This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Lzio Spyware

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I need help in order to remove lzio spyware from my computer.
I tried to do it myself by removing all occurrences of programs that were created after (what I think is) the first time I got this spyware. I deleted files from my C partition and from my registry (only keys that I was sure thay they are related to this spyware implications).
But it didn't work, after I did all this I connected to the internet and found out that my computer is connected to this newupdates.lzio.com AGAIN!! (I felt so stupid at that moment :angry: )
Anyway, I download and ran HijackThis and I copied here the logfile I got.
I hope you'll be able to help me with it.
TIA.

p.s. what should I do if you'll tell me to fix/delete something that I know what it is and I'm sure that it's safe?

===================================

Logfile of HijackThis v1.98.2
Scan saved at 04:07:17, on 01/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\WINDOWS\System32\GSICON.EXE
C:\WINDOWS\System32\dslagent.exe
C:\Program Files\הפוך על הפוך\Hebrew.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\viraxtb.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Babylon\Babylon.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\YahooPOPs\YahooPOPs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Brickner's\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.walla.co.il/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [IncredimailDownloader] C:\WINDOWS\DOWNLO~1\imloader.exe
O4 - HKLM\..\Run: [Hebrew] C:\Program Files\הפוך על הפוך\Hebrew.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\viraxtb.exe
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe
O4 - HKLM\..\RunOnce: [djtopr1150.exe] "C:\DOCUME~1\BRICKN~1\LOCALS~1\Temp\djtopr1150.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Babylon Translator] C:\Program Files\Babylon\Babylon.exe
O4 - Startup: YahooPOPs.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Microsoft WFC Forms Designer - file://E:\VJ98\wfcforms.cab
O16 - DPF: Visual Studio 6 Extensibility Libraries - file://E:\VJ98\vstudio6.cab
O16 - DPF: {F59AB0C4-3443-4551-A78F-C101F9DE0215} (LauncherV1 Class) - http://irc.tapuz.co.il/BlogTVU1/launcher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{60A61418-9D46-463A-83F3-1FDD52D1CCE9}: NameServer = 62.219.186.7 192.115.106.35
Download the latest version of Ad-Aware here:

After installing Ad-Aware, and before running the program.
Please be sure to update the reference file following the instructions here:

Reconfigure Ad-Aware for Full Scan:

Launch the program, and click on the Gear at the top of the start screen.

Click the "Scanning" button.
Under Drives, Folders and Files, select "Scan within Archives".
Click "Click here to select Drives + folders" and select your installed hard drives.

Under Memory & Registry, select all options.
Click the "Advanced" button.
Under "Log-file detail level", select all options.
Click the "Tweaks" button.

Under "Scanning Engine", select the following:
"Unload recognized processes during scanning."
Under "Cleaning Engine", select the following:
"Let Windows remove files in use after reboot."
Click on 'Proceed' to save these Preferences.

Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT to allow it to finish.



Don't think you want this if not remove it in add and remove programs "Web_Rebates"
O4 - HKLM\..\Run: [WebRebates0] C:\Program Files\Web_Rebates\WebRebates0.exe


For the following file, I want to make sure it's not a valid file before removing it. Right click on it and go to Properties.
Then go to the Version tab to see what company name it's from:

C:\DOCUME~1\BRICKN~1\LOCALS~1\Temp\djtopr1150.exe
First of all thanx for the fast response! :)

I ran AD-Aware and it found some files and registry keys. I deleted them all.
I noticed that some of the files were related to WebRebates too.
I didn't delete any of the 'Negligible Objects' list.

I forgot to mention earlier that I put 'newupdates.lzio.com' and ''updates.lzio.com' in my firewall's (NIS 2003) restricted list so my computer won't connect to these sites and won't download any other new programs.

While writing this reply I ran a search on my computer after files that have WebRebates in their name (and that their creation date is from yesterday) and I still found 2 files: webrebates_installas.exe (under C:\WINDOWS\system32) and WEBREBATES_INSTALLAS.EXE-376FBF6F.pf (under C:\WINDOWS\Prefetch).
I'm not so sure I wanted to find these files :( (and I still didn't search the registry after Webrebates)

I ran another HijackThis search and I didn't find Webrebates in the logfile this time. Should I delete those 2 files? should I look for it also in the registry?

About C:\DOCUME~1\BRICKN~1\LOCALS~1\Temp\djtopr1150.exe:
I checked it but I didn't find any version tab under the properties.
Would it help if I tell you that the created & modified dates are from 2/9/2004?
BTW, I didn't find djtopr also on my new HijackThis logfile, although I did find it in the same location it was earlier…

I added my new HijackThis logfile.

Thanx.

============================

Logfile of HijackThis v1.98.2
Scan saved at 05:47:49, on 01/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\WINDOWS\System32\GSICON.EXE
C:\WINDOWS\System32\dslagent.exe
C:\Program Files\הפוך על הפוך\Hebrew.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\viraxtb.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Babylon\Babylon.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\YahooPOPs\YahooPOPs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Brickner's\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.walla.co.il/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://find.walla.co.il/ts.cgi?tsscript=find&ie;=searchbar
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://find.walla.co.il/ts.cgi?tsscript=ie/config
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [IncredimailDownloader] C:\WINDOWS\DOWNLO~1\imloader.exe
O4 - HKLM\..\Run: [Hebrew] C:\Program Files\הפוך על הפוך\Hebrew.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\viraxtb.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [Babylon Translator] C:\Program Files\Babylon\Babylon.exe
O4 - Startup: YahooPOPs.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Microsoft WFC Forms Designer - file://E:\VJ98\wfcforms.cab
O16 - DPF: Visual Studio 6 Extensibility Libraries - file://E:\VJ98\vstudio6.cab
O16 - DPF: {F59AB0C4-3443-4551-A78F-C101F9DE0215} (LauncherV1 Class) - http://irc.tapuz.co.il/BlogTVU1/launcher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{60A61418-9D46-463A-83F3-1FDD52D1CCE9}: NameServer = 192.115.106.31 192.115.106.35

While writing this reply I ran a search on my computer after files that have WebRebates in their name (and that their creation date is from yesterday) and I still found 2 files: webrebates_installas.exe (under C:\WINDOWS\system32) and WEBREBATES_INSTALLAS.EXE-376FBF6F.pf (under C:\WINDOWS\Prefetch).
I'm not so sure I wanted to find these files



Wish I had the answer? After checking mine I found Spider search. :rofl:

Now it's time to check with the experts. On the one

But you log looks clean.

Please consider using Firefox it's all I use now.
http://texturizer.net/firefox/index.html

Please read this

Get back to you tomarrow or as soon as I get an answer.
From Tweaks for Windows XP
http://www.rpatrick.com/tech/tweakxp/

Clean Temp and Prefetch

I recommend that you erase all files located in your TEMP and PREFETCH folders on a monthly basis. Locations for these folders:
C:\Documents and Settings\username\Local Settings\Temp
C:\WINDOWS\TEMP
C:\WINDOWS\Prefetch

Guess it's time to clean them out :D
Don't I need any of these files?? Can I just delete all the .pf files? And even if I do - I told you I deleted some files that were related to this lzio and its implication (programs named tsl.exe, ventra1_9.exe, DealHelper.exe, myDailyHoroscope.exe), and I deleted also the .exe files along with the .pf files. It didn't help, I still had the source of all this spyware on my computer and the minute I connected to the internet - my computer was connected to lzio's site too. (this connection between my computer and this site stopped only after I restricted it through my firewall, but it didn't solve the problem of course it just hides it). What I'm trying to say is that I don't think deleteing the .pf file will work (not to mention that this way I still leave the .exe file on my computer, under C:\WINDOWS\system32)… Oh, and another thing: I checked all the files in C:\WINDOWS\TEMP - the most recently changed file (according the modifed and created date) is Class3SoftwarePublishers[1].crl, on 8/9/2004 (which is before all my problems started). The change before that occur on 2/2004… I didn't delete yet the folders you told me to. Do you still think I should delete them? Do you think this can help me? (are you sure it won't cause any further damage?) TIA

Can I just delete all the .pf files?

A soon as you use a program it will show back up in the prefetch folder again.

What I'm trying to say is that I don't think deleteing the .pf file will work (not to mention that this way I still leave the .exe file on my computer, under C:\WINDOWS\system32)…

If you look in your Windows folder, you will see a Prefetch folder. Think of this folder as a table of contents of the things that run when you start your computer and also, those things that you use the most.

It does not contain the files. The Prefetch folder only contains links or references to those items. Every three days or so during idle periods, Windows XP updates these links and saves these links on the fastest part of the hard drive. By monitoring these files, Windows XP can prefetch them at start-up.

A lot of techs believe that over time, this folder can get bogged down and full of things that a person no longer uses on a computer. After all, just about any computer user routinely adds and removes files and programs.

What I'm trying to say is that I don't think deleteing the .pf file will work (not to mention that this way I still leave the .exe file on my computer, under C:\WINDOWS\system32)…

Your right if the .exe file runs you will find it back in the prefetch folder again. but if you delete it in the prefetch folder and it doesn't show back up after a reboot then the .exe file should not be on your system.


I didn't delete yet the folders you told me to. Do you still think I should delete them? Do you think this can help me? (are you sure it won't cause any further damage?)

I recommend that you erase all files located in your TEMP and PREFETCH folders on a monthly basis. Locations for these folders:

Not the folders


Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

You may want to check your recycle bin first



Please Scan with Spybot Search and Destroy:


Downloaded and Install Spybot S&D, accepting the Default Settings

In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.

Close ALL windows except Spybot S&D

Click the button to ‘Search for Updates’ and download and install the Updates.

Next click the button ‘Check for Problems’

When Spybot is complete, it will be showing ‘RED’ (RED) entries ‘BLACK’ entries and ‘GREEN’ (GREEN) entries in the window

Make certain there is a check mark beside all of the RED (RED) entries ONLY.

Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED (RED) entries.

REBOOT to complete the scan.

Then post another log.
Thank you for your detailed reply! It's not that I solved the problem on my computer I just don't have the time to work on it (I work on my computer at work all day long, more then 14 hours a day… :( ) Anyway, I just wanted to ask you not to close this thread yet. I'll get back to it as soon as I get a few minutes to myself. Thanx.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI