This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop Up Attacks On Mine, Too

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I have read the other threads hoping I would not have to trouble you. I have run Ad-Aware, Spybot, and a few others more than half a dozen times, and still no salvation. The pop ups just keep coming, even when I don't use IE. They come in waves - I'll be free for 20 minutes then have 20 minutes of killing IE.

I also just got the prevention tools I've seen mentioned, plus Firefox, and Sygate, so hopefully this will never happen again. Thanks so much in advance. You guys are amazing and beyong generous.

Kati

Logfile of HijackThis v1.99.1
Scan saved at 12:03:59 PM, on 3/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system\mraxmndbe.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://staging2/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://staging2/
R3 - Default URLSearchHook is missing
O2 - BHO: SDWin32 Class - {04B9045D-0E27-4EA4-BB95-047DA4CD2B21} - C:\WINDOWS\system32\ykoeg.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSW.cIExplorer - {4B57B77A-B130-4EB8-8CFB-42B880F6D311} - C:\Documents and Settings\All Users\Application Data\msw\MSW.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CAUN Object - {59F12660-2B92-4554-98F9-87295AD8A0CE} - C:\WINDOWS\system32\AUNBHO.dll (file missing)
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll (file missing)
O2 - BHO: SDWin32 Class - {FC3DE1D9-FD0B-402E-8125-198E5B905800} - C:\WINDOWS\system32\pltzq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [rpskwfs] c:\windows\system32\rpskwfs.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Hi Kati, Welcome to TomCoyote forum. You have some real nasties on your computer. I will see what I can do to help you. Please do your best to follow directions, ask questions and give me information you think I may need.

1) First I see a Sygate\SPF, but I do not see a Antivirus program? This may well be the reason you are infected. The following link will take you to where you can download AVG which is a very good free antivirus program. Be carefull to make sure you click on only FREE and not trial version, etc. Once onboard, update and run it right away, it may find and kill some of the bad stuff. http://free.grisoft.com/freeweb.php

2) I wish to make sure there is no CoolWebSearch on your computer, please download the CWShredder, save it to your desktop, open it then update. Then click on FIX not scan, allow it to run and remove anything it locates. Let me know if it finds andthing.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

3) I see you have Spybot, I still want you to review the information in the tutorials and run it again according to those instructions. Make sure you have the newest version.
We need to run our big guns for cleaning out malware. Ad-aware and Spybot can get the areas we can't reach with the HJT tool. I am going to give you links to tutorials and it is important that you take the time to review the information, then to download, update, configure exactly as in the tutorials and remove what is suggested in the tutorials. Make notes of anything these two programs can't remove, the exact name and location of the item. Run Spybot first, if you receive any DSO Exploit notifications, ignore them and please do not activate TeaTimer at this time, once you are clean you may activate it. If Spybot removes anything reboot before running Ad-aware SE Personal.
Spybot:
http://www.bleepingcomputer.com/forums/tutorial43.html
Ad-aware:
http://www.bleepingcomputer.com/forums/tutorial48.html

4) You have installed and run AVG by Grisoft by now, I want you to also run this free online scan and have it fix or clean anything it locates. If it finds something it can not fix, write down the exact name and location of the item.
http://www.pandasoftware.com/activescan/co…n_principal.htm

Once this is done empty the recycle bin and restart the computer. Use ADD REPLY, stay in the same thread. Post a new log along with any information you have for me along with your comments. We will have more to do.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Hi pskelley,

Thank you very much for your help. I’m sorry for the delay – I have been pulled away all day, and most of the scans took way longer than I thought they would. AVG was over an hour, and so was Panda. Here is what I have done, as well as my newest log. I did all your instructions to the letter:

I got AVG, updated it, and ran it. It took over an hour, found one virus, and got rid of it. It did not tell me the virus name.

I had tried CWShredder already (the latest version), so I checked for updates again and ran it one more time. Nothing.

Just to make sure I did it perfectly, I uninstalled Spybot and downloaded it again. I set all the settings like the tutorial instructed. It came up with two things - mysearch, which it killed, and callinghome.biz. I have tried a few times to remove it, including restarting and running Spybot again, but no luck. It is still there. I couldn't figure out how to determine its location in Spybot, so I tried to search for it. It only came up in Spybot's recovery files.

I followed the tutorial for Ad-Aware and it found nothing serious. It had a few negligibles, but they were just document histories.

Panda found some viruses. It said it removed all of them.

I then emptied the recycle bin, restarted, and pulled the new log below.

I have to go for a while, and I will be back to follow your next round of instructions asap, but it might not be until tomorrow. Thank you again for your help. I appreciate it very much.

Best regards,
Kati

Logfile of HijackThis v1.99.1
Scan saved at 5:59:33 PM, on 3/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://staging2/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://staging2/
R3 - Default URLSearchHook is missing
O2 - BHO: SDWin32 Class - {04B9045D-0E27-4EA4-BB95-047DA4CD2B21} - C:\WINDOWS\system32\ykoeg.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MSW.cIExplorer - {4B57B77A-B130-4EB8-8CFB-42B880F6D311} - C:\Documents and Settings\All Users\Application Data\msw\MSW.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CAUN Object - {59F12660-2B92-4554-98F9-87295AD8A0CE} - C:\WINDOWS\system32\AUNBHO.dll (file missing)
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll (file missing)
O2 - BHO: SDWin32 Class - {FC3DE1D9-FD0B-402E-8125-198E5B905800} - C:\WINDOWS\system32\pltzq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [rpskwfs] c:\windows\system32\rpskwfs.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Hi Kati, You go girl, you did good. We still have work to do but that was a good start.

I couldn't figure out how to determine its location in Spybot, so I tried to search for it. It only came up in Spybot's recovery files.

I believe it is in the quarantine area of Spybot, both Ad-aware and Spybot place the stuff they remove in quarantine in case of a mistake (been using both products for six years and I have never had to bring anything back from quarantine these products said was bad) Just make sure I show you how to dump thoses files if you don't locate it first.

I have to go for a while, and I will be back to follow your next round of instructions asap, but it might not be until tomorrow.

This is no problem, I have enough logs waiting to last another lifetime. :blink:

OK Katie, If you look below you will see the bad stuff that got on your computer, it is nasty too. I believe we have a much better chance of cleaning out this junk if we use Safe Mode when we kill it so nothing is running to stop our fix. Make sure you allow plenty of time to do this, do not rush. In case you do not know how to enter Safe Mode (diagnostic mode) I will post two links to help, while they both say about the same thing one view might help more than another.
I also see HJT is placed properly and it may help if you place a shortcut on the Desktop to keep from going to C:\ when you need to run HJT. Go there and open the folder and point at HJT and RIGHT click then click "Send to" then Desktop (Create Shortcut) Now HJT can be started from the Shortcut on your Desktop.

So you won't have to do this in while in Safe Mode and malware writers like to hide there junk, follow the instructions in the following link to enable hidden files for this operating system. You may wish to reverse this once you are clean if you are concerned anyone will get in these hidden windows files?
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

http://www.bleepingcomputer.com/forums/tutorial61.html
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Once you are in the Safe Mode, open HJT and click SCAN check the box in front of each of these lines, do not miss any.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://staging2/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://staging2/
R3 - Default URLSearchHook is missing
O2 - BHO: SDWin32 Class - {04B9045D-0E27-4EA4-BB95-047DA4CD2B21} - C:\WINDOWS\system32\ykoeg.dll (file missing)
O2 - BHO: MSW.cIExplorer - {4B57B77A-B130-4EB8-8CFB-42B880F6D311} - C:\Documents and Settings\All Users\Application Data\msw\MSW.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CAUN Object - {59F12660-2B92-4554-98F9-87295AD8A0CE} - C:\WINDOWS\system32\AUNBHO.dll (file missing)
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll (file missing)
O2 - BHO: SDWin32 Class - {FC3DE1D9-FD0B-402E-8125-198E5B905800} - C:\WINDOWS\system32\pltzq.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [rpskwfs] c:\windows\system32\rpskwfs.exe
O4 - HKLM\..\Run: [farmmext] C:\WINDOWS\farmmext.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)

Once they are all checked then click on "Fix Checked" Now RIGHT click on Start then click on Explore. Locate and delete these files:

C:\WINDOWS\farmmext.exe >>> file

c:\windows\system32\rpskwfs.exe >>> file

Empty the recycle bin and restart the computer back to Normal mode. Post a new log along with your comments…anything you believe I should know. I will know more when I see that log.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Hi pskelley,

I restarted in safe mode with hidden files visible. I clicked fix for everything you listed in HJT, and I did not miss any.

Then I went to explorer and located the farmmext file in c:\windows and deleted it. I even got a little frisky and deleted the farmmext config file next to it (I live on the edge).

The other file you mentioned, c:\windows\system32\rpskwfs.exe, was not there. I searched and found this: c:\windows\prefetch\rpskwfs.exe-07988544.pf but didn't detete it. I wanted to check with you first. I have no clue what prefetch is.

I decided to search for farmmext, too. It looked like Spybot was saving copies of the application? They were in the zipped recovery files in Spybot, and yes, it said file type = application. Strangely, the zipped files all ended in callinghome.biz, and that is the file I couldn't find before. I can send you a screen shot of what it says, if you want.

AND it listed c:\windows\prefetch\farmmext.exe-19A43853.pf in the search results, too. Should I delete everything I can find with both of those file names in them? Or maybe the entire prefetch folder? I wanted to check with you before doing anything extra exciting like that.

Be proud - I am installing everything you told me about for this one on both of my other computers BEFORE I do something to screw them up, too. It’s finals writing weekend here, and I am in my 2nd to last class in grad school. I'm off to work on the non-mangled computer to write an award winning paper on Kentucky Fried Chicken (no joke, that’s the topic). Thanks again. I will check in later when I resurface.

Here is my log now…

Logfile of HijackThis v1.99.1
Scan saved at 4:08:42 PM, on 3/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwa…ash/swflash.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Hi Kati, Congratulations :) Your log is clean!!! :thumbup:

I even got a little frisky and deleted the farmmext config file next to it (I live on the edge).

I can see that…HJT makes backups for you in the event of an issue, but if you remove a wrong file it goes to the recycle bin (unless you have it set to remove without a stop at the bin, which you should not) and I must point out that when I am removing bad stuff I always empty the bin last thing. :unsure:

I searched and found this: c:\windows\prefetch\rpskwfs.exe-07988544.pf but didn't detete it. I wanted to check with you first. I have no clue what prefetch is.

Yep, that needs to go, in fact we will clean out the Prefetch Folder, but first here is the information you will need to feel good about doing do:
http://www.pcmag.com/article2/0,1759,1683520,00.asp
http://techrepublic.com.com/5100-6270-5165773.html

While you are in there, I suggest you take the time to delete all Temp items also. When you do this, do not delete the folder, just the stuff in it. Here is information for you:
http://www.personal-computer-tutor.com/deletingtempfiles.htm
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also Temporary Internet Files: IE > Tools > Internet Options > General Tab > Delete Cookies > OK > Delete Files (make sure to check the box to delete all offline content) then OK.

I just installed this small utility after years of backing up the weak cleanmgr built into windows with a program called CleanDisk2002. I loved the way this utility cleaned up junk I was not getting: http://www.ccleaner.com/
Try it out, if you don't like it…uninstall it. I believe you will though.

They were in the zipped recovery files in Spybot

I still need to look at this, but I think that is quarantine in Spybot…where you can "recover" something if it is removed by mistake. I would clean out all quarantine areas in all programs. I will even purge System Restore files by turning them off and on as this is the only way to clean anything bad out of those protected files. Often something bad gets in there and is forgotten until a reason to restore come up, and BANG, they are infected again…lol
I can also say that this junk like farmmext gets all over the registry and often a regedit is the only way to get it all. You may search and delete any instance of it you locates, the same with rpskwfs.exe. One thing I did not mention, because temp stuff and Prefetch files are often in use, I would suggest you clean in Safe Mode so you can get it all. Windows will put back anything removed that is needed and the first boot will be a little slow as Prefetch repopulates the files needed to boot quickly.

Be proud - I am installing everything you told me about for this one on both of my other computers BEFORE I do something to screw them up

Kati, I will suggest you install them a little more slowly. Do them from top down and wait a few days to see if anything unusual happens. Some software just will not run on some computers and if you install it all at once, you will not know what the problem software is. I run them all and most folks I know whos computers I keep running do also, but one girl I know just cannot run SpywareGuard on her Gateway. Thanks.

Your log is clean, you should be proud of yourself. I would still complete the steps above and when you get to the last one, follow these instructions to purge System Restore:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Since you have a clean log, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

You seen to enjoy killing this bad stuff, if you would like to learn more and perhaps even help others, free training opportunites are available. Just let me know or PM any member of the team.

Thanks…Phil Skelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI