This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is my first post. I've read a number of threads and think I'm close to restoring my computer, but want to be sure.

When I started with my friends computer, there were no icons or start menu. I could open the task manager though. I tried to repair the operating system (XP Home) with the CD and it worked temporarily. I booted into safe mode and ran Norton Antivirus, Spybot and Ad-aware, making sure the latest definitions were downloaded first. I then made sure all the security fixes and patches were applied from Windows Update. The properties screen from My Computer says that it is still on SP1, but when I went to install SP2, it said it ws already loaded. The Windows Update isn't working anymore and all the options under Automatic Updates are greyed out. I may have disallowed a needed process in ZoneAlarm, but erred on the side of caution.

I installed Counterspy and re-ran everything again. It seems to be working for now, but I'm not convinced all the spyware/malware has been removed. I left my USB jumpdrive attached so I could copy the log file and send it from another computer. Please review the following hjt file and advise.

Thanks


Logfile of HijackThis v1.99.1
Scan saved at 7:51:29 PM, on 4/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\svhost.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
c:\windows\system32\vkuomc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\video2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDTServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\WINDOWS\System32\wuauclt.exe
C:\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=C:\WINDOWS\system32\svhost.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: WinSurferHelper - {C52CBAEC-D969-4635-9F50-426CC15CE463} - C:\WINDOWS\System32\4162200f.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Service] C:\WINDOWS\system32\video2.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [eEPMR4Oh] C:\WINDOWS\jgfcfvq.exe
O4 - HKLM\..\Run: [vggodz] c:\windows\system32\vggodz.exe
O4 - HKLM\..\Run: [hwxqfol] C:\WINDOWS\hwxqfol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDTServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [roxona] c:\windows\system32\vkuomc.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\video2.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fucked.biz
O15 - Trusted Zone: *.traffic2cash.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094327858343
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {86A63E0C-CCF7-11D4-90CE-00C02627FC4F} (HTMLXpress.MainControl) - http://my.electradigital.com/HTMLXPress.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O20 - Winlogon Notify: msguard - eplrr0.dll (file missing)
O20 - Winlogon Notify: wsrv - wsrv.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Welcome to the forum.

You are still infected

These two programs have worked well on this nasty infection, please run them.

Download ewido security suite from here… http://www.ewido.net/en/download/

Update it’s database from here.. http://www.ewido.net/en/download/updates/
Run a scan and let it clean the PC.

Reboot..
I would also like you to download and run this run this scan:

http://www.simplysup.com/tremover/details.html


Reboot and post a fresh HJT log and we'll clean up the rest, MrC
Thanks. It took a while for the ewido scan to run, so I let it run overnight. There were still a few things that popped up this morning, but I can tell we're getting close. I also ran the trojan remover you suggested.

I know I still need to upgrade to SP2, but I wanted to post the results and let you take a look at them before I did anything else. It's finally letting me go to the windows update website and download SP2, but the automatic update settings are all still grayed out. I'm hoping that will be taken care of after SP2 is installed.

Thanks,

Bryan


Logfile of HijackThis v1.99.1
Scan saved at 7:33:45 AM, on 4/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\iinstall.exe
C:\hjt\HijackThis.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServAlert.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nshE.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: WinSurferHelper - {C52CBAEC-D969-4635-9F50-426CC15CE463} - C:\WINDOWS\System32\4162200f.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [eEPMR4Oh] C:\WINDOWS\jgfcfvq.exe
O4 - HKLM\..\Run: [hwxqfol] C:\WINDOWS\hwxqfol.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [pc_flashbang] C:\Program Files\PCFlashBang\PCFlashBang.exe -sys
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [Disspy] C:\Program Files\Disspy\Disspy.exe - silent
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\System32\video2.exe
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - WWW. Prefix: http://
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fucked.biz
O15 - Trusted Zone: *.traffic2cash.biz
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094327858343
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://static.topconverting.com/activex/website.ocx
O16 - DPF: {86A63E0C-CCF7-11D4-90CE-00C02627FC4F} (HTMLXpress.MainControl) - http://my.electradigital.com/HTMLXPress.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: msguard - eplrr0.dll (file missing)
O20 - Winlogon Notify: wsrv - wsrv.dll (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE


I also included the ewido report.


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 6:52:05 AM, 4/29/2005
+ Report-Checksum: 28ECAED6

+ Date of database: 4/28/2005
+ Version of scan engine: v3.0

+ Duration: 600 min
+ Scanned Files: 139592
+ Speed: 3.87 Files/Second
+ Infected files: 103
+ Removed files: 103
+ Files put in quarantine: 103
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\127062.exe -> Not-A-Virus.PornWare.Downloader.Tibsystems -> Cleaned with backup
C:\Documents and Settings\Administrator\efefe.exe -> Spyware.ISearch.d -> Cleaned with backup
C:\Documents and Settings\Administrator\efvefefe.exe -> TrojanDownloader.IstBar.it -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\B141910364\build2.exe -> Spyware.Isearch -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\bb.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\Del64.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\DrTemp\Pynix.dll -> Spyware.DlMax.a -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\powerscan.exe -> Spyware.PowerScan.d -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CDAF8HEZ\istrecover[1].exe -> TrojanDownloader.IstBar.ij -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CDAF8HEZ\sfbho13[1].dll -> Spyware.SideFind -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\nem220[1].dll -> TrojanDownloader.Dyfuca -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\sidefind13[1].dll -> Spyware.SideFind -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\sidefind[1].exe -> Spyware.SideFind -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\ysb[1].dll -> Spyware.YourSiteBar.c -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JUSY0Q30\powerscan[1].exe -> Spyware.PowerScan.d -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LN9HFEMM\bb[1].exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LN9HFEMM\ncase_new[1].exe -> Spyware.180solutions -> Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LN9HFEMM\polall1p[1].exe -> Trojan.Agent.ay -> Cleaned with backup
C:\Documents and Settings\Administrator\sefer.exe -> Spyware.Agent.bn -> Cleaned with backup
C:\Documents and Settings\Administrator\tool.exe -> Spyware.HotSearchBar.e -> Cleaned with backup
C:\Documents and Settings\Administrator\video2.exe -> TrojanDownloader.Small.my -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@21733306[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@45813911[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@47883303[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@48487900[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@7153726[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@79074435[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@86553617[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@87971403[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@92267575[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@al[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed]-traffic[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@gostats[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@link[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@LPtimex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@netpoll[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@search123[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason 2@tracker[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\Cookies\jason [removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Jason 2\efvefefe.exe -> TrojanDownloader.IstBar.it -> Cleaned with backup
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\CP2JSL2B\127062[1].exe -> Not-A-Virus.PornWare.Downloader.Tibsystems -> Cleaned with backup
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\EPFW9ONM\thnall1p[1].exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\QDK3Y9A5\otype[1].exe -> TrojanDropper.Inor.y -> Cleaned with backup
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\QDK3Y9A5\otype[3].exe -> TrojanDropper.Inor.y -> Cleaned with backup
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\S9U3SPEN\mtrslib2[1].js -> TrojanDownloader.Small -> Cleaned with backup
C:\Documents and Settings\Jason 2\tool.exe -> Spyware.HotSearchBar.e -> Cleaned with backup
C:\Documents and Settings\Jason 2\video2.exe -> TrojanDownloader.Small.my -> Cleaned with backup
C:\Program Files\SBC Self Support Tool\bin\closeAll.exe -> Trojan.Autoit.d -> Cleaned with backup
C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\2565E94A-BF28-46D7-81A8-77E088\E64C4A5F-DAE0-42BB-93B5-D82F3F -> Spyware.Beginto.c -> Cleaned with backup
C:\Program Files\WebSiteViewer\127062.exe -> Not-A-Virus.PornWare.Downloader.Tibsystems -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000001.TXT -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000094.dll -> Spyware.WebSearch.d -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000105.EXE -> Spyware.WebRebates.a -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000106.EXE -> Spyware.TopRebates.a -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000172.dll -> Spyware.TotalVelocity.o -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000173.dll -> Spyware.TotalVelocity.o -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000174.exe -> Spyware.TotalVelocity.o -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000186.DLL -> Spyware.ClearSearch.j -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000297.OCX -> Spyware.DelphinMediaViewer.a -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000299.dll -> Spyware.DelphinMediaViewer.a -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000389.dll -> TrojanDownloader.Agent.bf -> Cleaned with backup
C:\RECYCLER\NPROTECT\00000396.exe -> Spyware.BargainBuddy.i -> Cleaned with backup
C:\WINDOWS\ATLASSUI.exe -> Spyware.Hijacker.Generic -> Cleaned with backup
C:\WINDOWS\Bolger.dll -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll -> Spyware.Gator.1019 -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll -> Spyware.Gator.1019 -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll -> Spyware.Gator.1019 -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll -> Spyware.Gator.1019 -> Cleaned with backup
C:\WINDOWS\gdkqw.exe -> TrojanDownloader.IstBar.ij -> Cleaned with backup
C:\WINDOWS\Nail.exe -> Trojan.Nail -> Cleaned with backup
C:\WINDOWS\njsjykzpetj.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\svcproc.exe -> Trojan.Stervis.b -> Cleaned with backup
C:\WINDOWS\system32\41621e4b.dll -> Spyware.BHO.k -> Cleaned with backup
C:\WINDOWS\system32\Bewufa.exe -> Trojan.Popmon.a -> Cleaned with backup
C:\WINDOWS\system32\dload.exe -> TrojanDownloader.Small.my -> Cleaned with backup
C:\WINDOWS\system32\HookPopup.dll -> Spyware.DealHelper.ab -> Cleaned with backup
C:\WINDOWS\system32\in10b6.dlltmp -> Trojan.Revop.c -> Cleaned with backup
C:\WINDOWS\system32\lifczhx.exe -> Trojan.Agent.cp -> Cleaned with backup
C:\WINDOWS\system32\siae3123.exe -> TrojanDropper.Small.gt -> Cleaned with backup
C:\WINDOWS\system32\thin-94-1-x-x.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__DrPMon.dll -> Trojan.Agent.db -> Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__vggodz.exe -> Trojan.Agent.ay -> Cleaned with backup
C:\WINDOWS\ufhcap.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent.b -> Cleaned with backup


::Report End
OK, unless you know what these are we're going to uninstall/delete them:

PCFlashBang
Disspy

O4 - HKCU\..\Run: [pc_flashbang] C:\Program Files\PCFlashBang\PCFlashBang.exe -sys
O4 - HKCU\..\Run: [Disspy] C:\Program Files\Disspy\Disspy.exe - silent


Look in you control panels add/remove programs and uninstall PCFlashBang and
Disspy.

Also look for any other programs you didn't install or don't recognize and uninstall them - if you're not sure please ask first.


HowToShowHiddenFiles - <—enable this

Download and unzip the KillBox to a folder - we'll use it later.



Press Control-Alt-Del to enter the Task Manager.
Click on the Processes tab and end the following processes if listed:

iinstall.exe

Exit the Task Manager when finished

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nshE.dll (file missing)
O2 - BHO: WinSurferHelper - {C52CBAEC-D969-4635-9F50-426CC15CE463} - C:\WINDOWS\System32\4162200f.dll
O4 - HKLM\..\Run: [eEPMR4Oh] C:\WINDOWS\jgfcfvq.exe
O4 - HKLM\..\Run: [hwxqfol] C:\WINDOWS\hwxqfol.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\System32\video2.exe
O4 - HKCU\..\Run: [pc_flashbang] C:\Program Files\PCFlashBang\PCFlashBang.exe -sys
O4 - HKCU\..\Run: [Disspy] C:\Program Files\Disspy\Disspy.exe - silent

O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.admin2cash.biz
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.bettersearch.biz
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.private-dialer.biz
O15 - Trusted Zone: *.private-iframe.biz
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.sp2fucked.biz
O15 - Trusted Zone: *.traffic2cash.biz
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://static.topconverting.com/activex/website.ocx
O20 - Winlogon Notify: msguard - eplrr0.dll (file missing)
O20 - Winlogon Notify: wsrv - wsrv.dll (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)

Click on Fix Checked and exit HijackThis.

Now open up the KillBox and copy and paste each one of these in and hit delete, if the file exists, it will appear in blue under the window, if not move on to the next file.

C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\iinstall.exe
C:\WINDOWS\System32\4162200f.dll
C:\WINDOWS\System32\nshE.dll
C:\WINDOWS\svcproc.exe
C:\WINDOWS\hwxqfol.exe
C:\WINDOWS\jgfcfvq.exe
C:\WINDOWS\Bolger.dll
C:\WINDOWS\System32\video2.exe

The KillBox has a 'delete on reboot' or 'replace on reboot' (use dummy), use them if needed.
When using delete on reboot or replace on reboot - you can add multiple files.

The KillBox creates a folder called "!submit" in C:\ , after we are done you can delete the folder.

Also delete these folders:

C:\Program Files\Disspy
C:\Program Files\PCFlashBang


Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Delete all files in these folders.(if they exist)
C:\documents and settings\(your name)\local settings\temp
C:\documents and settings\(anyone)\local settings\temp
C:\windows\temp
C:\Temp

Empty recycle bin.


Reboot and post a fresh HijackThis log and we'll take another look. MrC
Here's the latest logfile. Not sure if this is an issue or not, but CounterSpy keeps popping up messages that is has blocked the Internet Explorer security setting Safety Warning Level from being changed.



Logfile of HijackThis v1.99.1
Scan saved at 5:24:25 PM, on 4/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\System32\wuauclt.exe
C:\hjt\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServAlert.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - WWW. Prefix: http://
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094327858343
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {86A63E0C-CCF7-11D4-90CE-00C02627FC4F} (HTMLXpress.MainControl) - http://my.electradigital.com/HTMLXPress.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Just clean these two up….

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

O13 - WWW. Prefix: http://
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)

Click on Fix Checked and exit HijackThis.

Make sure this files is gone!
C:\WINDOWS\svcproc.exe


Reboot and post a fresh HijackThis log and use IE see if you still get that warning, MrC
It's still a bit sluggish on boot up. I'm also still getting the blocked Security Change notice. After the hjt scan, the following were picked up by CounterSpy and ZoneAlarm:

abetterinternet
poker.exe
begin2search broser plug-in

Thanks for your help, I made a contribution earlier today.

Bryan


Logfile of HijackThis v1.99.1
Scan saved at 6:26:34 PM, on 4/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\hjt\HijackThis.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServAlert.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServAlert.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nssD.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Owner"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094327858343
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {86A63E0C-CCF7-11D4-90CE-00C02627FC4F} (HTMLXpress.MainControl) - http://my.electradigital.com/HTMLXPress.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
OK, here's some new malware that has surfaced.

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINDOWS\System32\nssD.dll
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) <—this one keeps coming back, make sure you have no other programs running when you have HJT fix it - it after fixing it, it's still there - reboot into safe mode and fix it)

Click on Fix Checked and exit HijackThis.

Delete this file:


C:\WINDOWS\System32\nssD.dll


To uncover any other malware on the system, please do this:

Click here http://www.mwti.net/download/tools/mwav.exe to download mwavscan.
Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane.
Highlight it, CTRL C (to copy it) and paste it in your next reply.
It's going to take a while to scan and if you get a pop-up to buy the program, just X it out.

Thanks, MrC
I ran an Ad-aware and Spybot scan that apparently fixed a couple things, because the only item I could select and delete in the hjt scan was the svcproc.exe file. I'm going to run NAV again and remove the quarantined files in the meantime. Here are the results from the mwavscan you requested: File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "BetterInternet Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "BetterInternet Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "vendor Spyware/Adware" Virus. Action Taken: No Action Taken. File C:\WINDOWS\assest.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Celeb-Fakes[cf-10028,,].exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. File C:\WINDOWS\DHP2.dll infected by "not-a-virus:AdWare.DealHelper.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sasent.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sasetup.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msfdje.gif infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\svhost.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\thin-94-5-x-x.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\xdldr24.exe infected by "Trojan-Downloader.Win32.Small.fo" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\1.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\iinstall.exe infected by "Trojan-Downloader.Win32.IstBar.ir" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CDAF8HEZ\package_MARKETING27[1].exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\pynix[1].cab infected by "not-a-virus:AdWare.DlMax.a" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JUSY0Q30\optimize[1].exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LN9HFEMM\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer24.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS1.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temp\1.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temp\iinstall.exe infected by "Trojan-Downloader.Win32.IstBar.ir" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\0D89S56J\istdownload[1].exe infected by "Trojan-Downloader.Win32.IstBar.ir" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\0D89S56J\thin_bundlelite2[1].exe infected by "not-a-virus:AdWare.Sahat.m" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[2].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[3].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[4].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[5].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\AFI3IDYR\ysb_regular[1].cab infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\CP2JSL2B\thin_poker[1].exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\WR9F62ZP\ysb_prompt[1].php infected by "Trojan-Downloader.JS.IstBar.j" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\X0GBH9SD\rdgUS1742[1].exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Jason 2\tool.exe infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\Program Files\ewido\security suite\Quarantine\quaraFile69.ess infected by "Trojan-Dropper.VBS.Inor.y" Virus. Action Taken: No Action Taken. File C:\Program Files\ewido\security suite\Quarantine\quaraFile70.ess infected by "Trojan-Dropper.VBS.Inor.y" Virus. Action Taken: No Action Taken. The majority of the files found in the scan were in the NAV\Quarantine directory. To save space, I’m only including the first entry. File C:\Program Files\Norton AntiVirus\Quarantine\0000131F.dll infected by "Trojan-Downloader.Win32.Small.aai" Virus. Action Taken: No Action Taken. File C:\Program Files\Parsons\QuickVerse\QuickVerse\move.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\04FDA112-CD39-462B-858C-B809E5\731BA037-4F4E-4FF8-94F3-69F44E infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\B43BC775-A10C-4165-969C-94B6F7\A1B49F87-866E-4DBA-8899-64875C infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken. File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\DC6A3D0F-ED76-4FCA-ADD6-FE6A33\966811EB-FF67-4552-81E6-357D4C infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000089.exe infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000090.dll infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000149.exe infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000185.exe infected by "not-a-virus:AdWare.ClearSearch.j" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000314.EXE infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000325.dll infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\RECYCLER\NPROTECT\00000327.gif infected by "Trojan-Spy.Win32.Delf.dx" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274367.DLL infected by "not-a-virus:AdWare.ClearSearch.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274369.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274374.dll infected by "Trojan-Downloader.Win32.Briss.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274382.DLL infected by "not-a-virus:AdWare.ClearSearch.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274383.DLL infected by "not-a-virus:AdWare.ClearSearch.f" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274405.exe infected by "Trojan-Downloader.Win32.VB.cw" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274408.dll infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274409.dll infected by "not-a-virus:AdWare.Ipend" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274412.dll infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274431.exe infected by "Trojan-Spy.Win32.Agent.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274440.exe infected by "Trojan-Dropper.Win32.Agent.bc" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274441.exe infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274442.exe infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274534.exe infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274535.dll infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274536.dll infected by "not-a-virus:AdWare.WebSearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274540.exe infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274541.exe infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274542.exe infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274561.dll infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274562.dll infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274563.exe infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274564.exe infected by "Trojan-Dropper.Win32.Small.gj" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274568.exe infected by "not-a-virus:AdWare.ClearSearch.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274581.exe infected by "Trojan-Downloader.Win32.Agent.ct" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274587.ocx infected by "not-a-virus:AdWare.DelphinMediaViewer.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274593.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274595.dll infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274596.dll infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274601.exe infected by "not-a-virus:AdWare.BargainBuddy.i" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP104\A0007577.dll infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP104\A0007578.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP104\A0007607.exe infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP104\A0007612.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000004.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000011.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000012.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000014.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000041.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000049.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000135.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000136.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000150.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000167.exe infected by "not-a-virus:AdWare.PowerScan.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000168.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000171.exe infected by "not-a-virus:AdWare.DealHelper.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000172.dll infected by "not-a-virus:AdWare.DealHelper.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000173.exe infected by "not-a-virus:AdWare.DealHelper.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000189.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000191.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000195.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000198.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000206.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000208.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000245.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000248.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000249.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000616.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000749.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000760.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000762.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000763.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000811.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000835.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000837.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000838.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000846.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000858.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000859.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000862.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000872.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000896.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000898.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000911.new infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000917.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000919.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000932.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000934.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000935.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0000937.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001043.srg infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001044.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001061.dll infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001062.srg infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001063.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001064.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001065.vxd infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001066.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001067.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001069.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001071.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001072.vxd infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001073.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001074.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001080.dll infected by "not-a-virus:AdWare.ToolBar.YourSiteBar.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001082.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001084.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001089.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001091.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001099.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0001110.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0007300.exe infected by "not-a-virus:AdWare.Sahat.m" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0007340.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0007341.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009563.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009565.dll infected by "Trojan-Downloader.Win32.Ieser.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009568.exe infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009569.dll infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009578.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009579.dll infected by "not-a-virus:AdWare.Sahat.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009580.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009591.exe infected by "not-a-virus:AdWare.PowerScan.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009592.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009593.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009595.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009596.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009597.dll infected by "not-a-virus:AdWare.DlMax.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009598.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009600.dll infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009606.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0009881.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0013974.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0013975.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0013992.new infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0013996.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0013997.exe infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014008.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014011.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014012.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014013.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014014.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014015.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014016.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014017.exe infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014018.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014019.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014020.exe infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014021.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014023.dll infected by "not-a-virus:AdWare.WebSearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014024.EXE infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014025.EXE infected by "not-a-virus:AdWare.WebRebates.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014026.dll infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014027.dll infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014028.exe infected by "not-a-virus:AdWare.TotalVelocity.o" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014030.OCX infected by "not-a-virus:AdWare.DelphinMediaViewer.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014032.dll infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014033.exe infected by "not-a-virus:AdWare.BargainBuddy.i" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014034.exe infected by "Trojan.Win32.StartPage.ig" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014035.dll infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014036.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014037.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014038.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014039.exe infected by "Trojan.Win32.Stervis.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014040.dll infected by "not-a-virus:AdWare.ToolBar.BHO.k" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014041.exe infected by "not-a-virus:AdWare.DealHelper.ab" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014042.dll infected by "not-a-virus:AdWare.DealHelper.ab" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014043.exe infected by "not-a-virus:AdWare.F1Organizer.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014044.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014045.exe infected by "Trojan.Win32.Agent.ay" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014046.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014047.dll infected by "not-a-virus:AdWare.WildTangent.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014052.dll infected by "Trojan.Win32.Agent.db" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014059.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014061.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014074.dll infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014075.exe infected by "Trojan.Win32.Agent.ay" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014076.dll infected by "not-a-virus:AdWare.DlMax.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014087.exe infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014090.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014092.exe infected by "Trojan-Downloader.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014237.exe infected by "Trojan-Downloader.Win32.IstBar.ir" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014252.exe infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014253.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014255.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014256.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014277.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{CFC2D26F-AA6A-43C7-9490-048D34278F89}\RP0\A0014300.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP121\A0010508.exe infected by "Trojan.Win32.LowZones.ac" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP121\A0010509.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010518.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010519.exe infected by "Trojan-Downloader.Win32.Agent.hw" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010520.exe infected by "not-a-virus:AdWare.DealHelper.ac" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010521.exe infected by "not-a-virus:AdWare.ToolBar.SideFind.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010522.exe infected by "not-a-virus:AdWare.ToolBar.SideFind.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010524.dll infected by "not-a-virus:AdWare.ToolBar.YourSiteBar.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010525.dll infected by "Trojan-Downloader.Win32.Lookme.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010526.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010527.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010528.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010532.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010533.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010534.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\A0010535.dll infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken. File C:\WINDOWS\assest.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Celeb-Fakes[cf-10028,,].exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. File C:\WINDOWS\DHP2.dll infected by "not-a-virus:AdWare.DealHelper.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\abasa5jrp_.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\hochkaod3_.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\lkir8l2gm_.dll infected by "not-a-virus:AdWare.Sahat.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\setup4002b.cab infected by "not-a-virus:AdWare.Sahat.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sasent.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sasetup.dll infected by "Trojan.Win32.Dialer.bi" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\msfdje.gif infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\svhost.exe infected by "Virus.Win32.Bube.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\thin-94-5-x-x.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\xdldr24.exe infected by "Trojan-Downloader.Win32.Small.fo" Virus. Action Taken: No Action Taken.
OK, your system restore files are completely infected with malware and useless, lets delete them:
This link explains how:
XP system restore

When you reboot the system restore files will be deleted.

**************************************************************

These are from your temporary internet files, delete them all and make sure you delete them for all users and administrator .

Open up IE > Tools > Internet Options > Temporary Internet Files > Delete Files.

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CDAF8HEZ\package_MARKETING27[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\G9MN8HAF\pynix[1].cab
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\JUSY0Q30\optimize[1].exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\LN9HFEMM\istsvc[1].exe
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\0D89S56J\istdownload[1].exe
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\0D89S56J\thin_bundlelite2[1].exe
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[1].htm
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[2].htm
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[3].htm
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[4].htm
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\2NAZQTEF\ysb_prompt[5].htm
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\AFI3IDYR\ysb_regular[1].cab
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\CP2JSL2B\thin_poker[1].exe
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\WR9F62ZP\ysb_prompt[1].php
C:\Documents and Settings\Jason 2\Local Settings\Temporary Internet Files\Content.IE5\X0GBH9SD\rdgUS1742[1].exe

*************************************************************************

These are from Spybots Recovery, delete them:

File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer24.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.

File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.

File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS1.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.

***************************************************************************

These are from ewido, security suite > delete them.

File C:\Program Files\ewido\security suite\Quarantine\quaraFile69.ess infected by "Trojan-Dropper.VBS.Inor.y" Virus. Action Taken: No Action Taken.
File C:\Program Files\ewido\security suite\Quarantine\quaraFile70.ess infected by "Trojan-Dropper.VBS.Inor.y" Virus. Action Taken: No Action Taken.

*******************************************************************

The majority of the files found in the scan were in the NAV\Quarantine directory. To save space, I’m only including the first entry.

File C:\Program Files\Norton AntiVirus\Quarantine\0000131F.dll infected by "Trojan-Downloader.Win32.Small.aai" Virus. Action Taken: No Action Taken.

Delete the Quarantine directory. <———-

***************************************************************************

These are from CounterSpy Client, Quarantine folder > delete them.

File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\04FDA112-CD39-462B-858C-B809E5\731BA037-4F4E-4FF8-94F3-69F44E infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\B43BC775-A10C-4165-969C-94B6F7\A1B49F87-866E-4DBA-8899-64875C infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.

File C:\Program Files\Sunbelt Software\CounterSpy Client\Quarantine\DC6A3D0F-ED76-4FCA-ADD6-FE6A33\966811EB-FF67-4552-81E6-357D4C infected by "not-a-virus:AdWare.ToolBar.HotSearchBar.e" Virus. Action Taken: No Action Taken.

***********************************************************************
I'm not sure what these are from > maybe Norton > delete them if you can.

File C:\RECYCLER\NPROTECT\00000089.exe
File C:\RECYCLER\NPROTECT\00000090.dll
File C:\RECYCLER\NPROTECT\00000149.exe
File C:\RECYCLER\NPROTECT\00000185.exe
File C:\RECYCLER\NPROTECT\00000314.EXE
File C:\RECYCLER\NPROTECT\00000325.dll
File C:\RECYCLER\NPROTECT\00000327.gif.

*********************************************************************

Now…….

Download and unzip the KillBox to a folder.

Now open up the KillBox and copy and paste each one of these in and hit delete, if the file exists, it will appear in blue under the window.

C:\WINDOWS\assest.dll
C:\WINDOWS\Celeb-Fakes[cf-10028,,].exe
C:\WINDOWS\DHP2.dll
C:\WINDOWS\Downloaded Program Files\abasa5jrp_.exe
C:\WINDOWS\Downloaded Program Files\hochkaod3_.exe
C:\WINDOWS\Downloaded Program Files\lkir8l2gm_.dll
C:\WINDOWS\Downloaded Program Files\setup4002b.cab
C:\WINDOWS\system32\msfdje.gif
C:\WINDOWS\system32\thin-94-5-x-x.exe
C:\WINDOWS\system32\xdldr24.exe
C:\WINDOWS\DHP2.dll
C:\WINDOWS\sasent.dll
C:\WINDOWS\sasetup.dll
C:\WINDOWS\System32\svhost.exe
C:\WINDOWS\System32\thin-94-5-x-x.exe
C:\WINDOWS\System32\xdldr24.exe
C:\Documents and Settings\Jason 2\tool.exe
C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\1.exe.
C:\DOCUME~1\JASON2~1\LOCALS~1\Temp\iinstall.exe
C:\Documents and Settings\Jason 2\Local Settings\Temp\1.exe <—-These two may be the same as above
C:\Documents and Settings\Jason 2\Local Settings\Temp\iinstall.exe



The KillBox has a 'delete on reboot' or 'replace on reboot' (use dummy), use them if needed.
When using delete on reboot or replace on reboot - you can add multiple files.

The KillBox creates a folder called "!submit" in C:\ , after you are done you can delete the folder.

Reboot and run another mwavscan to see if we got them all. MrC
I've had to boot into safe mode the last few times. On a regular boot, it hangs up at the Welcome screen. I went to turn off the system restor and it was already checked. When I tried to uncheck and then re-check it it said I couldn't do it from safe mode. Can I delete them manually? Here is the latest mwav scan. File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "BetterInternet Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "BetterInternet Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "powerscan Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "ameopt Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "ist Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "avenue media Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "vendor Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "WebSiteViewer Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "pynix Spyware/Adware" Virus. Action Taken: No Action Taken. File C:\Program Files\Parsons\QuickVerse\QuickVerse\move.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274367.DLL infected by "not-a-virus:AdWare.ClearSearch.h" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274369.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274374.dll infected by "Trojan-Downloader.Win32.Briss.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274382.DLL infected by "not-a-virus:AdWare.ClearSearch.g" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274383.DLL infected by "not-a-virus:AdWare.ClearSearch.f" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274405.exe infected by "Trojan-Downloader.Win32.VB.cw" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274408.dll infected by "not-a-virus:AdWare.ClientMan" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274409.dll infected by "not-a-virus:AdWare.Ipend" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274412.dll infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274431.exe infected by "Trojan-Spy.Win32.Agent.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274440.exe infected by "Trojan-Dropper.Win32.Agent.bc" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274441.exe infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274442.exe infected by "not-a-virus:AdWare.ToolBar.CaptainCode.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274534.exe infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274535.dll infected by "not-a-virus:AdWare.ToolBar.ZSearch.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{16066D93-7561-4CEA-9BB1-1F93D271056D}\RP504\A0274536.dll infected by "not-a-virus:AdWare.WebSearch.d" Virus. Action Taken: No Action Taken. Plenty more of these since I couldn't get rid of the system restore point in safe mode.
Here's what I found to get those restore files:

If you start the Disk Cleanup utility and you click the Disk Cleanup tab, a System Restore: Obsolete Data Stores entry is available. These are files that were created before Windows was reformatted or reinstalled. They are obsolete and you can delete them. If you choose to clean up and delete these files, you will no longer see them under the folders that are mentioned earlier in this article, and the option to delete obsolete data stores will no longer appear on the Disk Cleanup utility. • You start the Disk Cleanup utility, click the More Options tab, and then click Clean up under System Restore. When you do this, all restore points (except the most recent one) are deleted.


I don't know why the rest of those are showing up.
Update Spybot and Adaware and run them again.
Here's how to tweak AdAware:

http://forum.malwareremoval.com/viewtopic.php?t=13

Let me know, MrC
I was able to use the CD to do a repair and then was able to boot normally. I was also able to delete the restore points and then ran the modified Ad-aware and Spybot scans. The Ad-Aware scan is listed below and Spybot didn't find anything.

I also included the latest hjt log for good measure.

Ad-Aware SE Build 1.05
Logfile Created on:Saturday, April 30, 2005 1:58:30 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R42 28.04.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
SideFind(TAC index:5):2 total references
TIB Browser(TAC index:6):2 total references
YourSiteBar(TAC index:6):2 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Definition File:
=========================
Definitions File Loaded:
Reference Number : SE1R42 28.04.2005
Internal build : 49
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 466557 Bytes
Total size : 1403889 Bytes
Signature data size : 1373297 Bytes
Reference data size : 30080 Bytes
Signatures total : 39226
Fingerprints total : 836
Fingerprints size : 28245 Bytes
Target categories : 15
Target families : 654


Memory + processor status:
==========================
Number of processors : 1
Processor architecture : Intel Pentium IV
Memory available:33 %
Total physical memory:228848 kb
Available physical memory:74728 kb
Total page file size:560056 kb
Available on page file:302932 kb
Total virtual memory:2097024 kb
Available virtual memory:2044492 kb
OS:Microsoft Windows XP Home Edition Service Pack 1 (Build 2600)

Ad-Aware SE Settings
===========================
Set : Move deleted files to Recycle Bin
Set : Safe mode (always request confirmation)
Set : Don't log streams smaller than 0 Bytes
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


4-30-2005 1:58:30 PM - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 492
ThreadCreationTime : 4-30-2005 6:42:46 PM
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 556
ThreadCreationTime : 4-30-2005 6:42:47 PM
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 580
ThreadCreationTime : 4-30-2005 6:42:47 PM
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 624
ThreadCreationTime : 4-30-2005 6:42:48 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 636
ThreadCreationTime : 4-30-2005 6:42:48 PM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 780
ThreadCreationTime : 4-30-2005 6:42:49 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 936
ThreadCreationTime : 4-30-2005 6:44:11 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1000
ThreadCreationTime : 4-30-2005 6:44:11 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1144
ThreadCreationTime : 4-30-2005 6:44:12 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1228
ThreadCreationTime : 4-30-2005 6:44:13 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1368
ThreadCreationTime : 4-30-2005 6:44:13 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:12 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1752
ThreadCreationTime : 4-30-2005 6:44:17 PM
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE

#:13 [drgtodsc.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\
ProcessID : 1808
ThreadCreationTime : 4-30-2005 6:44:18 PM
BasePriority : Normal
FileVersion : 6.1.1.40
ProductVersion : 6.1.1.40
ProductName : Drag-to-Disc
CompanyName : Roxio
FileDescription : Drag To Disc Application
InternalName : D2D
LegalCopyright : Copyright © 1999-2003 Roxio, Inc.
LegalTrademarks : Copyright © 1999-2003 Roxio, Inc.
OriginalFilename : BurnCtrl.EXE

#:14 [rxmon.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 1820
ThreadCreationTime : 4-30-2005 6:44:18 PM
BasePriority : Normal


#:15 [motivesb.exe]
FilePath : C:\PROGRA~1\SBCSEL~1\SMARTB~1\
ProcessID : 1836
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 5.6.7.asst_classic.smartbridge.20031210_035000
ProductVersion : 5.6.7.asst_classic.smartbridge
ProductName : Motive System
CompanyName : Motive Communications, Inc.
FileDescription : SBC Self Support Tool Alerts
InternalName : version
LegalCopyright : Copyright 1998-2003
OriginalFilename : version

#:16 [mmtask.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ProcessID : 1844
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 9.0.0.1
ProductVersion : 9.0.0.1
ProductName : Musicmatch Jukebox
CompanyName : Musicmatch Inc.
FileDescription :
InternalName : mmtask.exe
LegalCopyright : © Musicmatch Inc.. All rights reserved.
OriginalFilename : mmtask.exe

#:17 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 1852
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 4.7.1.30
ProductVersion : 4.7.1.30
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe

#:18 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 1860
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe

#:19 [mixer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1872
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 1.44
ProductVersion : 1.44
ProductName : Mixer
CompanyName : C-Media Electronic Inc. (www.cmedia.com.tw)
FileDescription : Mixer
InternalName : Mixer
LegalCopyright : Copyright © 1997-2001
LegalTrademarks : NONE
OriginalFilename : Mixer.EXE
Comments : Feng Min-Chih ([removed])

#:20 [cfd.exe]
FilePath : C:\Program Files\BroadJump\Client Foundation\
ProcessID : 1888
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal


#:21 [tgcmd.exe]
FilePath : C:\program files\support.com\bin\
ProcessID : 1904
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 5,5,479,0
ProductVersion : 5,5,479,0
ProductName : Support.com Scheduler and Command Dispatcher
CompanyName : Support.com, Inc.
FileDescription : Support.com Scheduler and Command Dispatcher
InternalName : TGCMD
LegalCopyright : Copyright 1997-2069 Support.com
OriginalFilename : TGCMD.EXE

#:22 [zlclient.exe]
FilePath : C:\Program Files\Zone Labs\ZoneAlarm\
ProcessID : 1924
ThreadCreationTime : 4-30-2005 6:44:19 PM
BasePriority : Normal
FileVersion : 5.5.062.004
ProductVersion : 5.5.062.004
ProductName : Zone Labs Client
CompanyName : Zone Labs Inc.
FileDescription : Zone Labs Client
InternalName : zlclient
LegalCopyright : Copyright © 1998-2004, Zone Labs Inc.
OriginalFilename : zlclient.exe

#:23 [sunasdtserv.exe]
FilePath : C:\Program Files\Sunbelt Software\CounterSpy Client\
ProcessID : 1948
ThreadCreationTime : 4-30-2005 6:44:20 PM
BasePriority : Normal
FileVersion : 1.00.0121
ProductVersion : 1.00.0121
ProductName : CounterSpy
CompanyName : Sunbelt Software Inc.
FileDescription : CounterSpy Data Service
InternalName : sunasDtServ
LegalCopyright : Copyright © 2004, Sunbelt Software Inc. All rights reserved.
OriginalFilename : sunasDtServ.exe

#:24 [sunasserv.exe]
FilePath : C:\Program Files\Sunbelt Software\CounterSpy Client\
ProcessID : 1964
ThreadCreationTime : 4-30-2005 6:44:20 PM
BasePriority : Idle
FileVersion : 1.00.0054
ProductVersion : 1.00.0054
ProductName : CounterSpy
CompanyName : Sunbelt Software Inc.
FileDescription : CounterSpy AntiSpyware Service
InternalName : sunasServ
LegalCopyright : Copyright © 2004, Sunbelt Software Inc. All rights reserved.
OriginalFilename : sunasServ.exe

#:25 [ybrwicon.exe]
FilePath : C:\Program Files\Yahoo!\browser\
ProcessID : 2008
ThreadCreationTime : 4-30-2005 6:44:20 PM
BasePriority : Normal
FileVersion : 2003, 7, 11, 1
ProductVersion : 1, 0, 0, 1
ProductName : Yahoo!, Inc. YBrwIcon
CompanyName : Yahoo!, Inc.
FileDescription : YBrwIcon
InternalName : YBrwIcon
LegalCopyright : Copyright © 2003
OriginalFilename : YBrwIcon.exe

#:26 [jusched.exe]
FilePath : C:\Program Files\Java\j2re1.4.2_04\bin\
ProcessID : 2040
ThreadCreationTime : 4-30-2005 6:44:21 PM
BasePriority : Normal


#:27 [hpgs2wnd.exe]
FilePath : C:\Program Files\Hewlett-Packard\HP Share-to-Web\
ProcessID : 168
ThreadCreationTime : 4-30-2005 6:44:22 PM
BasePriority : Normal
FileVersion : 2,4,0,26
ProductVersion : 2,4,0,26
ProductName : Hewlett-Packard hpgs2wnd
CompanyName : Hewlett-Packard
FileDescription : hpgs2wnd
InternalName : hpgs2wnd
LegalCopyright : Copyright © 2001
OriginalFilename : hpgs2wnd.exe

#:28 [ycommon.exe]
FilePath : C:\PROGRA~1\Yahoo!\browser\
ProcessID : 204
ThreadCreationTime : 4-30-2005 6:44:22 PM
BasePriority : Normal
FileVersion : 2003, 7, 14, 1
ProductVersion : 1, 0, 0, 1
ProductName : YCommon Exe Module
CompanyName : Yahoo!, Inc.
FileDescription : YCommon Exe Module
InternalName : YCommonExe
LegalCopyright : Copyright 2003 Yahoo! Inc.
OriginalFilename : YCommon.EXE

#:29 [em_exec.exe]
FilePath : C:\Program Files\Logitech\MouseWare\system\
ProcessID : 220
ThreadCreationTime : 4-30-2005 6:44:22 PM
BasePriority : Normal
FileVersion : 9.75.302
ProductVersion : 9.75.302
ProductName : MouseWare
CompanyName : Logitech Inc.
FileDescription : Logitech Events Handler Application
InternalName : Em_Exec
LegalCopyright : © 1987-2002 Logitech. All rights reserved.
LegalTrademarks : Logitech® and MouseWare® are registered trademarks of Logitech Inc.
OriginalFilename : Em_Exec.exe
Comments : Created by the MouseWare team

#:30 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 336
ThreadCreationTime : 4-30-2005 6:44:23 PM
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:31 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 368
ThreadCreationTime : 4-30-2005 6:44:23 PM
BasePriority : Normal
FileVersion : 1.03.4
ProductVersion : 1.03.4
ProductName : Event Manager
CompanyName : Symantec Corporation
FileDescription : Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe

#:32 [playlist.exe]
FilePath : C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\
ProcessID : 516
ThreadCreationTime : 4-30-2005 6:44:25 PM
BasePriority : Normal


#:33 [hpgs2wnf.exe]
FilePath : C:\PROGRA~1\HEWLET~1\HPSHAR~1\
ProcessID : 532
ThreadCreationTime : 4-30-2005 6:44:25 PM
BasePriority : Normal
FileVersion : 2,4,0,26
ProductVersion : 2,4,0,26
ProductName : hpgs2wnf Module
FileDescription : hpgs2wnf Module
InternalName : hpgs2wnf
LegalCopyright : Copyright 2001
OriginalFilename : hpgs2wnf.EXE

#:34 [ewidoctrl.exe]
FilePath : C:\Program Files\ewido\security suite\
ProcessID : 860
ThreadCreationTime : 4-30-2005 6:44:26 PM
BasePriority : Normal
FileVersion : 3, 0, 0, 1
ProductVersion : 3, 0, 0, 1
ProductName : ewido control
CompanyName : ewido networks
FileDescription : ewido control
InternalName : ewido control
LegalCopyright : Copyright © 2004
OriginalFilename : ewidoctrl.exe

#:35 [ewidoguard.exe]
FilePath : C:\Program Files\ewido\security suite\
ProcessID : 872
ThreadCreationTime : 4-30-2005 6:44:26 PM
BasePriority : Normal
FileVersion : 3, 0, 0, 1
ProductVersion : 3, 0, 0, 1
ProductName : guard
CompanyName : ewido networks
FileDescription : guard
InternalName : guard
LegalCopyright : Copyright © 2004
OriginalFilename : guard.exe

#:36 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 1024
ThreadCreationTime : 4-30-2005 6:44:29 PM
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright © Microsoft Corporation 2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:37 [acrotray.exe]
FilePath : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
ProcessID : 1112
ThreadCreationTime : 4-30-2005 6:44:34 PM
BasePriority : Normal
FileVersion : 5, 0, 0, 0
ProductVersion : 5, 0, 0, 0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright © 2001
OriginalFilename : AcroTray.exe

#:38 [hpobrt07.exe]
FilePath : C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\
ProcessID : 1404
ThreadCreationTime : 4-30-2005 6:44:36 PM
BasePriority : Normal
FileVersion : 2.00
ProductVersion : A.14.03.05
ProductName : hp psc 700 series
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Device Objects
InternalName : HPOBRT07
LegalCopyright : Copyright © Hewlett-Packard Co. 1995-2000
OriginalFilename : HPOBRT07.EXE
Comments : HP OfficeJet PSC 7 Series COM Device Objects

#:39 [navapsvc.exe]
FilePath : C:\Program Files\Norton AntiVirus\
ProcessID : 1492
ThreadCreationTime : 4-30-2005 6:44:37 PM
BasePriority : Normal
FileVersion : 9.05.1015
ProductVersion : 9.05.1015
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Copyright © 2000-2002 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE

#:40 [cmanager.exe]
FilePath : C:\Program Files\SBC\Connection Manager\
ProcessID : 1548
ThreadCreationTime : 4-30-2005 6:44:39 PM
BasePriority : Normal


#:41 [hotsync.exe]
FilePath : C:\Program Files\Palm\
ProcessID : 1700
ThreadCreationTime : 4-30-2005 6:44:41 PM
BasePriority : Normal
FileVersion : 4.0.4
ProductVersion : 4.1.0
ProductName : HotSync® Manager, Palm Desktop
CompanyName : Palm, Inc.
FileDescription : HotSync® Manager Application
InternalName : HotSync®
LegalCopyright : Copyright © 1995-2001 Palm, Inc.
LegalTrademarks : HotSync® is a registered trademark of Palm, Inc.
OriginalFilename : Hotsync.exe

#:42 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2052
ThreadCreationTime : 4-30-2005 6:44:44 PM
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:43 [vsmon.exe]
FilePath : C:\WINDOWS\system32\ZoneLabs\
ProcessID : 2092
ThreadCreationTime : 4-30-2005 6:44:45 PM
BasePriority : Normal
FileVersion : 5.5.062.004
ProductVersion : 5.5.062.004
ProductName : TrueVector Service
CompanyName : Zone Labs Inc.
FileDescription : TrueVector Service
InternalName : vsmon
LegalCopyright : Copyright © 1998-2004, Zone Labs Inc.
OriginalFilename : vsmon.exe

#:44 [ccd.exe]
FilePath : C:\PROGRA~1\BROADJ~1\CORREC~1\
ProcessID : 2236
ThreadCreationTime : 4-30-2005 6:44:52 PM
BasePriority : Normal


#:45 [hpoevm07.exe]
FilePath : C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\
ProcessID : 2408
ThreadCreationTime : 4-30-2005 6:45:04 PM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : A.14.03.05
ProductName : hp psc 700 series
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet COM Event Manager
InternalName : HPOEVM07
LegalCopyright : Copyright © Hewlett-Packard Co. 1995-2000
OriginalFilename : HPOEVM07.EXE
Comments : HP OfficeJet COM Event Manager

#:46 [hposts07.exe]
FilePath : C:\Program Files\Hewlett-Packard\AiO\Shared\bin\
ProcessID : 2532
ThreadCreationTime : 4-30-2005 6:45:10 PM
BasePriority : Normal
FileVersion : 1.00
ProductVersion : A.14.03.05
ProductName : hp psc 700 series
CompanyName : Hewlett-Packard Co.
FileDescription : HP OfficeJet Status
InternalName : HPOSTS07
LegalCopyright : Copyright © Hewlett-Packard Co. 1995-2000
OriginalFilename : HPOCPY07.EXE
Comments : HP OfficeJet Status

#:47 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 3008
ThreadCreationTime : 4-30-2005 6:46:13 PM
BasePriority : Normal
FileVersion : 4.7.1.30
ProductVersion : 4.7.1.30
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe

#:48 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3428
ThreadCreationTime : 4-30-2005 6:54:16 PM
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

TIB Browser Object Recognized!
Type : File
Data : A0007612.exe
Category : Dialer
Comment :
Object : C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP104\



SideFind Object Recognized!
Type : File
Data : A0010521.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\



SideFind Object Recognized!
Type : File
Data : A0010522.exe
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\



YourSiteBar Object Recognized!
Type : File
Data : A0010524.dll
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\
FileVersion : 1, 2, 0, 4
ProductVersion : 1, 2, 0, 4
ProductName : YourSiteBar
FileDescription : YourSiteBar
InternalName : YourSiteBar
LegalCopyright : Copyright 2004
OriginalFilename : ysb.dll


TIB Browser Object Recognized!
Type : File
Data : A0010534.exe
Category : Dialer
Comment :
Object : C:\System Volume Information\_restore{FB2C89D4-8DC1-41CC-A2A3-C666EB37F75C}\RP122\



Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 5

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
0 entries scanned.
New critical objects:0
Objects found so far: 5




Performing conditional scans…
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

YourSiteBar Object Recognized!
Type : RegValue
Data :
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\toolbar
Value : Locked

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 6

2:11:56 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:13:26.500
Objects scanned:104960
Objects identified:6
Objects ignored:0
New critical objects:6


Logfile of HijackThis v1.99.1
Scan saved at 2:34:43 PM, on 4/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\hjt\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo;! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1094327858343
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {86A63E0C-CCF7-11D4-90CE-00C02627FC4F} (HTMLXpress.MainControl) - http://my.electradigital.com/HTMLXPress.CAB
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
The logs looks GOOD! Well Done :thumbup:

Just clean up this one:

Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - (no file)

Click on Fix Checked and exit HijackThis.

How's it running? I have some info on running defrag and cleaning up the registry if you want it, also some preventive maintenance tips, MrC
It seems to be running pretty good. I think it's still a little slow booting up, but not bad. Thanks for your help, any additional tips would be appreciated. Also, what would you recommend for a new PC, besides the obvious NAV, Spybot, Ad-Aware and ZoneAlarm? I'm going to reboot and then perform all available windows updates. Thanks again, now I know there are some options short of a re-format/re-install. Bryan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI