieservice.dll Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{9E992732-295F-4987-8BE3-16FAC1639198} FastFind Object recognized! Type : File Data : ieservice.dll Category : Malware Comment : Object : c:\windows\all users\application data\ieservice\ FileSize : 111 KB Copyright : : Created on : 7/9/2004 1:04:43 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 7/9/2004 1:04:44 AM FastFind Object recognized! Type : RegKey Data : Category : Malware Comment : c:\windows\all users\application data\ieservice\ieservice.dll Rootkey : HKEY_CLASSES_ROOT Object : CLSID\{D72A7651-8A16-476E-953C-347F0241FD32} FastFind Object recognized! Type : RegKey Data : c:\windows\all users\application data\ieservice\ieservice.dll Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : TYPELIB\{B929C108-045F-48D1-8638-E3195AD6FF03} FastFind Object recognized! Type : RegKey Data : Category : Malware Comment : ({9E992732-295F-4987-8BE3-16FAC1639198}) Rootkey : HKEY_CLASSES_ROOT Object : E.HH FastFind Object recognized! Type : RegKey Data : Category : Malware Comment : ({D72A7651-8A16-476E-953C-347F0241FD32}) Rootkey : HKEY_CLASSES_ROOT Object : E.ZZA AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : ({965A592F-8EFA-4250-8630-7960230792F1}) Rootkey : HKEY_CLASSES_ROOT Object : URLSearch.URLSearch.1 AdRotator Object recognized! Type : RegKey Data : Category : Malware Comment : ({965A592F-8EFA-4250-8630-7960230792F1}) Rootkey : HKEY_CLASSES_ROOT Object : URLSearch.URLSearch Lycos Sidesearch Object recognized! Type : RegValue Data : Category : Misc Comment : ({C5183ABC-EB6E-4E05-B8C9-500A16B6CF94}) Rootkey : HKEY_LOCAL_MACHINE Object : SOFTWARE\Microsoft\Internet Explorer\Toolbar Value : {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} GigexAgent-SpeedDelivery Object recognized! Type : RegKey Data : Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/gigexagent.dll Redhotnetworks Object recognized! Type : RegKey Data : Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\microsoft\windows\currentversion\moduleusage\C:/WINDOWS/Downloaded Program Files/videox.dll Redhotnetworks Object recognized! Type : File Data : videox.dll Category : Malware Comment : Object : c:\windows\downloaded program files\ FileSize : 196 KB FileVersion : 1, 0, 0, 6 ProductVersion : 1, 0, 0, 6 Copyright : Copyright 2000 FileDescription : VideoX Module InternalName : VideoX OriginalFilename : VideoX.DLL ProductName : VideoX Module Created on : 9/20/2000 4:13:46 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 9/20/2000 4:13:46 PM CoolWebSearch Object recognized! Type : RegValue Data : Category : Malware Comment : "msmc" Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows\CurrentVersion\Run Value : msmc CoolWebSearch Object recognized! Type : File Data : msgked.exe Category : Malware Comment : Object : c:\windows\system\ FileSize : 46 KB Created on : 5/29/2004 6:18:52 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 8/23/2001 GigexAgent-SpeedDelivery Object recognized! Type : RegValue Data : c:\windows\downloaded program files\gigexagent.dll Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\SharedDLLs Value : C:\WINDOWS\Downloaded Program Files\gigexagent.dll Redhotnetworks Object recognized! Type : RegValue Data : c:\windows\downloaded program files\videox.dll Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : Software\Microsoft\Windows\CurrentVersion\SharedDLLs Value : C:\WINDOWS\Downloaded Program Files\videox.dll Deep registry scan result : ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ New objects : 14 Objects found so far: 102 Deep scanning and examining files (C:) ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ Win32.Revop.Trojan Object recognized! Type : File Data : a0078239.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : N S Created on : 5/7/2004 3:00:05 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0078276.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : KB Created on : 5/7/2004 2:05:38 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0078316.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : Lav Created on : 5/7/2004 8:06:45 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0078390.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : ile Created on : 5/8/2004 3:00:06 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0078394.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : rig Created on : 5/5/2004 7:00:03 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0078396.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : œ 1 Created on : 5/5/2004 7:00:03 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0079318.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : rig Created on : 5/8/2004 7:00:03 AM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0080317.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : 079 Created on : 5/8/2004 3:11:07 PM Last accessed : 8/1/2004 7:00:00 AM Last modified : 4/29/2004 10:28:20 PM Win32.Revop.Trojan Object recognized! Type : File Data : a0080366.cpy Category : Malware Comment : Object : C:\_RESTORE\TEMP\ FileSize : 64 KB Copyright : ,
HI Alyluna I have asked for help from the people who support Ad-Aware and await their response. The Ad-Aware log is not complete, please post the rest of the log

Since we haven't updated any of the log files in almost 3 weeks I would appreciate it if you would update and scan with Spybot SD again following all my instructions earlier in this thread. REBOOT after Spybot SD

I would like you to download the new Ad-Aware SE that has just been released, and scan with it producing an Ad-Aware log file but do not reboot unless you feel confident that it won't cause more problems. .


Scanning With Ad-Aware SE :


1. Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan

2.Close ALL windows except Ad-Aware SE

3. Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.

4. Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window

1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

Under Definitions:
*Prompt to udate outdated definitions - set the number of days


2) Click on the ‘Scanning’ button on the left and select in green :

Under Driver, Folders & Files:
*Scan Within Archives

Under Select drives & folders to scan -
*choose all hard drives

Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file


3) Click on the ‘Advanced’ button on the left and select in green:

Under Shell Integration:
*Move deleted files to recycle bin

Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information

Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT


4) Click the ‘Tweak’ button and select in green:

Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only


Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot


Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile


5. Click on ‘Proceed’ to save the settings.

6. Click ‘Start’

*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.

8. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window

9. Save the log file when it asks and then click ‘finish’


Finally after running both Spybot SD and Ad-Aware SE, RESCAN with HijackThis and POST your logfile in the same thread using ‘Add Reply’. Do not attempt to fix anything in HijackThis yourself!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI