This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Mikarn & Prui will not go away

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have this entry in my HJT log for Mikarn.exe and Prui.exe that I can't get rid of.

Have tried changing file extension to .old and deleting, but they just keep coming back. Have even used Killbox - still they come back.

I suspect these files are a big part of the pop up problem I'm having, but there is likely more.

Appreciate your advice with the attached HJT log

Logfile of HijackThis v1.99.1
Scan saved at 11:26:09 PM, on 5/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\intranet.exe
C:\WINDOWS\System32\mikarn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
c:\windows\system32\xvlnwn.exe
C:\WINDOWS\System32\wasptis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\MOM&DA~1\LOCALS~1\Temp\3.tmp\thnall1ac.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteizb32.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mikarn.exe
O4 - HKLM\..\Run: [rkcmqpj] c:\windows\system32\xvlnwn.exe
O4 - HKLM\..\Run: [The Intranet] intranet.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\Run: [The Intranet] intranet.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/Maxis…yScapeTeleX.cab
O23 - Service: Intranet Service (IntranetService) - Brought to you by the Bandwidth Bandits - C:\WINDOWS\SYSTEM32\intranet.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Download this tool: LQfix.zip
Unzip it to your Desktop.
Don't use it yet!

IMPORTANT! Reboot the computer into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').

Doubleclick LQfix.bat that you saved on your desktop before.
A doswindow will open and close again, that is normal.

Reboot into normal mode and scan with HijackThis. Post the new log as a reply to this thread.
Did what you said. HJT log is still showing Mikarn.exe. See attached




Logfile of HijackThis v1.99.1
Scan saved at 9:33:59 PM, on 5/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\mikarn.exe
C:\WINDOWS\System32\intranet.exe
c:\windows\system32\ecxonvi.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\System32\wasptis.exe
C:\WINDOWS\system32\intranet.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mikarn.exe
O4 - HKLM\..\Run: [gxsckf] c:\windows\system32\ecxonvi.exe
O4 - HKLM\..\Run: [The Intranet] intranet.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\Run: [The Intranet] intranet.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/Maxis…yScapeTeleX.cab
O23 - Service: Intranet Service (IntranetService) - Brought to you by the Bandwidth Bandits - C:\WINDOWS\SYSTEM32\intranet.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Download the the FindQoologic-Narrator.zip and save it to your Desktop.
http://forums.net-integration.net/index.ph…=post&id=134981

1. Extract (unzip) the files inside into their own folder called FindQoologic.
2. Open the FindQoologic folder.
3. Locate and double-click the Activesetup.vbs file to run it.
Please wait until a "Finished" message appears.

* When the set-up is complete a file named "Activesetup components[Machine ID][date].txt" will have been saved in the FindQoologic folder.

4. Locate and double-click the Find-Qoologic.bat to run it.

* The tool will open a DOS window and begin to check your system.
When it is finished a text file will open in Notepad called "file.txt".
* Save this text file in the FindQoologic folder.
* Close the DOS box If on win 98 or me.

5. Open the "Activesetup components[Machine ID][date].txt" file and the file you saved and copy / paste their contents to this thread (as a reply).
.txt files attached: "Find activesetup", version1, launched at: 06:46 Operating System: Windows XP HKLM\Software\Microsoft\Active Setup\Installed Components\ "14ca49e4-f5a0-4a28-83d1-b8845ab13a03\(Default)" = "" \StubPath = "C:\WINDOWS\System32\rdmxcom.exe" [null data] ">{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default)" = "Microsoft Windows Media Player" \StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS] PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Adobe Reader Speed Launch.lnk priu.exe User Startup: C:\Documents and Settings\Mom & Dad\Start Menu\Programs\Startup . .. SpywareGuard.lnk »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\tmxsgqxf REG_SZ {164e0c69-a69e-45d0-9525-aa796489324c} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin »»»»»»»»»»»»»»»»»»»»»»»»» Active setup »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
When I executed the Find-Qoologic.bat file the following came up. Windows Script Host There is no file extension in "C:\DOCUME~1\MOM". I hit OK to proceed then I got. 16 bit MS-DOS Subsystem C:\Windows\System32\Cmd.exe C:\Windows\System32\AUTOEXEC.NT the system file is not suitable for running MS-DOS and Microsoft Windows application. Choose 'close' to terminate the application. Choices offered are CLOSE or IGNORE hitting ethier about 10 times gave me the log I posted.
Running XP Pro Fix you seems to have worked. Txt files attached. "Find activesetup", version1, launched at: 06:33 Operating System: Windows XP HKLM\Software\Microsoft\Active Setup\Installed Components\ "14ca49e4-f5a0-4a28-83d1-b8845ab13a03\(Default)" = "" \StubPath = "C:\WINDOWS\System32\rdmxcom.exe" [null data] ">{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default)" = "Microsoft Windows Media Player" \StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS] PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» * aspack C:\WINDOWS\System32\SAIE_KYF.DAT * urllogic C:\WINDOWS\HMZRA.DLL * qoologic C:\WINDOWS\HMZRA.DLL * qoologic C:\WINDOWS\UNADBEH.EXE * ad-beh C:\WINDOWS\System32\HSREPGR.DLL * ad-beh C:\WINDOWS\System32\PDUON.DLL * ad-beh C:\WINDOWS\System32\WINUP2~1.DLL * ad-beh C:\WINDOWS\System32\MIKARN.EXE * ad-beh C:\WINDOWS\System32\RDMXCOM.EXE * ad-beh C:\WINDOWS\System32\WMCONFIG.CPL * ad-beh C:\WINDOWS\UNADBEH.EXE »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» * exe C:\docume~1\alluse~1\startm~1\programs\startup\PRIU.EXE »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Adobe Reader Speed Launch.lnk priu.exe User Startup: C:\Documents and Settings\Mom & Dad\Start Menu\Programs\Startup . .. SpywareGuard.lnk »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\tmxsgqxf REG_SZ {164e0c69-a69e-45d0-9525-aa796489324c} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin »»»»»»»»»»»»»»»»»»»»»»»»» Active setup »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Download Killbox.
Click killbox.exe.
Select the option "Delete on reboot".

Now copy the next bold:

C:\WINDOWS\System32\SAIE_KYF.DAT
C:\WINDOWS\HMZRA.DLL
C:\WINDOWS\System32\HSREPGR.DLL
C:\WINDOWS\System32\PDUON.DLL
C:\WINDOWS\System32\WINUP2~1.DLL
C:\WINDOWS\System32\MIKARN.EXE
C:\WINDOWS\System32\RDMXCOM.EXE
C:\WINDOWS\System32\WMCONFIG.CPL
C:\WINDOWS\UNADBEH.EXE
C:\docume~1\alluse~1\startm~1\programs\startup\PRIU.EXE


Open 'file' in the killboxmenu on top and choose Paste from clipboard

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines must be there together!

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

Your system must reboot now.

Open notepad and copy and paste next content in the field in it:

REGEDIT4

[-HKLM\Software\Microsoft\Active Setup\Installed Components\{14ca49e4-f5a0-4a28-83d1-b8845ab13a03}]

[-HKEY_CLASSES_ROOT\CLSID\{14ca49e4-f5a0-4a28-83d1-b8845ab13a03}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14ca49e4-f5a0-4a28-83d1-b8845ab13a03}]

Save this as Qfix.reg choose to save as *all files and place it on your desktop.
Doubleclick on it and when it asks you to add the content to the registry, click yes/ok

Post a new findqoologic-log in your next reply.
Did everything. New .txt files attached. "Find activesetup", version1, launched at: 21:09 Operating System: Windows XP HKLM\Software\Microsoft\Active Setup\Installed Components\ ">{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default)" = "Microsoft Windows Media Player" \StubPath = "C:\WINDOWS\inf\unregmp2.exe /ShowWMP" [MS] PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Adobe Reader Speed Launch.lnk User Startup: C:\Documents and Settings\Mom & Dad\Start Menu\Programs\Startup . .. SpywareGuard.lnk »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\tmxsgqxf REG_SZ {164e0c69-a69e-45d0-9525-aa796489324c} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin »»»»»»»»»»»»»»»»»»»»»»»»» Active setup »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
In addition to the last posted reply, I ran AdAwareSE, SpyBot S&D, CWShredder then HJT - see attached log <>



Logfile of HijackThis v1.99.1
Scan saved at 9:43:53 PM, on 5/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\intranet.exe
c:\windows\system32\ewgfrhn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wasptis.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\mikarn.exe
O4 - HKLM\..\Run: [wcdlro] c:\windows\system32\ewgfrhn.exe
O4 - HKLM\..\Run: [The Intranet] intranet.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\Run: [The Intranet] intranet.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/Maxis…yScapeTeleX.cab
O23 - Service: Intranet Service (IntranetService) - Brought to you by the Bandwidth Bandits - C:\WINDOWS\SYSTEM32\intranet.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Download and install: http://www.srnmicro.com/downloads/
Click “Update” and make sure you’ve got the latest updates. Now click “Options” and place a checkmark near “Create Report”. Now go to “Action on Virus” and choose in the pulldown-menu for “Clean Files”. Now click “OK”. Hit “Scan & Clean” now.

Reboot your system, make a new HijackThis log and post it here. Also post the log provided by Solo Antivirus Scanner (that log can be found at :\Program Files\SRN Micro\VirusReport.txt). :)
Solo and HJT log attached.

Solo log of deleted files.


Solo Virus Scanning Report
==========================
______________________________________________
File Name Virus Name Path
______________________________________________

tool2_162813.exe Trojan.Adware.Ilookup C:\WINDOWS\SYSTEM32\Cache
SSK_B5 Seedcorn 2.EXE TrojanDownloader.Win32.Small.WD C:\WINDOWS\SYSTEM32\Cache
saie1101.exe TrojanDownloader.Win32.Small.MR C:\WINDOWS\SYSTEM32\Cache
pop.exe Trojan.Adware.WinAd C:\WINDOWS\SYSTEM32\Cache
WASPTIS.EXX Trojan.Win32.VB.VV C:\WINDOWS\SYSTEM32
VCMnet9.exe TrojanDownloader.Win32.Small.Aly C:\WINDOWS\SYSTEM32
tool2_667279.exe Trojan.Adware.Ilookup C:\WINDOWS\SYSTEM32
SSK_B5 Verticlick 7.EXE TrojanDownloader.Win32.Small.WD C:\WINDOWS\SYSTEM32
saie1108.exe TrojanDownloader.Win32.Small.MR C:\WINDOWS\SYSTEM32
rtneg2.dll Trojan.Adware.Begin2search C:\WINDOWS\SYSTEM32
pop2.exe Trojan.Adware.WinAd C:\WINDOWS\SYSTEM32
papray.exe TrojanDownloader.Win32.Agent.Cp C:\WINDOWS\SYSTEM32
INTRANET.EXX Backdoor.VBbot.B C:\WINDOWS\SYSTEM32
DrPMon.dll TrojanDownloader.Win32.Agent.Db C:\WINDOWS\SYSTEM32
Dell Image Expert.scr Trojan.Exact C:\WINDOWS\SYSTEM32
cxtpls_loader.exe TrojanDownloader.Win32.Apropo.R C:\WINDOWS\SYSTEM32
bwkgq.dat TrojanDownloader.Win32.Qoologic C:\WINDOWS\SYSTEM32
svcproc.exe Trojan.Win32.StervisC:\WINDOWS
Nail.exe Trojan.Nail C:\WINDOWS
mvytntkbuv.exe Trojan.Win32.Gen C:\WINDOWS
farmmext.exe Trojan.Stubby.C C:\WINDOWS
Bolger.dll Trojan.Adware.BetterInternet C:\WINDOWS
A0010956.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010955.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010954.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010953.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010952.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010951.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010950.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010949.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010948.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010947.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010946.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010945.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010944.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010943.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010942.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010941.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010940.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010939.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010938.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010937.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010936.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010935.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010934.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010933.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010932.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010931.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010930.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010929.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010928.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010927.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010926.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010925.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010924.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010923.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010922.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010921.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010920.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010919.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010918.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010917.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010916.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010915.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010914.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010913.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010912.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010911.old Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010910.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010909.old TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010908.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010907.dll Trojan.Adware.WinAd C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010906.exe Trojan.Adware.WinAd C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010905.dll Trojan.Adware.WinAd C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010904.dll Trojan.Win32.Mirar C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010903.dll Trojan.Win32.Mirar C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010902.EXE Trojan.Adware.Minibug C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010901.exe Trojan.Adware.WinAd.K C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010899.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010898.old TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010897.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010896.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010895.old TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010892.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010886.exe Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010885.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010884.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010883.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010882.exe Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010881.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010880.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010879.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010878.exe Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010876.exe Trojan.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010874.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010869.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010860.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010853.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP30
A0010848.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010842.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010832.exe TrojanDownloader.Win32.VB.EM C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010831.exe Trojan.Win32.VB.VV C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010830.exe Backdoor.VBbot.B C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010827.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010809.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010805.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010796.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP29
A0010790.dll Trojan.Adware.WinAd C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010778.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010762.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010758.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010752.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010750.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP28
A0010737.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0009746.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0009738.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008746.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008740.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008728.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008715.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008705.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008700.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008690.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP27
A0008666.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP26
A0008658.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP26
A0007650.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007646.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007636.exe Trojan.StartPage.NP C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007635.exe Trojan.StartPage.NK C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007634.exe Trojan.StartPage.NP C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007625.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0007608.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006611.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006600.dll Trojan.Adware.BetterInternet C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006596.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006587.old TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006584.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006583.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006577.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006573.dll Trojan.Win32.WildAgent C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006570.dll Trojan.Win32.WildAgent C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP25
A0006555.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006547.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006546.old TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006545.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006540.dll Trojan.Adware.Elitebar C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006530.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006529.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006525.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006522.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP24
A0006519.exe Trojan.StartPage.Nk C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP23
A0006512.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP23
A0006504.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP22
A0005511.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP22
A0005504.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP22
A0005496.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP22
A0005479.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP21
A0005473.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP21
A0005465.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP21
A0005464.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP21
A0005459.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP20
A0005449.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP19
A0005438.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP18
A0005432.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP18
A0005423.exe TrojanDownloader.Win32.Agent.Cp C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP18
A0005422.exe Trojan.Win32.Gen C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP18
A0005404.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP17
A0005403.exe TrojanDownloader.Win32.Qoologic C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP17
Dc94.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc93.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc92.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc91.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc90.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc89.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc88.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc87.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc86.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc85.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc84.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc83.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc82.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc81.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc80.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc79.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc78.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc77.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc76.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc75.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc74.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc73.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc72.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc71.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc70.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc69.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc68.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc67.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc66.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc65.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc64.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc63.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc62.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc61.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc60.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc59.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc58.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc57.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc56.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc55.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc54.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc53.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc52.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc51.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc50.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc49.old Trojan.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc48.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc47.old TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
Dc32.exe TrojanDownloader.Win32.VB.EM C:\RECYCLER\S-1-5-21-2372122917-2413124425-3619004274-1006
WinStatComm.dll Trojan.Adware.WinAd C:\Program Files\Windows AdStatus
PrevAdKeep.exe Trojan.Adware.WinAd C:\Program Files\Preview AdService
PrevAdComm.dll Trojan.Adware.WinAd C:\Program Files\Preview AdService
PdeHlp2.dll Trojan.Win32.Mirar C:\Program Files\Dell\JBSeries2Drv
PdeHlp2.dll Trojan.Win32.Mirar C:\Program Files\Dell\Digital Jukebox Drivers
WxBug.EXE Trojan.Adware.Minibug C:\Program Files\AIM\Sysfiles
AdToolsKeep.exe Trojan.Adware.WinAd.K C:\Program Files\AdTools Service
backup-20050501-230832-966-priu.exe TrojanDownloader.Win32.Qoologic C:\HJT\backups
backup-20050501-230832-746-priu.old TrojanDownloader.Win32.Qoologic C:\HJT\backups
backup-20050501-222002-178-oldpruiold.exe TrojanDownloader.Win32.Qoologic C:\HJT\backups
BMan1.exe Trojan.Win32.Gen C:\Documents and Settings\All Users\Application Data\msw
mikarn.old TrojanDownloader.Win32.Qoologic C:\!Submit
mikarn.abc TrojanDownloader.Win32.Qoologic C:\!Submit
abcmikarnabc.abc TrojanDownloader.Win32.Qoologic C:\!Submit
______________________________________________

NEW HJT LOG

Logfile of HijackThis v1.99.1
Scan saved at 12:28:32 PM, on 5/7/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\SpywareGuard\sgmain.exe
c:\windows\system32\hypovf.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BolgerObj Class - {302A3240-4805-4a34-97D7-1645A0B08410} - C:\WINDOWS\Bolger.dll (file missing)
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [The Intranet] intranet.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\SYSTEM32\AAU4ZY.EXE
O4 - HKLM\..\Run: [qgemyca] c:\windows\system32\hypovf.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\Run: [The Intranet] intranet.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D3D83E08-54D1-4E9D-8EAF-9F979D139294} (MaxisSimCityScapeTeleX Control) - http://simcity.ea.com/scape/teleport/Maxis…yScapeTeleX.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O23 - Service: Intranet Service (IntranetService) - Unknown owner - intranet.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Please follow these instructions carefully and exactly. Print these instructions out, as you will not be able to access the internet during the fix.

1. Download and install Ewido: http://download.ewido.net/ewido-setup.exe
When installed, run the program. It will give you a warning that the database is outdated. Click OK, and go to "Update" and click "start updating". When it's done Ewido will close… If not close it yourself.

2. Download rkfiles.zip
UNZIP the contents to a permanent folder (on your desktop)

3. Download Killbox from here:
http://www.downloads.subratam.org/KillBox.zip
UNZIP the contents to a permanent folder(on your desktop)

4. Disconnect from the internet (if you use a router or modem, turn it off)

5. Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg (save as: all files) and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SvcProc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SvcProc]      

DO NOT RUN IT YET!

6. Reboot in SAFE MODE !! Important !!
°To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key

Please set your system to show all files.
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Doubleclick rkfiles.bat
It will scan for a while.
Wait till the doswindow closes. STAY IN SAFE MODE!

Please try to find a way to post the contents of C:\log.txt. You could save it to a floppy or USB-stick and go to another computer with internet access and post the rkfiles.bat log.

Also make a new HijackThis log (while in safe mode) and get it, along with the rkfiles.bat log, to another PC to post it here.

PLEASE, DO NOT REBOOT ANYTIME, UNTILL I'M BACK WITH A FIX! So, only reboot if I say so!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI