This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Me Please...

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can anybody tell me what I need to delete and what I need to keep from my Hijack This log. Thanks, help is greatly appreciated. Here's my Log file: Logfile of HijackThis v1.98.2 Scan saved at 11:02:00 PM, on 12/13/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\atlbi.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\WINDOWS\System32\Software\software.exe C:\WINDOWS\system32\ipcv.exe C:\PROGRA~1\COMMON~1\tsa\tsm2.exe C:\Program Files\America Online 9.0\aoltray.exe C:\Program Files\Dell AIO Printer A960\dlbfbmon.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\America Online 9.0\waol.exe C:\Program Files\America Online 9.0\shellmon.exe C:\Program Files\America Online 9.0\aolwbspd.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\System32\dwge.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\efvee.exe C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS208.exe C:\Program Files\HijackThis\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\orwhg.dll/sp.html#29126 R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {E957FC8D-57CB-4025-F3D8-B7A984623DCA} - C:\WINDOWS\system32\addcv32.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [Dell AIO Printer A960] "C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe" O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - HKLM\..\Run: [Software] C:\WINDOWS\System32\Software\software.exe O4 - HKLM\..\Run: [ipcv.exe] C:\WINDOWS\system32\ipcv.exe O4 - HKLM\..\Run: [kalvsys] C:\windows\system32\kalvnic32.exe O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck O4 - HKCU\..\Run: [Tsa2] C:\PROGRA~1\COMMON~1\tsa\tsm2.exe O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O15 - Trusted Zone: *.awmdabest.com O15 - Trusted Zone: *.c4tdownload.com O15 - Trusted Zone: *.clickspring.net O15 - Trusted Zone: *.finefind.net O15 - Trusted Zone: *.iframe.biz O15 - Trusted Zone: *.megapornix.com O15 - Trusted Zone: *.mt-download.com O15 - Trusted Zone: *.musicmatch.com O15 - Trusted Zone: *.newiframe.biz O15 - Trusted Zone: *.overpro.com O15 - Trusted Zone: *.pizdato.biz O15 - Trusted Zone: *.slotch.com O15 - Trusted Zone: *.sp2admin.biz O15 - Trusted Zone: *.sp2fucked.biz O15 - Trusted Zone: *.vse-moe.biz O15 - Trusted Zone: *.windupdates.com O15 - Trusted Zone: *.xxxtoolbar.com O15 - Trusted Zone: *.ysbweb.com O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2 (file missing)
Click here to download CWShredder and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware SE and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Click "Start", select "Perform Full System scan" and "Next" to start the scan. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done. Rescan with HJT and post a new log here so that any remnants can be removed manually.

Also, click here to download ServiceFilter, a little script by rand1038 that reveals potential unauthorised running services in your system. Download, unzip and double-click ServiceFilter.vbs (you may need to enable your antivirus program to run the file). This script will create a text file named Post_This.txt in the same folder as the script itself has been saved - copy and paste the contents of Post_This.txt in your next reply here.
Thank you for your reply. Here are the requested logs:

~~~The new Hijack This log file~~~
Logfile of HijackThis v1.98.2
Scan saved at 10:59:06 PM, on 12/14/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\sysvq.exe
C:\WINDOWS\mfczs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vltts.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vltts.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5AE87369-A8F4-B1D6-ED81-BB42DB32D81B} - C:\WINDOWS\addmy32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [mfczs.exe] C:\WINDOWS\mfczs.exe
O4 - HKLM\..\RunOnce: [sysvq.exe] C:\WINDOWS\sysvq.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.finefind.net
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fucked.biz
O15 - Trusted Zone: *.windupdates.com
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://www.globalphon.com/dialer/internazionale_ver4.CAB
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2 (file missing)



~~~POST_THIS file from the script~~~

The script did not recognize the services listed below.
This does not mean that they are a problem.

To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows XP Professional
Version: 5.1.2600
Dec 14, 2004 11:02:39 PM


===> Begin Service Listing <===

Unknown Service #1
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Manages software-based volume shadow copies taken by the Volume Shadow Copy service. If this …
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{5d03cc0f-ecfd-4c18-ba9e-77bc2d974027}
State: Stopped
Process ID: 0
Started: False
Exit Code: 1077
Accept Pause: False
Accept Stop: False

Unknown Service # 2
Service Name: ZESOFT
Display Name: ZESOFT
Start Mode: Auto
Start Name: LocalSystem
Description: ZESoft …
Service Type: Own Process
Path: c:\windows\zeta.exe
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

Unknown Service # 3
Service Name: %AF夶À¨
Display Name: Network Security Service
Start Mode: Auto
Start Name: LocalSystem
Description: …
Service Type: Share Process
Path: c:\windows\atlbi.exe /s
State: Stopped
Process ID: 0
Started: False
Exit Code: 0
Accept Pause: False
Accept Stop: False

—> End Service Listing <—

There are 82 Win32 services on this machine.
3 were unrecognized.

Script Execution Time: 0.53125 seconds.
Print out these instructions as most of the steps need to be done in Safe Mode and you won't be able to go online.

Do this so you can see hidden files and folders - click here to download xphidden.zip. Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes. Click here to download About:Buster and unzip it to your desktop. Don´t run it yet. Also, click here to download System Security Suite. Extract it from the zip file into a folder.

Next, go to Start->Run and type Services.msc then hit Ok. Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Repeat for ZESOFT. Now hit Apply and then Ok and close any open windows.

Reboot into Safe Mode by tapping F8 after the BIOS has loaded.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\vltts.dll/sp.html#29126
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vltts.dll/sp.html#29126
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\vltts.dll/sp.html#29126
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5AE87369-A8F4-B1D6-ED81-BB42DB32D81B} - C:\WINDOWS\addmy32.dll
O4 - HKLM\..\Run: [mfczs.exe] C:\WINDOWS\mfczs.exe
O4 - HKLM\..\RunOnce: [sysvq.exe] C:\WINDOWS\sysvq.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.finefind.net
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fucked.biz
O15 - Trusted Zone: *.windupdates.com
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://www.globalphon.com/dialer/internazionale_ver4.CAB
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2 (file missing)

Find and delete the following:

c:\windows\atlbi.exe
c:\windows\zeta.exe
C:\WINDOWS\mfczs.exe
C:\WINDOWS\sysvq.exe

Now double click AboutBuster.exe that you downloaded earlier. Click Start then click OK. This will scan your computer for the bad files and delete them. Save the report (copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

Rescan with Adaware and let it remove any bad files found.

Reboot back into Normal Mode. Click here to download cwsuninst.zip. Extract cwsuninst.reg from the zip file and save it to the desktop. When done, double-click the cwsuninst.reg and when asked to merge say yes. Open System Security Suite and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Click here to make sure that you have the latest Critical Update patches for Windows. Rescan with HijackThis and post a new log here.
Thanks again for a quick reply. I did everything you told me–and the requested logs are attached–but I could not find the following two files manually or through a search so I could not delete them: c:\windows\atlbi.exe and c:\windwos\zeta.exe Here is Hijack this log: Logfile of HijackThis v1.98.2 Scan saved at 7:57:49 PM, on 12/15/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe C:\Program Files\America Online 9.0\aoltray.exe C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\System32\wuauclt.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll Here is About:Buster log: Scanned at: 7:24:33 PM on: 12/15/2004 – Scan 1 ————————— About:Buster Version 4.0 Reference List : 19 Removed Data Streams: C:\WINDOWS\DtcInstall.log:ikbek C:\WINDOWS\iis6.log:jpfvl C:\WINDOWS\KB823559.log:msatc C:\WINDOWS\Q329115.log:dqbrl C:\WINDOWS\Soap Bubbles.bmp:acesw C:\WINDOWS\vb.ini:wxtvp Removed 4 Random Key Entries ******************************** Removed sys\explorer.exe (fake) ******************************** —————————– Removed! infected hosts file. Attempted Clean Of Temp folder. Removed Uninstall Key (HSA) Removed Uninstall Key (SE) Removed Uninstall Key (SW) Pages Reset… Done! – Scan 2 ————————— About:Buster Version 4.0 Reference List : 19 Removed Data Streams: C:\WINDOWS\DtcInstall.log:ikbek C:\WINDOWS\iis6.log:jpfvl C:\WINDOWS\KB823559.log:msatc C:\WINDOWS\Q329115.log:dqbrl C:\WINDOWS\Soap Bubbles.bmp:acesw C:\WINDOWS\vb.ini:wxtvp Attempted Clean Of Temp folder. Pages Reset… Done!
It is certainly better than it was! A lot less pop-ups (I have had only a few pop ups in the last two days) and my computer runs a lot faster. However, there is a HTML document on my desktop that that covers the entire screen with a box in the middle that says "You are in danger…your computer is infected" and that kind of stuff. How do I get rid of that? Also, when I go to start and programs, there are three programsa ("VirtualGirl," "LipGame," and "! Secure Yourself") that were installed as a result of the viruses and popups on my computer. These "programs" cannot be located on the "Add/Remove Programs" in control panel. Are they actual programs and how do I delete them? My last concern is a TSA program on "Add/Remove Programs" in control panel. I'm not sure what it is and if it is good or bad. Do you know what it is and should it be deleted? Besides the above mentioned problems, everything else runs great. You have been very helpful and your help is greatly appreciated. PS: What do you mean I need to update Windows? (Are you talking about the message by the clock that says "Updates are ready for your computer?")
Click Start>Settings>Control Panel>Display>Desktop>Customise Desktop>Web and remove all checks from any boxes in there.

Let's do a detailed scan - see what is left on your system.

Click here to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
File C:\WINDOWS\d3lo32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\internet.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\WINDOWS\ipmx32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\javasz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msyz32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sideb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\vltts.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\adrbr.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\calcul.exe tagged as not-a-virus:PornWare.Dialer.Salc. No Action Taken. File C:\WINDOWS\System32\desktop.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dwge.exe infected by "TrojanDownloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\efvee.exe infected by "TrojanClicker.Win32.Agent.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\WINDOWS\System32\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\orwhg.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\sysoz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\tvmk10ez.dll infected by "not-a-virus:AdWare.EZula.ac" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\vbsys2.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winvp32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\DELL\drivers\R68973\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-6c522c5b-5bf73037.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-45fe0620-6ce70bd1.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-ab3806d-60b2e02f.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy1.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy16.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy31.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy41.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy56.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\j2sdk1.4.2_04\demo\applets\BarChart\BarChart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\j2sdk1.4.2_04\demo\plugin\applets\BarChart\BarChart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\msinfo.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Common Files\Java\Update\Base Images\j2sdk1.4.2-b28\demos.zip tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\Program Files\Common Files\tsa\tsl.exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\Program Files\Common Files\tsa\tsl2.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\Program Files\Common Files\tsa\tsp2.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\Program Files\HijackThis\backups\backup-20041213-225057-561.dll infected by "Trojan-Downloader.Win32.IstBar.gp" Virus. Action Taken: No Action Taken. File C:\Program Files\Internet Explorer\bgrkbszm.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\Program Files\Internet Explorer\wha.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\Program Files\Windows Media Player\wmplayer.exe.tmp infected by "Trojan-Downloader.Win32.Zdesnado.y" Virus. Action Taken: No Action Taken. File C:\sidebDD.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP135\A0017459.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP138\A0017583.exe infected by "Trojan-Downloader.Win32.Zdesnado.y" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP141\A0017976.exe infected by "not-a-virus:AdWare.EZula.z" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP141\A0017978.dll infected by "not-a-virus:AdWare.EZula.x" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP142\A0018021.dll infected by "not-a-virus:AdWare.SurfSide.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP144\A0018629.exe infected by "Trojan-Downloader.Win32.Zdesnado.x" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP144\A0018717.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018751.dll infected by "TrojanDownloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018753.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018759.exe infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018761.exe infected by "not-a-virus:AdWare.WebRebates.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018763.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018831.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0018902.dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP145\A0019100.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019387.exe infected by "Trojan-Downloader.Win32.Small.abp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019388.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019392.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019453.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019558.exe infected by "Trojan-Downloader.Win32.Small.abp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019559.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019561.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP146\A0019564.exe infected by "TrojanDownloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP147\A0019566.exe infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP147\A0019569.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP147\A0019587.dll infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP148\A0019616.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019776.exe infected by "Trojan-Downloader.Win32.Small.abp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019779.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019784.dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019785.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019799.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019869.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019878.dll infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019905.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP151\A0019906.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP152\A0019923.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP152\A0019934.exe infected by "Trojan-Downloader.Win32.IstBar.go" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019946.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019952.exe infected by "Trojan-Downloader.Win32.IstBar.gm" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019984.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019985.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019988.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0019990.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020022.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020023.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020109.dll infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020116.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020119.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020181.exe infected by "Trojan-Downloader.Win32.Zdesnado.y" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020213.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020234.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020419.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020423.exe infected by "Trojan-Downloader.Win32.Agent.ap" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020424.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020425.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020426.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020427.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020428.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020429.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020430.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020431.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020432.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020433.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020434.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020435.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020436.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020437.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020438.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020439.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020440.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{8DD6D61F-3491-48E6-B5FE-17129832F796}\RP153\A0020441.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\upgradetb093.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\d3lo32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS208.exe infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\v3.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.s" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS208.exe infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\v3.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.s" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\gdnUS208.exe infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\v3.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.s" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\YSBactivex.dll infected by "Trojan-Downloader.Win32.IstBar.gk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\internet.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\WINDOWS\ipmx32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\javasz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msyz32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sideb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\adrbr.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\calcul.exe tagged as not-a-virus:PornWare.Dialer.Salc. No Action Taken. File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S927S5Y3\sideb[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U22YSC25\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\desktop.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\dwge.exe infected by "TrojanDownloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\efvee.exe infected by "TrojanClicker.Win32.Agent.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\WINDOWS\system32\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\orwhg.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\sysoz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\tvmk10ez.dll infected by "not-a-virus:AdWare.EZula.ac" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\vbsys2.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\winvp32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\vltts.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken.
Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file then double-click on Killbox.exe to run it. In the 'Full Path of File to Delete' box, copy and paste the following, clicking the red 'Delete File' button after pasting each one:

C:\WINDOWS\d3lo32.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\ipmx32.exe
C:\WINDOWS\javasz.exe
C:\WINDOWS\msyz32.exe
C:\WINDOWS\System32\adrbr.dll
C:\WINDOWS\System32\calcul.exe
C:\WINDOWS\System32\desktop.exe
C:\WINDOWS\System32\dwge.exe
C:\WINDOWS\System32\efvee.exe
C:\WINDOWS\System32\instsrv.exe
C:\WINDOWS\System32\mac80ex.idf
C:\WINDOWS\System32\netut80ex.vxd
C:\WINDOWS\System32\orwhg.dll
C:\WINDOWS\System32\sysoz.exe
C:\WINDOWS\System32\tvmk10ez.dll
C:\WINDOWS\System32\vbsys2.dll
C:\msinfo.exe
C:\Program Files\Common Files\tsa\tsl.exe
C:\Program Files\Common Files\tsa\tsl2.exe
C:\Program Files\Common Files\tsa\tsp2.exe
C:\Program Files\Internet Explorer\bgrkbszm.exe
C:\Program Files\Internet Explorer\wha.exe
C:\Program Files\Windows Media Player\wmplayer.exe.tmp
C:\sidebDD.exe
C:\upgradetb093.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS208.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\v3.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS208.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\v3.dll
C:\WINDOWS\Downloaded Program Files\gdnUS208.exe
C:\WINDOWS\Downloaded Program Files\v3.dll
C:\WINDOWS\Downloaded Program Files\YSBactivex.dll
C:\WINDOWS\sideb.exe
C:\WINDOWS\system32\winvp32.exe
C:\WINDOWS\vltts.dll

Click 'Exit' when done.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.

Reboot when done. Using Windows Explorer, navigate to the !Submit folder on the C:\ drive and inside you will the files removed by TheKillbox - zip them up individually and send to this e-mail address including a link to this thread in the body of the email.

1. Right-click My Computer>Click Properties>Click the System Restore tab>Check the box next to 'Turn off System Restore on all drives'>Click Apply>Click OK.

2. Reboot.

3. Repeat the process but this time remove the check from the box.

Click here to download System Security Suite. Extract it from the zip file into a folder and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Rescan with mwavscan and post a new log.
File C:\!Submit\adrbr.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\adrbr.zip infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\bgrkbszm.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\bgrkbszm.zip infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\calcul.exe tagged as not-a-virus:PornWare.Dialer.Salc. No Action Taken. File C:\!Submit\calcul.zip tagged as not-a-virus:PornWare.Dialer.Salc. No Action Taken. File C:\!Submit\d3lo32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\d3lo32.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\desktop.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken. File C:\!Submit\desktop.zip infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken. File C:\!Submit\dwge.exe infected by "TrojanDownloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken. File C:\!Submit\dwge.zip infected by "TrojanDownloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken. File C:\!Submit\efvee.exe infected by "TrojanClicker.Win32.Agent.v" Virus. Action Taken: No Action Taken. File C:\!Submit\efvee.zip infected by "TrojanClicker.Win32.Agent.v" Virus. Action Taken: No Action Taken. File C:\!Submit\gdnUS208.exe infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: No Action Taken. File C:\!Submit\gdnUS208.zip infected by "Trojan.Win32.Dialer.ay" Virus. Action Taken: No Action Taken. File C:\!Submit\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\!Submit\instsrv.zip tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\!Submit\internet.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\!Submit\internet.zip infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken. File C:\!Submit\ipmx32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\ipmx32.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\javasz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\javasz.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\!Submit\mac80ex.zip infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\!Submit\msinfo.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\msinfo.zip infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\msyz32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\msyz32.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\netut80ex.zip infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\orwhg.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\orwhg.zip infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\sideb.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\!Submit\sideb.zip infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\!Submit\sidebDD.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\!Submit\sidebDD.zip infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\!Submit\sysoz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\sysoz.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\tsl.exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\!Submit\tsl.zip infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\!Submit\tsl2.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\!Submit\tsl2.zip infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\!Submit\tsp2.exe infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\!Submit\tsp2.zip infected by "Trojan-Downloader.Win32.TSUpdate.g" Virus. Action Taken: No Action Taken. File C:\!Submit\tvmk10ez.dll infected by "not-a-virus:AdWare.EZula.ac" Virus. Action Taken: No Action Taken. File C:\!Submit\tvmk10ez.zip infected by "not-a-virus:AdWare.EZula.ac" Virus. Action Taken: No Action Taken. File C:\!Submit\upgradetb093.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\!Submit\upgradetb093.zip infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\!Submit\v3.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.s" Virus. Action Taken: No Action Taken. File C:\!Submit\v3.zip infected by "not-a-virus:AdWare.ToolBar.EliteBar.s" Virus. Action Taken: No Action Taken. File C:\!Submit\vbsys2.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken. File C:\!Submit\vbsys2.zip infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken. File C:\!Submit\vltts.dll infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\vltts.zip infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\wha.exe infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\wha.zip infected by "Trojan-Downloader.Win32.WinShow.ao" Virus. Action Taken: No Action Taken. File C:\!Submit\winvp32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\winvp32.zip infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. File C:\!Submit\wmplayer.exe.tmp infected by "Trojan-Downloader.Win32.Zdesnado.y" Virus. Action Taken: No Action Taken. File C:\!Submit\wmplayer.exe.zip infected by "Trojan-Downloader.Win32.Zdesnado.y" Virus. Action Taken: No Action Taken. File C:\!Submit\YSBactivex.dll infected by "Trojan-Downloader.Win32.IstBar.gk" Virus. Action Taken: No Action Taken. File C:\!Submit\YSBactivex.zip infected by "Trojan-Downloader.Win32.IstBar.gk" Virus. Action Taken: No Action Taken. File C:\DELL\drivers\R68973\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-6c522c5b-5bf73037.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-45fe0620-6ce70bd1.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator.DELL\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-ab3806d-60b2e02f.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL\C_America Online 9.0\misc\temp\YSBactiv00.zip infected by "TrojanDownloader.Win32.WinShow.ak" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy1.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy16.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy31.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy41.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy56.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\j2sdk1.4.2_04\demo\applets\BarChart\BarChart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\j2sdk1.4.2_04\demo\plugin\applets\BarChart\BarChart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Common Files\Java\Update\Base Images\j2sdk1.4.2-b28\demos.zip tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\Program Files\HijackThis\backups\backup-20041213-225057-561.dll infected by "Trojan-Downloader.Win32.IstBar.gp" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\S927S5Y3\sideb[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.v" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U22YSC25\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken.
It is running good now. I tried sending those zip files through both AOL and Yahoo! but they both scan mail for viruses so they could not go through. Is there another way to send them? Did you notice anything else that needs to be done from that scan?
OK, just delete the C:\!Submit folder. Run SSS again and you should be good to go. To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI