This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vx2 Problem -- I Think

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HijackThis is running from a temporary folder

Create a new folder called C:HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qvugiw.exe

Click here, for instructions on how to enable hidden files and folders to be visible. After enabling, reboot into Safe Mode by tapping F8 after the BIOS has loaded, find and delete the following:

C:\WINDOWS\qvugiw.exe

Reboot back to Normal Mode when done. Rescan with HJT and post a new log here.
After the last procedures here is the HJT log:

Logfile of HijackThis v1.99.0
Scan saved at 7:20:19 PM, on 2/2/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\ENCOMPASS\ENCMONTR.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKD.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXAUTOUP.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXSHELL.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\@HOME\TIOGA\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\INTEL\INTEL PSNCU\CPUNUMBER.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKICE.EXE
C:\PROGRAM FILES\INTUIT\QUICKBOOKS PRO 2\COMPONENTS\QBAGENT\QBDAGENT2001.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\FKGIUH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\Monwow.exe
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\HIJACK THIS FOLDER\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f514.mail.yahoo.com/ym/login?.rand=4pds53067jd93
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F1 - win.ini: run=hpfsched
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Excite Platform] C:\PROGRA~1\EXCITE\PLATFORM\ExLaunch.exe
O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRAM FILES\COMMON FILES\AT&T\REDCON\PROGRAMS\AutoUpdate.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MSWheel] C:\WINDOWS\SYSTEM\mswheel.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TgAddServer] "C:\@Home\tioga\bin\tgfix" /fds "http://www/download/tioga"
O4 - HKLM\..\Run: [Tgcmd] "C:\@Home\tioga\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qvugiw.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinject.exe
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Encompass\ENCMONTR.EXE
O4 - HKLM\..\RunServices: [LoadBlackD] C:\Program Files\Network ICE\BlackICE\blackd.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IntelProcNumUtility] "C:\Program Files\Intel\Intel PSNCU\CpuNumber.exe" /nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Event Reminder.lnk = C:\PMG4\PMREMIND.EXE
O4 - Startup: BlackICE Utility.lnk = C:\Program Files\Network ICE\BlackICE\blackice.exe
O4 - Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro 2\Components\QBAgent\qbdagent2001.exe
O4 - Startup: fkgiuh.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra button: (no name) - {24E80680-B284-11D4-9FAA-00E029572CC5} - (no file) (HKCU)
O12 - Plugin for .lio: c:\PROGRA~1\INTERN~1\PLUGINS\NPMAD32L.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {8433A16D-1B78-11D4-8006-00D0B725EB0B} (Yahoo! FinanceVision (History)) - http://dl1.yahoo.com/dl/fv/fv.cab
O16 - DPF: {AEAD8593-667F-11D3-82FA-005004185BB3} (Servicesoft VoiceControl) - http://12.18.140.235/java/nm.cab
O16 - DPF: {1FA643B0-F90E-11D3-BA0B-00C04F384A92} (HomeTsrCtrl Class) - http://image.excite.com/sputnik/dynacat_up…ationchange.dll
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab
O16 - DPF: {47F591A2-8783-11D2-8343-00A0C945A819} (RFXPlayer Class) - http://download.richfx.com/player/mediaver…st/twophase.cab
O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4010/ftp…21/cpbrkpie.cab
O16 - DPF: {B33CCD56-0909-42C9-8A88-8976F66B8BF2} (AOL YGP Picture Finder Tool) - http://pak01.pictures.aol.com/ygp/aol/plug…der.8.0.3.0.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://pak02.pictures.aol.com/ygp/aol/plug…oad.9.0.0.2.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup…p1/imloader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://nada.webex.com/client/latest/webex/ieatgpc.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://69.95.9.175/activex/AxisCamControl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab




Looks like it is still there. I even tried the procedure twice. FYI– I also found qvugiw.exe in a folder C:\!Submit. I deleted it there as well.

Thanks again! I await further instructions. The good news is the browser hijacks seem to have stopped.
Log from qooligic: ECHO is off PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder………… ———————— C:\WINDOWS\qvugiw.exe: .aspack C:\WINDOWS\installer.exe: .aspack C:\WINDOWS\gwukap.dat: .aspack Files Found in all users startup Folder………… ———————— C:\WINDOWS\Start Menu\Programs\StartUp\fkgiuh.exe: .aspack Files Found in all users windows Folder………… ———————— C:\WINDOWS\USER.DAT: Qoologic C:\WINDOWS\USER.DAT: QOOLOGIC C:\WINDOWS\USER.DAT: ExtractToC:\Program Files\Qoologic\ C:\WINDOWS\USER.DAT: extract5C:\Program Files\Qoologicq C:\WINDOWS\knconh.dll: excl_urls=adsv2.delfinproject.com,popup.msn.com,i.emarketresearchgroup.com,u.clkoptimizer.com,ezula.com,ads2.revenue.net,banners.pennyweb.com,counters.honesty.com,ads.bidclix.com,oz.valueclick.com,radio.launch.yahoo.com,zone.msn.com,sr.adwave.com,xlime.offeroptimizer.com,clickit.go2net.com,us.update.companion.yahoo.com,kill-pop-ups.com,qksrv.net,clickspring.net,cdn-aimtoday.aol.com,search200.com,servedby.adscpm.com,xanga.com,count.exitexchange.com,jnictech.cjt1.net,xadsq.offeroptimizer.com,paypopup.com,popuptraffic.com,cdn-cf.aol.com,allaboutsearching.com,hotmail.msn.com,adfarm.mediaplex.com,by.optimost.com,amch.questionmarket.com,akapp.whenu.com,newupdates.lzio.com,cfg.mywebsearch.com,searcheffect.com,ads.delfinproject.com,master.mx-targeting.com,hotmail.com,ctl.twain-tech.com,mail.yahoo.com,m2.doubleclick.net,insider.msg.yahoo.com,focusin.ads.targetnet.com,e.rn11.com,jmnad1.com,topicks.com,ad.doubleclick.net,m3.doubleclick.net,as.casalemedia.com,pgq.yahoo.com,webpdp.gator.com,stopzilla.com,ayb.lop.com,xadso.offeroptimizer.com,download.smileycentral.com,mm.delfinproject.com,view.atdmt.com,delfinproject.com,jbns2.cydoor.com,bannerfarm.ace.advertising.com,as.adwave.com,popuppers.com,look2me.com,wisapidata.weatherbug.com,ads.addynamix.com,ar.atwola.com,ad.trafficmp.com,updates.qoologic.com,ads1.revenue.net,weatherbug.com,jicmedia.cjt1.net,games.yahoo.com,adsrv.qoologic.com,servedby.advertising.com,ww2.weatherbug.com,rightmedia.net,bannerserver.gator.com,www4.yesadvertising.com,mmm.media-motor.net,hop.clickbank.net,media76.fastclick.net,websearch.com,isapi60.weatherbug.com,web.tickle.com,messenger.zango.com,wwp.icq.com,smileycentral.com,adserv1.gruvmedia.com,cdn.icq.com,s.clkoptimizer.com,tv.180solutions.com,pops.browseraid.com,download.abetterinternet.com,adserv.internetfuel.com,messenger.msn.com,sr.websearch.com,top-banners.com,advert.runescape.com,join1.winhundred.com,odysseusmarketing.com,v4.windowsupdate.microsoft.com,adverts.lzio.com,windowsupdate.microsoft.com,filter.belkin.com,comcast.net,sc.musicmatch.com,license.hotbar.com,trk.pcsecurityshield.com,web.icq.com,whenusearch.com,jbigpops.cjt1.net,isg05.casalemedia.com,yahoo.com,aol.com,anrdoezrs.net,microsoft.com,target.com,aim-charts.pf.aol.com,download.websearch.com,actualdeals.com,images.trafficmp.com,mydailyhoroscope.net,couponage.com,c5.zedo.com,ekmas.com,ads.mydailyhoroscope.net,creativeby.viewpoint.com,affiliates.4lowrates.com,hits.clickandtrack.net,jcontent.bns1.net,clickserve.cc-dt.com,popups.ad-logics.com,adlog2.lzio.com,host239.ipowerweb.com,bv.channel.aol.com,img2.mailpostdirect.com,dw.dailywinner.net,toprebates.com,trk.bestmagsdirect.com,ads.clickagents.com,a.websponsors.com,sandboxer.com,media.fastclick.net,click2.containsitall.com,ads234.com,http300.edge.ru4.com,adlog.com.com,rs.websearch.com,ads.com.com,server.iad.liveperson.net, C:\WINDOWS\sipnoe.dll: updates.qoologic.com C:\WINDOWS\xluazh.exe: updates.qoologic.com C:\WINDOWS\iluqyc.dll: updates.qoologic.com Finished
Start Killbox, copy and paste each of the following lines into the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:

C:\WINDOWS\qvugiw.exe
C:\WINDOWS\gwukap.dat
C:\WINDOWS\Start Menu\Programs\StartUp\fkgiuh.exe
C:\WINDOWS\knconh.dll
C:\WINDOWS\sipnoe.dll
C:\WINDOWS\xluazh.exe
C:\WINDOWS\iluqyc.dll


For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

Reboot if it doesn't do so automatically and post a new qoologic log.
New qoologic log: ECHO is off PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder………… ———————— C:\WINDOWS\installer.exe: .aspack Files Found in all users startup Folder………… ———————— Files Found in all users windows Folder………… ———————— C:\WINDOWS\USER.DAT: Qoologic C:\WINDOWS\USER.DAT: QOOLOGIC C:\WINDOWS\USER.DAT: Qoologic C:\WINDOWS\USER.DAT: QOOLOGIC C:\WINDOWS\USER.DAT: qoologic C:\WINDOWS\USER.DAT: QOOLOGIC C:\WINDOWS\USER.DAT: dQoologic log 2-3-05.txt C:\WINDOWS\USER.DAT: Qoologic log 2-3-05.txt.lnk C:\WINDOWS\USER.DAT: ExtractToC:\Program Files\Qoologic\ C:\WINDOWS\USER.DAT: Qoologic log 2-3-05.txt.lnk C:\WINDOWS\USER.DAT: extract5C:\Program Files\Qoologic8 Finished
HJT log:

Logfile of HijackThis v1.99.0
Scan saved at 5:24:46 PM, on 2/4/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXAUTOUP.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXSHELL.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\@HOME\TIOGA\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\INTEL\INTEL PSNCU\CPUNUMBER.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKICE.EXE
C:\PROGRAM FILES\INTUIT\QUICKBOOKS PRO 2\COMPONENTS\QBAGENT\QBDAGENT2001.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\Monwow.exe
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\PROGRAM FILES\AMERICA ONLINE 7.0\WAOL.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\HIJACK THIS FOLDER\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f514.mail.yahoo.com/ym/login?.rand=4pds53067jd93
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F1 - win.ini: run=hpfsched
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Excite Platform] C:\PROGRA~1\EXCITE\PLATFORM\ExLaunch.exe
O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRAM FILES\COMMON FILES\AT&T\REDCON\PROGRAMS\AutoUpdate.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MSWheel] C:\WINDOWS\SYSTEM\mswheel.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TgAddServer] "C:\@Home\tioga\bin\tgfix" /fds "http://www/download/tioga"
O4 - HKLM\..\Run: [Tgcmd] "C:\@Home\tioga\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qvugiw.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinject.exe
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Encompass\ENCMONTR.EXE
O4 - HKLM\..\RunServices: [LoadBlackD] C:\Program Files\Network ICE\BlackICE\blackd.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IntelProcNumUtility] "C:\Program Files\Intel\Intel PSNCU\CpuNumber.exe" /nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Event Reminder.lnk = C:\PMG4\PMREMIND.EXE
O4 - Startup: BlackICE Utility.lnk = C:\Program Files\Network ICE\BlackICE\blackice.exe
O4 - Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro 2\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra button: (no name) - {24E80680-B284-11D4-9FAA-00E029572CC5} - (no file) (HKCU)
O12 - Plugin for .lio: c:\PROGRA~1\INTERN~1\PLUGINS\NPMAD32L.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {8433A16D-1B78-11D4-8006-00D0B725EB0B} (Yahoo! FinanceVision (History)) - http://dl1.yahoo.com/dl/fv/fv.cab
O16 - DPF: {AEAD8593-667F-11D3-82FA-005004185BB3} (Servicesoft VoiceControl) - http://12.18.140.235/java/nm.cab
O16 - DPF: {1FA643B0-F90E-11D3-BA0B-00C04F384A92} (HomeTsrCtrl Class) - http://image.excite.com/sputnik/dynacat_up…ationchange.dll
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab
O16 - DPF: {47F591A2-8783-11D2-8343-00A0C945A819} (RFXPlayer Class) - http://download.richfx.com/player/mediaver…st/twophase.cab
O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4010/ftp…21/cpbrkpie.cab
O16 - DPF: {B33CCD56-0909-42C9-8A88-8976F66B8BF2} (AOL YGP Picture Finder Tool) - http://pak01.pictures.aol.com/ygp/aol/plug…der.8.0.3.0.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://pak02.pictures.aol.com/ygp/aol/plug…oad.9.0.0.2.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup…p1/imloader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://nada.webex.com/client/latest/webex/ieatgpc.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://69.95.9.175/activex/AxisCamControl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qvugiw.exe

Reboot. Click here to download vx2fix15.zip. Extract vx2fix15.reg from the zip file and copy it to the desktop of the infected computer. When done, double click the vx2fix15.reg and when asked to merge say yes.

Rescan with HJT and post a final log here. Let me know how it's running now.
Ran HJT twice to attempt to fix. When I clicked the fix button all the entries on the screen disappeared and it didn't say if it fixed it or was unable to fix it.

Downloaded vx2fix15.reg and extracted it to the desktop. It asked if I wanted to add it to my registration and I clicked yes. It then said it was successful. Was it supposed to do anything else?

Latest HJT log:

Logfile of HijackThis v1.99.0
Scan saved at 10:33:59 AM, on 2/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\SYSTEM\WINMODEM.101\wmexe.exe
C:\PROGRAM FILES\ENCOMPASS\ENCMONTR.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKD.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\QVUGIW.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\PASSWORD MANAGER\ACCTMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXAUTOUP.EXE
C:\PROGRAM FILES\EXCITE\PLATFORM\EXSHELL.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\@HOME\TIOGA\BIN\TGCMD.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\INTEL\INTEL PSNCU\CPUNUMBER.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
C:\PROGRAM FILES\NETWORK ICE\BLACKICE\BLACKICE.EXE
C:\PROGRAM FILES\INTUIT\QUICKBOOKS PRO 2\COMPONENTS\QBAGENT\QBDAGENT2001.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\Monwow.exe
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\HIJACK THIS FOLDER\HIJACK THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.f514.mail.yahoo.com/ym/login?.rand=4pds53067jd93
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/ymsgr/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F1 - win.ini: run=hpfsched
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Excite Platform] C:\PROGRA~1\EXCITE\PLATFORM\ExLaunch.exe
O4 - HKLM\..\Run: [ATTRedUpate] C:\PROGRAM FILES\COMMON FILES\AT&T\REDCON\PROGRAMS\AutoUpdate.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MSWheel] C:\WINDOWS\SYSTEM\mswheel.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TgAddServer] "C:\@Home\tioga\bin\tgfix" /fds "http://www/download/tioga"
O4 - HKLM\..\Run: [Tgcmd] "C:\@Home\tioga\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\qvugiw.exe
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton SystemWorks\Norton Utilities\Nprotect.exe
O4 - HKLM\..\RunServices: [CSINJECT.EXE] C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinject.exe
O4 - HKLM\..\RunServices: [winmodem] WINMODEM.101\wmexe.exe
O4 - HKLM\..\RunServices: [Encompass_ENCMONTR] C:\Program Files\Encompass\ENCMONTR.EXE
O4 - HKLM\..\RunServices: [LoadBlackD] C:\Program Files\Network ICE\BlackICE\blackd.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IntelProcNumUtility] "C:\Program Files\Intel\Intel PSNCU\CpuNumber.exe" /nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {DA9935BA-22F7-44ee-BD12-BD8B87700BEA}
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Event Reminder.lnk = C:\PMG4\PMREMIND.EXE
O4 - Startup: BlackICE Utility.lnk = C:\Program Files\Network ICE\BlackICE\blackice.exe
O4 - Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro 2\Components\QBAgent\qbdagent2001.exe
O4 - Startup: fkgiuh.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\COMPANION\MODULES\MESSMOD2\V4\YHEXBMES.DLL
O9 - Extra button: (no name) - {24E80680-B284-11D4-9FAA-00E029572CC5} - (no file) (HKCU)
O12 - Plugin for .lio: c:\PROGRA~1\INTERN~1\PLUGINS\NPMAD32L.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {8433A16D-1B78-11D4-8006-00D0B725EB0B} (Yahoo! FinanceVision (History)) - http://dl1.yahoo.com/dl/fv/fv.cab
O16 - DPF: {AEAD8593-667F-11D3-82FA-005004185BB3} (Servicesoft VoiceControl) - http://12.18.140.235/java/nm.cab
O16 - DPF: {1FA643B0-F90E-11D3-BA0B-00C04F384A92} (HomeTsrCtrl Class) - http://image.excite.com/sputnik/dynacat_up…ationchange.dll
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab
O16 - DPF: {47F591A2-8783-11D2-8343-00A0C945A819} (RFXPlayer Class) - http://download.richfx.com/player/mediaver…st/twophase.cab
O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4010/ftp…21/cpbrkpie.cab
O16 - DPF: {B33CCD56-0909-42C9-8A88-8976F66B8BF2} (AOL YGP Picture Finder Tool) - http://pak01.pictures.aol.com/ygp/aol/plug…der.8.0.3.0.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} (AOL Downloader Plugin) - http://pak02.pictures.aol.com/ygp/aol/plug…oad.9.0.0.2.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup…p1/imloader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://nada.webex.com/client/latest/webex/ieatgpc.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://69.95.9.175/activex/AxisCamControl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
Narrator is still hanging in there for some reason. Click here to download eScan's mwav application. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.
Log file from eScan virus scan: File C:\WINDOWS\QVUGIW.EXE infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\QVUGIW.EXE infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\xluazh.exe infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\qvugiw.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Start Menu\Programs\StartUp\fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\gwukap.dat infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\appsetup.exe infected by "Trojan-Downloader.Win32.Small.aco" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sipnoe.dll infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\eZinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Cxtpls_loader.exe infected by "not-a-virus:AdWare.Apropos.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\installer.exe infected by "Trojan-Dropper.Win32.Small.kz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\iluqyc.dll infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\NBTBIOS.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\mqexdlm.srg infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\javexulm.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\msbe.dll infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\Aaitrap.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exdl0.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exdl1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exul1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\dosync.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\docore.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\akupd.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\backups\backup-20050131-183034-918-fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~apropos0\ph.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~apropos0\pm.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\8LURK1YF\loader2[1].ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\WINDOWS\OPTIONS\CABS\OLS\AT&T\ATTKIT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\SYSTEM\NBTBIOS.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\mqexdlm.srg infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\javexulm.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\msbe.dll infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\Aaitrap.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exdl0.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exdl1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\exul1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\dosync.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\docore.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\akupd.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\backups\backup-20050131-183034-918-fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~apropos0\ph.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~apropos0\pm.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\Process.exe tagged as not-a-virus:RiskWare.Tool.Processor.20. No Action Taken. File C:\WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Start Menu\Programs\StartUp\fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\loader2.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\8LURK1YF\loader2[1].ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\WINDOWS\gwukap.dat infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\appsetup.exe infected by "Trojan-Downloader.Win32.Small.aco" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sipnoe.dll infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\eZinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Cxtpls_loader.exe infected by "not-a-virus:AdWare.Apropos.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\installer.exe infected by "Trojan-Dropper.Win32.Small.kz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\iluqyc.dll infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\Program Files\Encompass\iecustomize.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Encompass\pager-ie.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Online Services\AT&T\ATTSETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\hbinst\Hbinst.exe infected by "not-a-virus:AdWare.ToolBar.Hotbar.c" Virus. Action Taken: No Action Taken. File C:\Program Files\Hijack This\backups\backup-20050131-180346-269-fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\Program Files\eZula\CHCON.dll infected by "not-a-virus:AdWare.EZula.ae" Virus. Action Taken: No Action Taken. File C:\Program Files\Web Offer\CHPON.dll infected by "not-a-virus:AdWare.EZula.ae" Virus. Action Taken: No Action Taken. File C:\!Submit\USICOWS.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\EIUMFILE.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PJTORERC.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\CBET16.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\WRWIZDLL.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DACPROP.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\NA3TWEAK.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\WSW32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\JBSD400.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\MGSIP32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\TPUMBVW.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ONEPRO32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DEBAND.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\MZXML3.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\OPBC32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\EKSEC32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LIAVI70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mhuni11.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\OBECLI32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\VDR.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LJWPG70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\SDTUPWBV.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\waadmod.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\wvv8dmoe.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PNTORERC.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ONEXL32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PNDLIB32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\VYAME.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\hxsetup.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LXWPG70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DHIMAN32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LR32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ipetres.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\TJOLHELP.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\CRICONFG.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mMpi32.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\SOROBJ.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\sbrrun.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mVpi32x.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\hnrm.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\co3230mt.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\oybctrac.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mldamg9x.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\n20050308.exe infected by "not-a-virus:AdWare.EZula.ah" Virus. Action Taken: No Action Taken. File C:\!Submit\lzelgd.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\!Submit\AutoUpdate.exe infected by "Trojan-Downloader.Win32.Apropo.g" Virus. Action Taken: No Action Taken. File C:\!Submit\logbvm60.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\!Submit\gwukap.dat infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\sipnoe.dll infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\xluazh.exe infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\!Submit\iluqyc.dll infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken.
Start Killbox, copy and paste each of the following lines into the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:

C:\Program Files\eZula\CHCON.dll
C:\Program Files\hbinst\Hbinst.exe
C:\Program Files\Web Offer\CHPON.dll
C:\WINDOWS\appsetup.exe
C:\WINDOWS\Cxtpls_loader.exe
C:\WINDOWS\Downloaded Program Files\loader2.ocx
C:\WINDOWS\eZinstall.exe
C:\WINDOWS\gwukap.dat
C:\WINDOWS\iluqyc.dll
C:\WINDOWS\installer.exe
C:\WINDOWS\QVUGIW.EXE
C:\WINDOWS\sipnoe.dll
C:\WINDOWS\Start Menu\Programs\StartUp\fkgiuh.exe
C:\WINDOWS\SYSTEM\Aaitrap.dll
C:\WINDOWS\SYSTEM\akupd.dll
C:\WINDOWS\SYSTEM\angelex.exe
C:\WINDOWS\SYSTEM\docore.dll
C:\WINDOWS\SYSTEM\dosync.dll
C:\WINDOWS\SYSTEM\exdl0.exe
C:\WINDOWS\SYSTEM\exdl1.exe
C:\WINDOWS\SYSTEM\exul1.exe
C:\WINDOWS\SYSTEM\javexulm.vxd
C:\WINDOWS\SYSTEM\mqexdlm.srg
C:\WINDOWS\SYSTEM\msbe.dll
C:\WINDOWS\SYSTEM\NBTBIOS.DLL
C:\WINDOWS\SYSTEM\netut80ex.vxd
C:\WINDOWS\TEMP\backups\backup-20050131-183034-918-fkgiuh.exe
C:\WINDOWS\TEMP\~apropos0\ph.exe
C:\WINDOWS\TEMP\~apropos0\pm.exe
C:\WINDOWS\Temporary Internet Files\Content.IE5\8LURK1YF\loader2[1].ocx
C:\WINDOWS\woinstall.exe
C:\WINDOWS\xluazh.exe

For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

Reboot if it doesn't do so automatically and post a new mwav scan.
Results of latest mwav scan: File C:\WINDOWS\OPTIONS\CABS\OLS\AT&T\ATTKIT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\SYSTEM32\Process.exe tagged as not-a-virus:RiskWare.Tool.Processor.20. No Action Taken. File C:\WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Program Files\Encompass\iecustomize.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Encompass\pager-ie.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Online Services\AT&T\ATTSETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Hijack This\backups\backup-20050131-180346-269-fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\USICOWS.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\EIUMFILE.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PJTORERC.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\CBET16.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\WRWIZDLL.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DACPROP.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\NA3TWEAK.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\WSW32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\JBSD400.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\MGSIP32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\TPUMBVW.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ONEPRO32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DEBAND.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\MZXML3.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\OPBC32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\EKSEC32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LIAVI70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mhuni11.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\OBECLI32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\VDR.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LJWPG70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\SDTUPWBV.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\waadmod.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\wvv8dmoe.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PNTORERC.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ONEXL32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\PNDLIB32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\VYAME.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\hxsetup.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LXWPG70N.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\DHIMAN32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\LR32.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\ipetres.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\TJOLHELP.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\CRICONFG.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mMpi32.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\SOROBJ.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\sbrrun.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mVpi32x.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\hnrm.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\co3230mt.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\oybctrac.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\mldamg9x.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\n20050308.exe infected by "not-a-virus:AdWare.EZula.ah" Virus. Action Taken: No Action Taken. File C:\!Submit\lzelgd.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\!Submit\AutoUpdate.exe infected by "Trojan-Downloader.Win32.Apropo.g" Virus. Action Taken: No Action Taken. File C:\!Submit\logbvm60.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\!Submit\CHCON.dll infected by "not-a-virus:AdWare.EZula.ae" Virus. Action Taken: No Action Taken. File C:\!Submit\gwukap.dat infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\sipnoe.dll infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\xluazh.exe infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\!Submit\iluqyc.dll infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: No Action Taken. File C:\!Submit\Hbinst.exe infected by "not-a-virus:AdWare.ToolBar.Hotbar.c" Virus. Action Taken: No Action Taken. File C:\!Submit\CHPON.dll infected by "not-a-virus:AdWare.EZula.ae" Virus. Action Taken: No Action Taken. File C:\!Submit\appsetup.exe infected by "Trojan-Downloader.Win32.Small.aco" Virus. Action Taken: No Action Taken. File C:\!Submit\Cxtpls_loader.exe infected by "not-a-virus:AdWare.Apropos.b" Virus. Action Taken: No Action Taken. File C:\!Submit\loader2.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\!Submit\eZinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\!Submit\installer.exe infected by "Trojan-Dropper.Win32.Small.kz" Virus. Action Taken: No Action Taken. File C:\!Submit\qvugiw.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\Aaitrap.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\akupd.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\!Submit\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\docore.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\!Submit\dosync.dll infected by "not-a-virus:AdWare.Couponage.a" Virus. Action Taken: No Action Taken. File C:\!Submit\exdl0.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\exdl1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\exul1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\javexulm.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\mqexdlm.srg infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\msbe.dll infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\!Submit\NBTBIOS.DLL infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\!Submit\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\!Submit\backup-20050131-183034-918-fkgiuh.exe infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\!Submit\ph.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\!Submit\pm.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\!Submit\loader2[1].ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\!Submit\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI