This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help, Please

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am in need of help from wiser heads. A few days ago, my son's computer (Windows ME) was infected with some nasty stuff. The first clue was a number of new desktop icons overnight, which I took to be some adventurous downloading on his part. It wasn't. I have run Ad-Aware, Spybot, Hijack This! and CWS Shredder without success. Occasionally, the machine will mysteriously download and install new desktop icons and programs - icons for e-bay, a dating service, and other miscellany. It also installed an icon for "My Daily Horoscope" down in the tray at the lower right of the screen. Spybot finds one or two problems and declares them fixed; Ad-Aware has found up to 100+, and declared all fixed except a handful of files in [C:\_RESTORE\TEMP. . .]. This folder is hidden; that is, the "TEMP" folder is not visible when c:_RESTORE is opened. It can be accessed directly through the "run option." Attempts to manually delete these files are denied ("access denied: source file may be in use.") Ad-Aware will find and fix, say, 100 problems one time, and fifteen minutes later (without having gone online) will find, say 25. The recurring items in Ad-Aware are Ezula, Ibis Toolbar, and Vx2. The computer periodically pops up full sized browsers for "Spotresults.com" and "Ad-w-a-r-e.com" The latest was "www.Ad-w-a-r-e.com/callback_ron.php?GUID. . . ."

Logs are posted below. Your help will be appreciated.

Hijack This!
Logfile of HijackThis v1.98.2
Scan saved at 5:06:31 PM, on 10/6/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServicesOnce: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot
O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - https://www.spydeleter.com/order2.php?KBID=1062 (file missing)

NOTE: ALL EXCEPT "EXTRA BUTTON" WERE KILLED BY HIJACK THIS

Spybot:

Virtual Bouncer: Program directory (Directory, nothing done)
C:\Program Files\VBOUNCER\

Common hijacker: Redirected host (Redirected host, nothing done)


Common hijacker: Redirected host (Redirected host, nothing done)


IGetNet: Redirected host (Redirected host, nothing done)



— Spybot - Search && Destroy version: 1.3 —
2004-08-11 Includes\Cookies.sbi
2004-09-30 Includes\Dialer.sbi
2004-09-30 Includes\Hijackers.sbi
2004-09-30 Includes\Keyloggers.sbi
2004-09-30 Includes\Malware.sbi
2004-08-12 Includes\Revision.sbi
2004-09-16 Includes\Security.sbi
2004-09-30 Includes\Spybots.sbi
2004-09-30 Includes\Trojans.sbi
2004-05-12 Includes\LSP.sbi
2004-08-30 Includes\Tracks.uti


Ad-Aware:

Ad-Aware SE Build 1.05
Logfile Created on:Wednesday, October 06, 2004 5:10:06 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R10 28.09.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
BroadCastPC(TAC index:7):3 total references
EzuLa(TAC index:6):16 total references
IBIS Toolbar(TAC index:5):102 total references
MRU List(TAC index:0):7 total references
Tracking Cookie(TAC index:3):10 total references
VX2(TAC index:10):14 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


10-6-2004 5:10:06 PM - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [KERNEL32.DLL]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4293871077
Threads : 5
Priority : High
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
ProductName : Microsoft® Windows® Millennium Operating System
CompanyName : Microsoft Corporation
FileDescription : Win32 Kernel core component
InternalName : KERNEL32
LegalCopyright : Copyright © Microsoft Corp. 1991-2000
OriginalFilename : KERNEL32.DLL

#:2 [MSGSRV32.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294935301
Threads : 1
Priority : Normal
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
ProductName : Microsoft® Windows® Millennium Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows 32-bit VxD Message Server
InternalName : MSGSRV32
LegalCopyright : Copyright © Microsoft Corp. 1992-1998
OriginalFilename : MSGSRV32.EXE

#:3 [SPOOL32.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294937469
Threads : 4
Priority : Normal
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
ProductName : Microsoft® Windows® Millennium Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler Sub System Process
InternalName : spool32
LegalCopyright : Copyright © Microsoft Corp. 1994 - 1998
OriginalFilename : spool32.exe

#:4 [MPREXE.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294842785
Threads : 2
Priority : Normal
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
ProductName : Microsoft® Windows® Millennium Operating System
CompanyName : Microsoft Corporation
FileDescription : WIN32 Network Interface Service Process
InternalName : MPREXE
LegalCopyright : Copyright © Microsoft Corp. 1993-2000
OriginalFilename : MPREXE.EXE

#:5 [LEXBCES.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294779637
Threads : 7
Priority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : © 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LexBceS.exe

#:6 [RPCSS.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294773177
Threads : 5
Priority : Normal
FileVersion : 4.71.3328
ProductVersion : 4.71.3328
ProductName : Microsoft® Windows NT™ Operating System
CompanyName : Microsoft Corporation
FileDescription : Distributed COM Services
InternalName : rpcss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1998
OriginalFilename : rpcss.exe

#:7 [LEXPPS.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294828805
Threads : 10
Priority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LEXPPS.EXE
InternalName : LEXPPS
LegalCopyright : © 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LEXPPS.EXE
Comments : MarkVision for Windows '95 New P2P Server (32-bit)

#:8 [mmtask.tsk]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294744921
Threads : 1
Priority : Normal
FileVersion : 4.90.3000
ProductVersion : 4.90.3000
ProductName : Microsoft Windows
CompanyName : Microsoft Corporation
FileDescription : Multimedia background task support module
InternalName : mmtask.tsk
LegalCopyright : Copyright © Microsoft Corp. 1991-2000
OriginalFilename : mmtask.tsk

#:9 [DDHELP.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294650437
Threads : 2
Priority : Realtime
FileVersion : 4.07.01.3000
ProductVersion : 4.07.01.3000
ProductName : Microsoft® DirectX for Windows® 95 and 98
CompanyName : Microsoft Corporation
FileDescription : Microsoft DirectX Helper
InternalName : DDHelp.exe
LegalCopyright : Copyright © Microsoft Corp. 1994-2000
OriginalFilename : DDHelp.exe

#:10 [EXPLORER.EXE]
FilePath : C:\WINDOWS\
ProcessID : 4294667617
Threads : 30
Priority : Normal
FileVersion : 5.50.4134.100
ProductVersion : 5.50.4134.100
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : EXPLORER.EXE

#:11 [STIMON.EXE]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294638873
Threads : 5
Priority : Normal
FileVersion : 4.90.3000.1
ProductVersion : 4.90.3000.1
ProductName : Microsoft® Windows® Millennium Operating System
CompanyName : Microsoft Corporation
FileDescription : Still Image Devices Monitor
InternalName : STIMON
LegalCopyright : Copyright © Microsoft Corp. 1981-2000
OriginalFilename : STIMON.EXE

#:12 [AD-AWARE.EXE]
FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PERSONAL\
ProcessID : 4294588817
Threads : 2
Priority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}

EzuLa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
Value :

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}

EzuLa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
Value :

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\web offer

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\explorer bars\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}

EzuLa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\explorer bars\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
Value : BarSize

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : protocols\name-space handler\res\wtoolsb.resprotocol

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : protocols\name-space handler\res\wtoolsb.resprotocol
Value :

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : wtoolsb.resprotocol

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : wtoolsb.resprotocol
Value :

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a8deb4a5-d9ef-4d21-b4f6-921475004e7d}

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{a8deb4a5-d9ef-4d21-b4f6-921475004e7d}
Value :

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{87766247-311c-43b4-8499-3d5fec94a183}

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{87766247-311c-43b4-8499-3d5fec94a183}
Value :

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{87067f04-de4c-4688-bc3c-4fcf39d609e7}

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hrl4nyirlx2j4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hr8g8kmi4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hrhrirlx2j4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hrhrirlx2j25s

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hrjy3ralsr4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : hminlzz2ym5hx3rk4irx

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : a4ix

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : alk3hm

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_USERS
Object : .DEFAULT\software\wintools
Value : 4irx2y4mnrk

IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : k25s4ak

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : llrmli

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : llrm8g8

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrhri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : z225s

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 25s2jr2bjy4x

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrlki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrbdlki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczr8g8

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : librmlczr8g8

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrli

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : librmlczrli

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : librmlczrhri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrjy3ralsr

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : librmlczrjy3ralsr

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2xhr

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zxhr

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : lkkrzl7

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : lkjhn2j

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : lkbd4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : lkixw4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : libkrzl7

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 25s4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 25swrx

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 5x62lalk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 5x62labd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 5x62laiar2

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzz2ym5hx3t

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzz2ym5hx3i7i

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzz2ym5hx3i7iru

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzzijyd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhminlcy4nhm5y

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhmin2ym5hx3

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhminml3r

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhmina4czhijrx

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : wrxcyir

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 5hxinlk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 5hxinbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rlk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rhri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rja

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rlkbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mml3rrihri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhminlzzhm5yt

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mhminlzzhm5y1

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 8g84xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : li4xz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mkralk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mkrabd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mkrari

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mkrahri

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 4mkraja

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : rmlczrl4nyhmin

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : n4hk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzz2ym5hx3rk

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : hminlzzzrwrz

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 24irxi

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : kydmklnr

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2lki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zlki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2rlki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zrlki

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2bd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2rbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zrbd

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 28g8

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2z8g8

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2li

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\wintools
Value : 2zli

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 99
Objects found so far: 106


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 106


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:[removed]/
Expires : 11-4-2004 9:15:38 PM
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@advertising[1].txt
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Expires : 10-4-2009 9:15:38 PM
LastSync : Hits:3
UseCount : 0
Hits : 3

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@doubleclick[1].txt
Category : Data Miner
Comment : Hits:3
Value : Cookie:[removed]/
Expires : 12-31-2030 7:59:58 PM
LastSync : Hits:3
UseCount : 0
Hits : 3

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@hitbox[1].txt
Category : Data Miner
Comment : Hits:17
Value : Cookie:[removed]/
Expires : 10-5-2005 9:16:12 PM
LastSync : Hits:17
UseCount : 0
Hits : 17

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment : Hits:8
Value : Cookie:[removed]/
Expires : 10-5-2005 9:16:12 PM
LastSync : Hits:8
UseCount : 0
Hits : 8

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 5
Objects found so far: 111



Deep scanning and examining files (c:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

VX2 Object Recognized!
Type : File
Data : A0394296.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0396408.1
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0396409.1
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0396410.1
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0397407.1
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0398409.1
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



EzuLa Object Recognized!
Type : File
Data : A0400631.1
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\
FileVersion : 0, 407, 14, 1347
ProductVersion : 2, 0, 0, 0
FileDescription : updak
InternalName : updak.dll


IBIS Toolbar Object Recognized!
Type : File
Data : A0400725.0
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400728.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400729.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400730.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400731.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



EzuLa Object Recognized!
Type : File
Data : A0400732.0
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\
FileVersion : 0, 407, 14, 1347
ProductVersion : 2, 0, 0, 0
FileDescription : updak
InternalName : updak.dll


IBIS Toolbar Object Recognized!
Type : File
Data : A0400733.0
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\



IBIS Toolbar Object Recognized!
Type : File
Data : A0400843.0
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400914.0
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : A0400994.CPY
Category : Malware
Comment :
Object : c:\_RESTORE\TEMP\



EzuLa Object Recognized!
Type : File
Data : A0400995.CPY
Category : Data Miner
Comment :
Object : c:\_RESTORE\TEMP\



VX2 Object Recognized!
Type : File
Data : UbBUI.DLL
Category : Malware
Comment :
Object : c:\WINDOWS\SYSTEM\



BroadCastPC Object Recognized!
Type : File
Data : GLK43A3.TMP
Category : Data Miner
Comment :
Object : c:\WINDOWS\TEMP\



BroadCastPC Object Recognized!
Type : File
Data : GLM43B0.TMP
Category : Data Miner
Comment :
Object : c:\WINDOWS\TEMP\



BroadCastPC Object Recognized!
Type : File
Data : GLM5236.TMP
Category : Data Miner
Comment :
Object : c:\WINDOWS\TEMP\



Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@hitbox[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@hitbox[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@doubleclick[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@doubleclick[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\[removed][2].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : anyuser@advertising[1].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\anyuser@advertising[1].txt

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [removed][2].txt
Category : Data Miner
Comment :
Value : c:\WINDOWS\Cookies\[removed][2].txt

IBIS Toolbar Object Recognized!
Type : File
Data : WToolsB.dll
Category : Data Miner
Comment :
Object : c:\Program Files\Common Files\WinTools\



Disk Scan Result for c:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 139


Scanning Hosts file……
Hosts file location:"C:\WINDOWS\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
13 entries scanned.
New critical objects:0
Objects found so far: 139




Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\web offer

EzuLa Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\explorer bars\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}

EzuLa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\internet explorer\explorer bars\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
Value : BarSize

EzuLa Object Recognized!
Type : Folder
Category : Data Miner
Comment :
Object : C:\WINDOWS\Start Menu\Programs\EARN

EzuLa Object Recognized!
Type : File
Data : EARN website.url
Category : Data Miner
Comment :
Object : C:\WINDOWS\Start Menu\Programs\earn\



EzuLa Object Recognized!
Type : File
Data : About EARN.lnk
Category : Data Miner
Comment :
Object : C:\WINDOWS\Start Menu\Programs\earn\



IBIS Toolbar Object Recognized!
Type : Regkey
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\wintools

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\wintools
Value : DisplayName

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\wintools
Value : UninstallString

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\wintools
Value : Publisher

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\uninstall\wintools
Value : URLInfoAbout

IBIS Toolbar Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\run
Value : WinTools

VX2 Object Recognized!
Type : File
Data : bw.exe
Category : Malware
Comment :
Object : C:\WINDOWS\TEMP\



Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 13
Objects found so far: 152

5:15:45 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:05:38.120
Objects scanned:56108
Objects identified:145
Objects ignored:0
New critical objects:145



Thank you
Greetings and welcome to TomCoyote.org!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
MOVE HijackThis into this folder, and off the desktop.

If required a tutorial is here = Hijackthis Folder Tutorial

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE

O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE

O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE

O4 - HKLM\..\RunServicesOnce: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot

O4 - HKCU\..\Run: [MyDailyHoroscope] C:\PROGRA~1\MYDAIL~1\MYDAIL~1.EXE

O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\program files\vbouncer <— FOLDER

c:\program files\common files\wintools <— FOLDER

c:\program files\my daily horoscope <— FOLDER

c:\program files\web offer <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Copy the following quote box into Notepad:

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]


Save it to your desktop as "fixme.reg".

Double-click the "fixme.reg" file on the desktop. Say "yes" to the next prompt. Then you can delete the "fixme.reg" file.

This process is the only way to remove this:

O9 - Extra button: Your PC is infected with Spyware - click here to fix your PC - {FB74C951-ACA1-4e33-A94C-A9261EB2CCB7} - https://www.spydeleter.com/order2.php?KBID=1062 (file missing)

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Followed instructions. Couldn't copy the HJT log, but it found nothing. I did get another "spotresults.com" popup browser when I logged back on. I'll run Ad-Aware again & see what I get. I'll post results. Thanks. Outstanding sig line, BTW.
Arrrgh (in a totally non-piratical sense.) Here's the post-fix Ad-Aware log (HJT still shows no problems.) Ad-Aware SE Build 1.05 Logfile Created on:Wednesday, October 06, 2004 7:56:49 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R10 28.09.2004 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» EzuLa(TAC index:6):3 total references IBIS Toolbar(TAC index:5):4 total references MRU List(TAC index:0):7 total references Tracking Cookie(TAC index:3):12 total references VX2(TAC index:10):19 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 10-6-2004 7:56:49 PM - Scan started. (Full System Scan) MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\runmru Description : mru list for items opened in start | run MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : .DEFAULT\software\corel\user assistant\8\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : .DEFAULT\software\corel\user assistant\8\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [KERNEL32.DLL] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4293866067 Threads : 5 Priority : High FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Win32 Kernel core component InternalName : KERNEL32 LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : KERNEL32.DLL #:2 [MSGSRV32.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294964403 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Windows 32-bit VxD Message Server InternalName : MSGSRV32 LegalCopyright : Copyright © Microsoft Corp. 1992-1998 OriginalFilename : MSGSRV32.EXE #:3 [mmtask.tsk] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294857907 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft Windows CompanyName : Microsoft Corporation FileDescription : Multimedia background task support module InternalName : mmtask.tsk LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : mmtask.tsk #:4 [MPREXE.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294860663 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : WIN32 Network Interface Service Process InternalName : MPREXE LegalCopyright : Copyright © Microsoft Corp. 1993-2000 OriginalFilename : MPREXE.EXE #:5 [EXPLORER.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294839139 Threads : 31 Priority : Normal FileVersion : 5.50.4134.100 ProductVersion : 5.50.4134.100 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : EXPLORER.EXE #:6 [RUNDLL32.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294875327 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Run a DLL as an App InternalName : rundll LegalCopyright : Copyright © Microsoft Corp. 1991-1998 OriginalFilename : RUNDLL.EXE #:7 [SPOOL32.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294755643 Threads : 4 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Spooler Sub System Process InternalName : spool32 LegalCopyright : Copyright © Microsoft Corp. 1994 - 1998 OriginalFilename : spool32.exe #:8 [LEXBCES.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294656571 Threads : 7 Priority : Normal FileVersion : 7.4 ProductVersion : 7.4 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LexBce Service InternalName : LexBce Service LegalCopyright : © 1993 - 2002 Lexmark International, Inc. OriginalFilename : LexBceS.exe #:9 [RPCSS.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294661947 Threads : 5 Priority : Normal FileVersion : 4.71.3328 ProductVersion : 4.71.3328 ProductName : Microsoft® Windows NT™ Operating System CompanyName : Microsoft Corporation FileDescription : Distributed COM Services InternalName : rpcss.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1998 OriginalFilename : rpcss.exe #:10 [LEXPPS.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294649239 Threads : 10 Priority : Normal FileVersion : 7.4 ProductVersion : 7.4 ProductName : MarkVision for Windows (32 bit) CompanyName : Lexmark International, Inc. FileDescription : LEXPPS.EXE InternalName : LEXPPS LegalCopyright : © 1993 - 2002 Lexmark International, Inc. OriginalFilename : LEXPPS.EXE Comments : MarkVision for Windows '95 New P2P Server (32-bit) #:11 [STIMON.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294759387 Threads : 5 Priority : Normal FileVersion : 4.90.3000.1 ProductVersion : 4.90.3000.1 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Still Image Devices Monitor InternalName : STIMON LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : STIMON.EXE #:12 [TAPISRV.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294520215 Threads : 8 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Microsoft® Windows™ Telephony Server InternalName : Telephony Service LegalCopyright : Copyright © Microsoft Corp. 1994-1998 OriginalFilename : TAPISRV.EXE #:13 [RNAAPP.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294569999 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Dial-Up Networking Application InternalName : RNAAPP LegalCopyright : Copyright © Microsoft Corp. 1992-1996 OriginalFilename : RNAAPP.EXE #:14 [AD-AWARE.EXE] FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PERSONAL\ ProcessID : 4294564815 Threads : 2 Priority : Normal FileVersion : 6.2.0.206 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 7 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 7 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 7 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 11-5-2004 6:36:22 PM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@advertising[1].txt Category : Data Miner Comment : Hits:3 Value : Cookie:[removed]/ Expires : 10-5-2009 6:36:22 PM LastSync : Hits:3 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@atdmt[1].txt Category : Data Miner Comment : Hits:1 Value : Cookie:[removed]/ Expires : 10-4-2009 8:00:00 PM LastSync : Hits:1 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@doubleclick[2].txt Category : Data Miner Comment : Hits:4 Value : Cookie:[removed]/ Expires : 10-6-2007 6:36:00 PM LastSync : Hits:4 UseCount : 0 Hits : 4 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@hitbox[1].txt Category : Data Miner Comment : Hits:31 Value : Cookie:[removed]/ Expires : 10-6-2005 6:41:34 PM LastSync : Hits:31 UseCount : 0 Hits : 31 Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Hits:15 Value : Cookie:[removed]/ Expires : 10-6-2005 6:41:34 PM LastSync : Hits:15 UseCount : 0 Hits : 15 Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 6 Objects found so far: 13 Deep scanning and examining files (c:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» VX2 Object Recognized! Type : File Data : A0394296.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0396408.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0396409.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0396410.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0397407.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0398409.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ EzuLa Object Recognized! Type : File Data : A0400631.0 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ FileVersion : 0, 407, 14, 1347 ProductVersion : 2, 0, 0, 0 FileDescription : updak InternalName : updak.dll IBIS Toolbar Object Recognized! Type : File Data : A0400725.1 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400728.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400729.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400730.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400731.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ EzuLa Object Recognized! Type : File Data : A0400732.1 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ FileVersion : 0, 407, 14, 1347 ProductVersion : 2, 0, 0, 0 FileDescription : updak InternalName : updak.dll IBIS Toolbar Object Recognized! Type : File Data : A0400733.1 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ IBIS Toolbar Object Recognized! Type : File Data : A0400843.1 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400914.1 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0400994.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ EzuLa Object Recognized! Type : File Data : A0400995.0 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : A0401983.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ IBIS Toolbar Object Recognized! Type : File Data : A0401984.0 Category : Data Miner Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : UZBUI.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : WNTDECOD.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : IUSETUP.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : IGSETUP.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : BDOWSELC.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ VX2 Object Recognized! Type : File Data : MMLOCUSR.0 Category : Malware Comment : Object : c:\_RESTORE\TEMP\ Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@hitbox[1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@hitbox[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\[removed][1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@advertising[1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@advertising[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@doubleclick[2].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@doubleclick[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@atdmt[1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@atdmt[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : [removed][1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\[removed][1].txt Disk Scan Result for c:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 45 Scanning Hosts file…… Hosts file location:"C:\WINDOWS\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 10 entries scanned. New critical objects:0 Objects found so far: 45 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 45 8:02:20 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:05:30.650 Objects scanned:56499 Objects identified:38 Objects ignored:0 New critical objects:38 It seems that ezula, Ibis Toolbar, and Vx2 are regenerating from the c:\RESTORE\TEMP files. That's where Ad-Aware keeps finding them. Any more ideas?
All the files that have "restore" in them are in your system restore area.

Go here:

System Restore

To learn how to turn system restore ON/OFF.

Then turn system restore OFF.

Run the Adaware scan. If should be able to take care of those files.

Afterwards turn system restore ON then reboot.

The tracking cookies are more of a nuisance than a threat.

Just for the record, not everything HIjack This! finds is "bad". It shows all the running programs, then we have to decipher what to keep and what is malware.

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI