This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hi, my name is Eri... I'm, err, computer-dumb

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
I'm not sure exactly how my computer got infested with all this spyware, but it is getting out of control! I use AdAware and NAV, and have removed the obvious things myself (such as MediaAccess, etc) with HijackThis, but the popups just keep coming back… (don't you have when they pop up right under your cursor the moment you start to click on something?)

I did my very best to take care of this myself but now humbly ask for the help of you experts. Note that I use a Japanese OS on a Japanese laptop bought purely for style (performance ain't bad either), and I don't know what half the preinstalled software is.

Please excuse my ingnorance and embarassingly long log file… many thanks for your help!

Eri


Logfile of HijackThis v1.99.1
Scan saved at 4:51:24 PM, on 5/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\LiquidView\lviewj.exe
C:\Program Files\MELCO INC\エアステーションユーティリティ\ABRECEIVER\ABReceiver.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\windows\system32\jhdukp.exe
C:\WINDOWS\System32\ilnvkz.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\SysCheckBop32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\えり\Application Data\asew.exe
C:\windows\system32\calc.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\conime.exe
C:\PROGRA~1\EzButton\DtcEMail.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\えり\デスクトップ\HijackThis.exe

O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [imjpmig] C:\Program Files\Common Files\Microsoft Shared\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe -nogui
O4 - HKLM\..\Run: [ABRECEIVER] "C:\Program Files\MELCO INC\?G?A?X?e?[?V?‡?“?†?[?e?B???e?B\ABRECEIVER\ABReceiver.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [jhdukp] c:\windows\system32\jhdukp.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ilnvkz.exe
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [win320882-4532650] C:\WINDOWS\win320882-4532650.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Tooc] C:\Documents and Settings\?|?e\Application Data\asew.exe
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: The翻訳_ページ翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O8 - Extra context menu item: The翻訳_範囲指定翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O8 - Extra context menu item: The翻訳_翻訳設定 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O8 - Extra context menu item: The翻訳_辞書参照 - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: ???T?[?` - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra 'Tools' menuitem: The?|?o_?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra button: (no name) - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra 'Tools' menuitem: The?|?o_?≪?‘?Q?A - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: (no name) - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra 'Tools' menuitem: The?|?o_”I?I?w’e?|?o - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra button: (no name) - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra 'Tools' menuitem: The?|?o_?|?o?Y’e - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra button: ?≪?‘?o?[ - {D1A62E0C-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandTate.dll
O9 - Extra button: ?|?o?o?[ - {D1A62E0E-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandYoko.dll
O14 - IERESET.INF: START_PAGE_URL=http://dynabook.com/
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…271/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FA2BDEB-D689-4770-BBA0-D43FCEB1022B}: NameServer = 210.196.3.183,210.141.112.163
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Sorry about the double post, but wanted to clarify what the problem is: non-stop popups, near 100% CPU usage, extremely time-consuming to type, etc. Thanks.
Hi Welcome to Tom Coyote Forums. Please run a new HijackThis scan and post the log in this topic and I will try to help you. Elrond :)
Hi Elrond,

Thanks for taking a look. Here's the new HJT log. Since posting the first time, I've noticed that Norton Antivirus is also acting up. The letters in the dialogue boxes are jumbled up and filled with question marks, and I am being prompted to "activate" my software. I can't seem to connect to their server to get any Live Updates, either.

Please help make my PC OK again…


Logfile of HijackThis v1.99.1
Scan saved at 8:38:07 AM, on 5/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\LiquidView\lviewj.exe
C:\Program Files\MELCO INC\エアステーションユーティリティ\ABRECEIVER\ABReceiver.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\windows\system32\jhdukp.exe
C:\WINDOWS\System32\ilnvkz.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SysCheckBop32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\windows\system32\packager.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\EzButton\DtcEMail.exe
C:\Documents and Settings\えり\Application Data\asew.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\えり\デスクトップ\Hijack this\HijackThis.exe

O2 - BHO: (no name) - {00000000-59D4-4008-9058-080011001200} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [imjpmig] C:\Program Files\Common Files\Microsoft Shared\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe -nogui
O4 - HKLM\..\Run: [ABRECEIVER] "C:\Program Files\MELCO INC\?G?A?X?e?[?V?‡?“?†?[?e?B???e?B\ABRECEIVER\ABReceiver.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdt.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [jhdukp] c:\windows\system32\jhdukp.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\ilnvkz.exe
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [SystemCheck] C:\WINDOWS\SysCheckBop32
O4 - HKLM\..\Run: [win320882-4532650] C:\WINDOWS\win320882-4532650.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Tooc] C:\Documents and Settings\?|?e\Application Data\asew.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: The翻訳_ページ翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O8 - Extra context menu item: The翻訳_範囲指定翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O8 - Extra context menu item: The翻訳_翻訳設定 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O8 - Extra context menu item: The翻訳_辞書参照 - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: ???T?[?` - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra 'Tools' menuitem: The?|?o_?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra button: (no name) - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra 'Tools' menuitem: The?|?o_?≪?‘?Q?A - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: (no name) - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra 'Tools' menuitem: The?|?o_”I?I?w’e?|?o - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra button: (no name) - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra 'Tools' menuitem: The?|?o_?|?o?Y’e - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra button: ?≪?‘?o?[ - {D1A62E0C-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandTate.dll
O9 - Extra button: ?|?o?o?[ - {D1A62E0E-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandYoko.dll
O14 - IERESET.INF: START_PAGE_URL=http://dynabook.com/
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…271/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FA2BDEB-D689-4770-BBA0-D43FCEB1022B}: NameServer = 210.196.3.183,210.141.112.163
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi bebop

You have a collection of infections on your computer. You have to understand that my knowledge of Japanese is nonexistent and it could be that I will ask a few questions or instruct you to do one or two things that are not absolutely necessary in just in order to to be sure that we do not miss something important but shigata genai. (I believe that that is correct). Please note that this will be amulti step cleanup process and that when I believe that your computer is clean I will ask you to update Windows and to take certain precautions to avoid a repetition of the infections. We are however far from there yet.

We will start with uninstalling som malware and then a number of different scans in order to try to get rid of as much as possible before we start doing the manual cleanup.

Before that there are some necessary preliminaries.

To be sure that you this topic again and that you get an E-mail informing you when an answer has ben posted please
1. Go to the Tom Coyote Forums http://forums.tomcoyote.org/index.php? .
Click on My Controls near the top middle of the window (make sure you have signed in first).
On the left hand column, click "view topics".
If you click on the title of your post, you will be taken there.
2. Also, while at that place in control panel, check the box to the right of your post and then scroll down.
Where it says "unsubscribe" click the pull-down menu and select "immediate email notification", By doing this, you will be notified as soon as I have posted a reply to your log.

Please note that RED or UNDERLINED or some times a different colored word/s are links that can be clicked to get to a website.

HOW TO Instructions:
Reboot in safe mode. If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.
How to print the fix instructions
How to Copy, Cut, and Paste
Click the red links above.

How to unzip a downloaded zip file.
Place the zip file in the folder where you want the unzipped program to be.
If you are running Windows XP you simply right click the zip file and select "Extract Files".
For the other versions of Windows you will need a program like 7-Zip . If you decide to use 7-Zip down load the newest version that is not a beta version.
Open 7-Zip. Navigate to to the downloaded zipfile and highlight it. Right click and select "Extract Here"

How to post a new HijackThis log
Close all windows and browsers.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button it is OK.)
When the "Scan" button changes into a "Save Log" button click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" ("Post Reply") button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V".
DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH

OK let's start the cleanup.

1. Please copy the instructions to a notepad or preferably print them.

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. Configure Windows to show all files. Showing hidden files and folders in Windows. if you need help with this.

5. On the Windows XP taskbar:
Click "Start" > "Control Panel".
In the "Control Panel" window, double-click "Add or Remove Programs".
Find Media Pass and remove it.
Reboot.

6. I know that you have run Adaware before but I would like you to follow the instructions found here http://tomcoyote.org/aawsb.php and run both Adaware and Spybot.

7. Please use the following links to run the two online Virus Scanners and let them fix whatever they find. Save the logs and post them if you can
Panda: http://www.pandasoftware.com/activescan/co…n_principal.htm
Trend Micro: http://housecall.trendmicro.com/housecall/start_corp.asp
Here are links to two online Trojan Scanners. Run one and let it fix what it finds.
http://scan.sygatetech.com/pretrojanscan.html
Or here:
http://www.windowsecurity.com/trojanscan/

8. I want you to download Microsoft Antispyware Beta1 from http://www.microsoft.com/athome/security/s…re/default.mspx. It is free and available for Microsoft Windows 2000, Windows XP, or Windows Server™ 2003.

To set up Microsoft Antispyware Beta1 for best results please read the tutorial here . Be SURE to get the latest updates for the program.

To post a log from Microsoft AntiSpyware do as follows:
Open Microsoft AntiSpyware.
Click "Tools" > "Spyware Scan" > View Spyware Scan History.
Highlight the latest scan.
Click "View full details of scan" found in the lower right corner.
Right-click on the window with the details of the scan.
Click "Select All"
Click Ctrl + c to copy the contents

Paste the content into a new post in this topic together with a new Hijack This log and any other logs you have been able to save.

Let me know in some detail what problems you have now.

Please also give me answers to the following questiones: Did TTI come installed on your computer or did you install it youself?
Do you know anything about the following files?
C:\WINDOWS\win320882-4532650.exe
c:\windows\system32\jhdukp.exe
C:\Documents and Settings\??\Application Data\asew.exe


With the information from the logs and your answers I will decide on the next step in the cleanup.

Elrond :) (Bowing deeply)
Dear Elrond,

It looks like my PC has a lot more going on than I imagined. The scans took hours, but your instructions helped get rid of most of the nasty ones. (A few new ones surfaced too.) Here are the results as requested. The log files are long, so the post will be broken up into a few smaller posts. Comments, answers to your questions follow the log files.

Spybot:
67 problems found, scan finished with an "Error during check!" message.

Ad-Aware SE Personal:
271 critical objects

Panda:
77of 294 files disinfected (log file follows)


Incident Status Location

Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Te\Temporary Internet Files\Content.IE5\25OZ2D29\4zvFBH4Pb0fw2gFK8YQ5[1].chm[1.htm]
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Te\Temporary Internet Files\Content.IE5\4XI7KT6J\CACDURCR.HTM
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Te\Temporary Internet Files\Content.IE5\G1EN0DQN\TYsbNsOwSpjvBJ-QhRBn[1].chm[1.htm]
Adware:Adware/Transponder No disinfected C:\Documents and Settings\えり\Local Settings\Temp\temp.frB007
Adware:Adware/QoolShown No disinfected C:\Documents and Settings\えり\Local Settings\Temp\temp.frCBC1
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\05MFCTU3\AxkQt_gPuWNKPoo3EL3w[1].chm[1.htm]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\05MFCTU3\CvgcgUe_ARwmQWdSMaX_[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\05MFCTU3\CvgcgUe_ARwmQWdSMaX_[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\1KTC9NAA\DnJTTNPaTdB6sysgyy8F[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\1KTC9NAA\L6myJD4X_g24AZD6-_Ed[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\1KTC9NAA\LfZgMBwIoi038NjfOycA[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\2P38P83Q\kxXJvtbCsjwS8qLUexxz[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\49WH8FEL\DfmkkEX60d9lOiyKeypC[1].chm[1.htm]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\49WH8FEL\Nqfcw4Q2Qog9BH1BFMuA[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\49WH8FEL\q1S5wALI6Nav6wcs5kae[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4D6P2D0T\hUb7Q-a41cg8KHvhMbJL[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4D6P2D0T\WaJGSjudv85dxwAbA-ly[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4D6P2D0T\WaJGSjudv85dxwAbA-ly[1].chm[on-line.exe]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4D6P2D0T\zwSXLxoKCEt6LYVmI73L[1].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4D6P2D0T\zwSXLxoKCEt6LYVmI73L[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\500B5P0X\3HWSFgQcCAMf6-TpEtnw[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\500B5P0X\Cvg7XUy_ARwmQWdSMaUD[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\500B5P0X\K9wspZHLNZvOmLCFbELf[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\500B5P0X\Nqd9Q4I2Qog9BH1BFMsv[1].chm
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\6R6HAP0J\CAQNWTMP.HTM
Adware:Adware/Transponder No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89A7GH63\aurora[1].exe
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89A7GH63\gjo1_VpbhZ2E_C3l1Cz5[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89A7GH63\OFqG6jHPU0VW2dSgQZkw[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89QZGLQF\4jVVp-OjE7AKftJZKUpU[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89QZGLQF\lh5sP2ePtWx3NrqODw33[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\89QZGLQF\NXMdHTrNNTaMi2F4XKcF[1].chm[1.htm]
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\8DMBGHIN\protector_update[1].exe
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\APWZ876Z\pmFD8xbVROwWHV0sinh8[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\B29JH5WE\3HU9_vYcCAMf6-TpEtnf[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\B29JH5WE\3HU9_vYcCAMf6-TpEtnf[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\B29JH5WE\7tO1OdMHzIOvqIq5BxxU[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\BFTV3LKW\yflQGu6moJL_Fr5gJ88f[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\EX0FMTU1\S7cxQ37u_bWosF5SZpF2[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\EX0FMTU1\XIROm1ywV-BF14HmN7BU[1].chm
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[Worker.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[Xeyond.class]
Virus:Trj/Downloader.CHD Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\counter[1].jpg[web.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\cWNQO9cGfcrJMQKqDWzq[1].chm
Adware:Adware/Transponder No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\Nail[1].exe
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\RI7m-O8Zb8Cx6GVBHCbk[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\RI7m-O8Zb8Cx6GVBHCbk[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\F6SNZTSP\vHJMcCdqxleXo4gN-gxg[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GH2F8LQB\3HV_EAQcCAMf6-TpEtm1[1].chm
Adware:Adware/Hotoffers No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GH2F8LQB\dropper[1].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GH2F8LQB\dropper[1].chm[xxx.html]
Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GH2F8LQB\pcs_0015[1].exe
Virus:Trj/Downloader.BYN Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GH2F8LQB\trk_0015[1].exe
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GPAR4TI7\7KMHysXkVEztCHtqPnPl[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\GPAR4TI7\7KMHysXkVEztCHtqPnPl[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\pL2zn-fbyBWTvME1srNg[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\SUG9LoBW_mu9apOKqSay[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\UPaD7g0LqGUIE002WD4U[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\UPaD7g0LqGUIE002WD4U[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\V78TU-LvCFFG046fFFZ6[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\Xh27yTxqdxAoVo0n-p7A[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\HSKZXHSL\XISuClmwV-BF14HmN7Bs[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\4Wb9lossULOtrEsP1cBP[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\a0zEOmwib5IzKKT4suH4[1].chm
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\CA8ZMDQ5.HTM
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\CAKPM1TI.HTM
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\CASXA74P.HTM
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\eWUgqGJPypy0NwkSFm4S[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\kAU5F3LEFYIazLQgnIfA[1].chm[1.htm]
Virus:VBS/Psyme.C No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IHYTET8B\TRACK15[1].CHM[track15.htm]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\KFX7II7T\3bAsc2abOWznjPD8JWlP[1].chm
Virus:Trj/Downloader.BDE No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\KFX7II7T\ddfs[1].chm[frame.exe]
Virus:VBS/Psyme.C No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\KFX7II7T\ddfs[1].chm[1.htm]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LBJOMCL3\6AvuXncmy71d1AJiSuMR[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LBJOMCL3\6AvuXncmy71d1AJiSuMR[1].chm[on-line.exe]
Spyware:Spyware/Media-motor No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LBJOMCL3\diamond[1].cab[m67m.inf]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\ArHMblkBHmJYJcriMj_P[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\ArHMblkBHmJYJcriMj_P[1].chm[on-line.exe]
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA1DZL22.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA339TOE.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA3M9GDJ.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA4D6HNK.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA5XK0SP.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CA7IKF3D.HTM
Virus:Exploit/Mhtredir.gen Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\CAQF0X2Z.HTM
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\casino-ico[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\casino[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\casino[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\casino[3].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dating-ico[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dating[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dating[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dating[3].bmp
Spyware:Spyware/Fstb No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[1].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[1].chm[xxx.html]
Spyware:Spyware/Fstb No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[2].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[2].chm[xxx.html]
Spyware:Spyware/Fstb No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[3].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[3].chm[xxx.html]
Spyware:Spyware/Fstb No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[4].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\dropper[4].chm[xxx.html]
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\drugs-ico[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\drugs-ico[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\drugs[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\drugs[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\drugs[3].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\fav-ico[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\fav[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\fav[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\fav[3].bmp
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[1].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[1].chm[on-line.exe]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[2].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[2].chm[on-line.exe]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[3].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\kAXzhW_EFYIazLQgnId8[3].chm[on-line.exe]
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\virus[1].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\virus[2].bmp
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\virus[3].bmp
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\zr1nNRXbyBWTvME1srMp[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\LYNC7K3Y\zr1nNRXbyBWTvME1srMp[1].chm[on-line.exe]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\ArE2LIIBHmJYJcriMj8q[1].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\ArE2LIIBHmJYJcriMj8q[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\gjofcqRbhZ2E_C3l1CwT[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\r1_F6ohpRO4-YJDdotXx[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\r1_F6ohpRO4-YJDdotXx[1].chm[on-line.exe]
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\OHCNS7CZ\wrapperouter[1].exe
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\S7R3MO1L\kAXs0VLEFYIazLQgnIff[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\SHYROHAB\cWPviP0GfcrJMQKqDWzk[1].chm[1.htm]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\SHYROHAB\Oacu8nEsGmyf683j2piV[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\b1ZkmKJUZlfu5eNX_iUm[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\bGErmAml2KHmmiAFSuxv[1].chm
Adware:Adware/Hotoffers No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\dropper[1].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\dropper[1].chm[xxx.html]
Adware:Adware/Hotoffers No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\dropper[2].chm[dropper.exe]
Virus:Exploit/CodeBase.S No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\dropper[2].chm[xxx.html]
Adware:Adware/Transponder No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\UTJ8L0BY\DrPMon[1].dll
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\WLCBKJGF\-RkRDEOaksaZiAZMBzw1[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\WLCBKJGF\aAUJY1XRsfReQWCsjYoK[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\WLCBKJGF\aAUJY1XRsfReQWCsjYoK[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\WLCBKJGF\SsrYNerdqwnsB-InCPmG[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YD0BYHQX\b1ZUSl5UZlfu5eNX_iVP[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YD0BYHQX\OFoq7sTPU0VW2dSgQZn2[1].chm[1.htm]
Adware:Adware/CWS.Aboutblank No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YD0BYHQX\OFoq7sTPU0VW2dSgQZn2[1].chm[on-line.exe]
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YD0BYHQX\qLfMeFTI_0-P8rb162mj[1].chm[1.htm]
Adware:Adware/Transponder No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YD0BYHQX\svcproc[1].exe
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YR8PWHY5\classload[1].jar[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YR8PWHY5\classload[1].jar[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YR8PWHY5\classload[1].jar[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YR8PWHY5\classload[1].jar[Installer.class]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YZ012LM5\EO-PqgHVm1TRtoLnYg7l[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YZ012LM5\HwZ0sRz-RBg-mT9ifIbf[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YZ012LM5\Oumz_RBzH5blS7YARaHz[1].chm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\YZ012LM5\PtAOFqFAAtCvps7jbjok[1].chm
Virus:Trj/Small.GV No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\30vihoRYxMi0Verjr0yU[1].chm[1.htm]
Adware:Adware Program No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\30vihoRYxMi0Verjr0yU[1].chm[on-line.exe]
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\9-hw90lE26TSuN2i7pbM[1].chm
Virus:W32/Spybot.QV.worm Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\i282[1].exe
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\t4jPDl63wNmKFxxQCKKY[1].chm
Adware:Adware/VirtualBouncer No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\ZZXTDLTM\wrapperouter[1].exe
Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Ssk.log
Adware:Adware/AlwaysupdatednewsNo disinfected C:\Program Files\Windows Media Player\wmplayer.exe.tmp
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763519.exe
Adware:Adware/ExactSearch No disinfected C:\RECYCLER\NPROTECT\01763524.exe
Adware:Adware/eZula No disinfected C:\RECYCLER\NPROTECT\01763534.ax[mscb.dll]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[bb_auto_wider.swf]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[bb_click_wider.swf]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[bb_welcome1.swf]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[bb_welcome.html]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[icon.gif]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[logo.gif]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[cashback.exe]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[cb.exe]
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\NPROTECT\01763534.ax[flash.exe]
Spyware:Spyware/BargainBuddy No disinfect
HouseCall:
Could not clean or delete the following:
TROJ_CLICKER.AD C:\windows\system32\AUNPS2.dll
TROJ_BRDUPDATE.D C:\windows\system32\e6fl873b.dll
TROJ_AGENT.ABS C:\windows\system32\gflerae.exe

Sygate Trojan Scan:
Says I have "blocked all of our probes!"

WindowsSecurity Scanner:
Picked up the following:
C:\windows\system32\AUNPS2.dll
C:\windows\system32\DOCE0C16B1.dll
C:\windows\system32\DrPMon.dll
C:\windows\system32\gflerae.exe
C:\windows\system32\sbgtryp.dll
C:\windows\system32\ilnvkz.exe
a bunch of cookies
a few files found in Local Settings\Temp and Temporary Internet Files folder
AntiSpyware:
Spyware Scan Details
Start Date: 5/20/2005 12:37:13 AM
End Date: 5/20/2005 1:34:14 AM
Total Time: 57 mins 1 secs

Detected Threats

ShopAtHome Spyware more information…
Details: ShopAtHome installs an agent in the Winsock layer of your computer. This redirects your Web browser to merchant sites affiliated with ShopAtHome rather than the Web sites you type in or click.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\recycler\nprotect\01763911.dll


TV Media Display Adware more information…
Details: TV Media Display is secretly installed on your computer to display advertising, usually pop-ups.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\recycler\nprotect\01763508.dll


WindUpdates Browser Plug-in more information…
Details: WindUpdates downloads additional adware and displays pop-up advertising.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\system32\winupdt.bin

Infected registry keys/values detected
HKEY_CURRENT_USER\Software\WinUpdt
HKEY_CURRENT_USER\Software\WinUpdt 0001 1063501
HKEY_CURRENT_USER\Software\WinUpdt 0002 11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run winupdtl


eXact.BullseyeNetwork Adware more information…
Details: Bullseye displays pop-up advertisements.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\recycler\nprotect\01763867.exe


Transponder.kz515 Spyware more information…
Details: Transponder is an Internet Explorer Browser Helper Object (BHO) that monitors web pages requested and data entered into forms.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\kz515.dll

Infected registry keys/values detected
HKEY_CLASSES_ROOT\TypeLib\{ED1282A6-4A6E-4893-85FC-6CCFD39D8377}
HKEY_CURRENT_USER\Software\kz515 KZI5d1OfSDist 8|3|0|0|THIN-8-3-X-X.EXE
HKEY_CURRENT_USER\Software\kz515 KZT5o1pListSPos 0
HKEY_CURRENT_USER\Software\kz515 KZs5t1icky1S 0
HKEY_CURRENT_USER\Software\kz515 KZs5t1icky2S 0
HKEY_CURRENT_USER\Software\kz515 KZs5t1icky3S 0
HKEY_CURRENT_USER\Software\kz515 KZs5t1icky4S 0
HKEY_CURRENT_USER\Software\kz515 KZC1o5d1eOfSFinalAd 0
HKEY_CURRENT_USER\Software\kz515 KZT5i1m5eOfSFinalAd 0
HKEY_CURRENT_USER\Software\kz515 KZD5s1tSSEnd 兆魔タタヘ泝恂来チ所ラ寃€搖麿蝿フ装は氓タ送・似実ッェョ諮芙・
HKEY_CURRENT_USER\Software\kz515 KZ5N1a5tionSCode XX
HKEY_CLASSES_ROOT\TypeLib\{ED1282A6-4A6E-4893-85FC-6CCFD39D8377}\1.1\0\win32 C:\WINDOWS\kz515.dll
HKEY_CURRENT_USER\Software\kz515 KZP5D1om オ延来中唐笈沱フ総・
HKEY_CURRENT_USER\Software\kz515 KZT5h1rshSCheckSIn 45
HKEY_CURRENT_USER\Software\kz515 KZT5h1rshSMots 7
HKEY_CURRENT_USER\Software\kz515 KZM5o1deSSync 1
HKEY_CURRENT_USER\Software\kz515 KZI5n1ProgSCab 0
HKEY_CURRENT_USER\Software\kz515 KZI5n1ProgSEx 0
HKEY_CURRENT_USER\Software\kz515 KZI5n1ProgSLstest 0
HKEY_CURRENT_USER\Software\kz515 KZE5v1nt 1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1
HKEY_CURRENT_USER\Software\kz515 KZU5n1reg 0
HKEY_CLASSES_ROOT\TypeLib\{ED1282A6-4A6E-4893-85FC-6CCFD39D8377}\1.1\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{ED1282A6-4A6E-4893-85FC-6CCFD39D8377}\1.1\HELPDIR C:\WINDOWS\
HKEY_CLASSES_ROOT\TypeLib\{ED1282A6-4A6E-4893-85FC-6CCFD39D8377}\1.1 kz515Dll 1.1 Type Library
HKEY_CURRENT_USER\Software\kz515
HKEY_CURRENT_USER\Software\kz515 KZI5d1OfSInst {5CA0C461-C277-4330-8E55-6458E339D1FD}
HKEY_CURRENT_USER\Software\kz515 KZC5n1trMsgSDisp 0
HKEY_CURRENT_USER\Software\kz515


Transponder.ABetterInternet.Aurora Spyware more information…
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\documents and settings\えり\local settings\temporary internet files\content.ie5\89a7gh63\aurora[1].exe
c:\windows\nail.exe


Transponder.ABetterInternet.DrPMon Spyware more information…
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\system32\drpmon.dll
c:\documents and settings\えり\local settings\temporary internet files\content.ie5\utj8l0by\drpmon[1].dll


BookedSpace Browser Plug-in more information…
Details: BookedSpace is an Internet Explorer browser helper object that displays pop-up advertising.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\bsx32\eech1.bsx
c:\windows\bsx32\spz3.bsx

Infected folders detected
c:\windows\bsx32


AvenueMedia.DyFuCA Browser Plug-in more information…
Details: AvenueMedia DyFuCA Internet Optimizer is adware that changes your browser error page. It periodically displays pop-up advertisements from its remote sites and may update itself.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Internet Optimizer Changed 0


Peper Trojan Downloader more information…
Details: Peper downloads advertisements and displays pop-up advertising, and downloads additional copies of itself and other adware.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\windows\system32\e6f1873b.dll

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run A70F6A1D-0195-42a2-934C-D8AC0F7C08EB rundll32.exe E6F1873B.DLL,D9EBC318C


SearchMiracle.EliteBar Browser Plug-in more information…
Details: SearchMiracle.EliteBar adds a search redirection toolbar to Internet Explorer called Elite Bar.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\documents and settings\えり\local settings\temporary internet files\content.ie5\8dmbghin\protector_update[1].exe

Infected registry keys/values detected
HKEY_CURRENT_USER\Software\LQ
HKEY_CURRENT_USER\Software\LQ leck trump
HKEY_CURRENT_USER\Software\LQ country Japan
HKEY_CURRENT_USER\Software\LQ city Tokyo
HKEY_CURRENT_USER\Software\LQ state 40
HKEY_CURRENT_USER\Software\LQ RX 1
HKEY_CURRENT_USER\Software\LQ RX2.8 1
HKEY_CURRENT_USER\Software\LQ RX2.9 1
HKEY_CURRENT_USER\Software\LQ RX3.0 1
HKEY_CURRENT_USER\Software\LQ RX3.1 1
HKEY_CURRENT_USER\Software\LQ RX3.2 1
HKEY_CURRENT_USER\Software\LQ TM 10
HKEY_CURRENT_USER\Software\LQ RX3.3 1
HKEY_CURRENT_USER\Software\LQ FU3.4 1
HKEY_CURRENT_USER\Software\LQ FU3.5 1
HKEY_CURRENT_USER\Software\LQ FU3.6 1
HKEY_CURRENT_USER\Software\LQ LU3.7 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run checkrun
HKEY_CURRENT_USER\Software\LQ AT 86400
HKEY_CURRENT_USER\Software\LQ AC 35950
HKEY_CURRENT_USER\Software\LQ U 0
HKEY_CURRENT_USER\Software\LQ AD 5
HKEY_CURRENT_USER\Software\LQ I {2508EBE2-FC25-4816-8E87-1D01EDA767AC}
HKEY_CURRENT_USER\Software\LQ AM 6
HKEY_CURRENT_USER\Software\LQ TR 86400


eXact.CashBack Adware more information…
Details: CashBack is part of BargainBuddy adware that displays pop-up advertisements.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\recycler\nprotect\01763519.exe
c:\recycler\nprotect\01763822.exe
c:\recycler\nprotect\01763835.exe


Begin2Search Browser Plug-in more information…
Details: Begin2Search installs third party spyware, displays pop-up advertisements, and redirects Internet Explorer.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\cache\tool2_162813.exe
c:\windows\system32\cache\trgen_fran-162813.exe


Unclassified.Spyware.Bundles Spyware more information…
Details: Spyware Bundles are groups of spyware installers that are silently downloaded and will automatically install when you restart Windows.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\cache\videoinst.exe


EnhanceMySearch Settings Modifier more information…
Details: EnhanceMySearch captures your Web searches and redirects them to a specific Web site.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\helper101.dll


eZula.Earn Adware more information…
Details: eZula.Earn is the advertising component of the eZula adware software.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\cache\installer_marketing17.exe


Transponder.ABetterInternet.Ceres Spyware more information…
Details: VX2.ABetterInternet.Transponder.2 is a new transponder variant of aBetterInternet.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\cache\bs5-va-egihsg.exe


AlwaysUpdateNews Spyware more information…
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\aunps2.dll


MSWSearch Spyware more information…
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\cache\installaps.exe
c:\windows\system32\cache\mswinstall.exe

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6}
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D}\TypeLib {A6713E88-E0C0-4E24-A2F3-11067BA30115}
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D}\VERSION 1.2
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D} BMan.BManager
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6}\LocalServer32 C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6}\ProgID BMan.cIExplorer
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6}\TypeLib {A6713E88-E0C0-4E24-A2F3-11067BA30115}
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6}\VERSION 1.2
HKEY_CLASSES_ROOT\clsid\{408A9E15-A481-4FD1-9C2E-D03F7FC50BE6} BMan.cIExplorer
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D}
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D}\LocalServer32 C:\DOCUME~1\ALLUSE~1\APPLIC~1\msw\BMan.exe
HKEY_CLASSES_ROOT\clsid\{C7B44349-9060-4D07-8CAD-80036C755A8D}\ProgID BMan.BManager


Unclassified.Spyware.57 Spyware more information…
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\windows\system32\ilnvkz.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run KavSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run KavSvc


PacerDMedia.Installer Trojan Downloader more information…
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\documents and settings\えり\local settings\temporary internet files\content.ie5\gh2f8lqb\pcs_0015[1].exe


AdDestroyer Adware more information…
Details: AdDestroyer is promoted as a spyware remover. However, it sets itself to run when you start the computer and remains memory-resident. When it runs, the software periodically attempts to contact a server to download updates and instructions.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\recycler\nprotect\01764587.dll
c:\recycler\nprotect\01764588.dll
c:\recycler\nprotect\01764589.dll
c:\recycler\nprotect\01764590.dll

Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}\InprocServer32 C:\WINDOWS\system32\PopOops2.dll
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}\ProgID PopOops2.PopOops
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}\TypeLib {D0C29A75-7146-4737-98EE-BC4D7CF44AF9}
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC}\VERSION 7.0
HKEY_CLASSES_ROOT\clsid\{417386C3-8D4A-4611-9B91-E57E89D603AC} PopOops2.PopOops


eXact.BargainBuddy Adware more information…
Details: BargainBuddy is a Browser Helper Object that watches the pages your browser requests and the terms you enter into a search engine web form. If a term matches a preset list of sites or keywords, BargainBuddy will display an ad.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.

Infected files detected
c:\recycler\nprotect\01763524.exe


iSearch.Toolbar Toolbar more information…
Details: ISearch toolbar is a spyware/adware toolbar that is purported to deliver advanced toolbar functions to Internet Explorer, however, it changes your browser settings.
Status: Removed
Elevated threat - Eleveated-risk items have some potential for harm. Users should review such programs and remove them if unwanted.

Infected files detected
c:\windows\system32\cache\mte0mza6odoxmg.exe


SurfSideKick Settings Modifier more information…
Details: SurfSideKick downloads and displays advertisements
Status: Removed
Elevated threat - Eleveated-risk items have some potential for harm. Users should review such programs and remove them if unwanted.

Infected files detected
c:\recycler\nprotect\01763840.dll
c:\recycler\nprotect\01763841.dll
c:\recycler\nprotect\01763842.exe
c:\windows\system32\cache\ssk_b5 wmg media - rev share 3.exe


BrowserAid Browser Plug-in more information…
Details: BrowserAid is a group of Internet Explorer toolbars that are installed without your consent.
Status: Removed
Elevated threat - Eleveated-risk items have some potential for harm. Users should review such programs and remove them if unwanted.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 15 1054749091
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate\Active 25 1054749091
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdate uid2 {39F9B233-16ED-4C72-B187-94E9DFE1FC96}


180search Assistant Adware more information…
Details: 180search Assistant displays pop-up advertismenets.
Status: Quarantined
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected files detected
c:\windows\system32\saie_kyf.dat
c:\windows\system32\saieau.dat


KaZaA Under Investigation more information…
Details: KaAaA is peer-to-peer file-sharing software that displays advertising and installs third-party adware on your computer.
Status: Quarantined
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected files detected
c:\program files\kazaa\cloudload.dat
c:\program files\kazaa\tsi2.cab
c:\program files\kazaa\db\data1024.dbb
c:\program files\kazaa\db\data256.dbb
c:\program files\kazaa\db\np.tmp
c:\program files\kazaa\my shared folder\kmd211_en.exe
c:\program files\kazaa\my shared folder\legenda the matrix reloaded [divx].ssa
c:\program files\kazaa\my shared folder\the matrix reloaded.avi

Infected folders detected
c:\program files\kazaa
c:\program files\kazaa\db
c:\program files\kazaa\my shared folder

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\software\kazaa
HKEY_LOCAL_MACHINE\software\kazaa\CloudLoad ShareDir C:\Program Files\Kazaa\My Shared Folder
HKEY_LOCAL_MACHINE\software\kazaa\CloudLoad ExeDir C:\Program Files\Kazaa
HKEY_LOCAL_MACHINE\software\kazaa\ConnectionInfo
HKEY_LOCAL_MACHINE\software\kazaa\ConnectionInfo +
HKEY_LOCAL_MACHINE\software\kazaa\LocalContent +
HKEY_LOCAL_MACHINE\software\kazaa\LocalContent DownloadDir C:\Program Files\Kazaa\My Shared Folder
HKEY_LOCAL_MACHINE\software\kazaa\LocalContent DatabaseDir C:\Program Files\Kazaa\Db
HKEY_LOCAL_MACHINE\software\kazaa Tmp 0
HKEY_LOCAL_MACHINE\software\kazaa ListenPort 1642
HKEY_LOCAL_MACHINE\software\kazaa UDP_probe_successes -1431655763
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\in b0 45022
HKEY_LOCAL_MACHINE\software\kazaa
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\in b1 0
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\in b0seconds 58254
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\LastEstimate b 50656
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\LastEstimate time 1054485459
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\out b0 2466
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\out b1 0
HKEY_LOCAL_MACHINE\software\kazaa\Bandwidth\out b0seconds 4940


Detected Spyware Cookies
No spyware cookies were found during this scan.
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 1:54:10 AM, on 5/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\gflerae.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\LiquidView\lviewj.exe
C:\Program Files\MELCO INC\エアステーションユーティリティ\ABRECEIVER\ABReceiver.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\EzButton\DtcEMail.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\えり\デスクトップ\Hijack this\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [imjpmig] C:\Program Files\Common Files\Microsoft Shared\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe -nogui
O4 - HKLM\..\Run: [ABRECEIVER] "C:\Program Files\MELCO INC\?G?A?X?e?[?V?‡?“?†?[?e?B???e?B\ABRECEIVER\ABReceiver.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [fynemq] c:\windows\system32\gflerae.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Tooc] C:\Documents and Settings\?|?e\Application Data\asew.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: The翻訳_ページ翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O8 - Extra context menu item: The翻訳_範囲指定翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O8 - Extra context menu item: The翻訳_翻訳設定 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O8 - Extra context menu item: The翻訳_辞書参照 - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: ???T?[?` - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra 'Tools' menuitem: The?|?o_?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra button: (no name) - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra 'Tools' menuitem: The?|?o_?≪?‘?Q?A - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: (no name) - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra 'Tools' menuitem: The?|?o_”I?I?w’e?|?o - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra button: (no name) - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra 'Tools' menuitem: The?|?o_?|?o?Y’e - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra button: ?≪?‘?o?[ - {D1A62E0C-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandTate.dll
O9 - Extra button: ?|?o?o?[ - {D1A62E0E-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandYoko.dll
O14 - IERESET.INF: START_PAGE_URL=http://dynabook.com/
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (32U?ET?A° On-Line Scan) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…271/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FA2BDEB-D689-4770-BBA0-D43FCEB1022B}: NameServer = 210.196.3.183,210.141.112.163
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Okay, that was long. (Please let me know if there's a better way to format/post log files)

As for the problems that are still occurring:
Recurring pop-ups that appear in groups of 3-5 at a time (smileys, spyware warnings)
Dialogue boxes that pop up. A "VBScript: Advertisement" to download a "Registry Cleaner"
XP Security alerts me every time an "MM Viewer" by "nLite" attempts to download to my PC.
Slow CPU.

And in response to your questions,
I believe TTI was pre-installed on the computer. Some sort of translation software.
As for the other files, I don't know what they are, though I'm pretty sure they're bad. (File date looks suspicious, and one or two were removed by scans?)

I really do appreciate your time with this. I await the next step.

Domo arigato,
Eri
Hello again Eri :wavey: (It should be a deep bow but no such smiley)

We got rid of a lot of junk to say the least. :) One or two new infections showed up but I do not know if they were there before but hidden by all the other stuff.

You have had two very serious infections Nail and Qoologic on your computer. :( There are indications that they have been cleaned up :) but as the method is still new I want to check that Qoologic is really gone and that the some of the files really are infected before we continue getting rid of them. That is the reason for the scans this time. If we are lucky there will be only two more rounds of postings but I do not promise anything. You never know. Let's hope for the best.

1. It is very good that Microsoft AntiSpyware is protecting you in real time but that can hinder the changes that are needed to get your computer clean. Therefore please:
Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

2. Clean out the temporary files.
Please download System Security Suite
Mark the page under the "Items to Clean" tab like this . Run the program. Repeat for each account on the system.

3. Go to http://virusscan.jotti.org
Copy this line into the white textbox:
c:\windows\system32\gflerae.exe
Click Submit. You will get a report. Please post it in your next reply.
Now repeat but instead copying the line please browse to C:\Documents and Settings\?|?e\Application Data\asew.exe. When you find it highlight it and click open. Submit it and post the result.

4. Download FindQoologic-Narrator.zip save it to your Desktop.
http://forums.net-integration.net/index.ph…=post&id;=134981

Extract (unzip) the files inside into their own folder called FindQoologic.
Open the FindQoologic folder. Preferable to your desktop.
Locate and double-click the Find-Qoologic.bat file to run it.
wait until a text opens, post it in a reply to your thread.

5. Download and install Agent Ransack a free search tool. http://www.mythicsoft.com/agentransack/default.aspx
Install the program.
Start the program. Start > Programs > Agent Ransack > Agent Ransack
Check expert user if it is not already checked.

Copy (Ctrl+c)/paste(ctrl+v) the following
(Qoologic|Aspack|narrator)+
into the "Containing Text" field.

Copy the following:
C:\windows;C:\windows\start menu\programs\Startup
into the "Look in" field.

Uncheck the box "Search subfolders"

Click "Start search"

Once the scan is finished please go to "File" (at the top of the screen) and click it. Select "Save results from the menu.
Clipboard is checked by default. Leave it as it is.
At the bottom of the screen under "Information" uncheck "Contents". Now click "Save". This copies it to your clipboard.
Right-click in the reply area below the last log and paste that information into the post. Again do not assume all thats is being found is bad.

6. Download FindRK-files.zip from here. http://skads.org/special/rkfiles.zip
Extract the FindRK-files.zip folder from zip to your desktop. (it cannot be run from the zip)

Reboot into safe mode. Open the FindRK-files folder.
Double click on the RKFILES.BAT file. It will take a few minutes to run.
When the cmd.exe window closes reboot your computer to normal mode.
A log file was created. It is found at C:\Log.txt.

Locate the log and add it to your next post.

7. Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button that is OK.) When the scan is finished put a check mark by the items that are listed in below. If you can not find an item just continue but inform me with your next post. Do not click fix until instructed to do so:
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe/B]
This is optional but you could also have HijackThis fix these entries as they are not needed and they can slow down your PC when starting up
Application Scheduler is installed along with RealOne Player and is running in startup, and is not needed. Once installed, it runs independently of RealOne Player and consumes resources. You can fix this with HijackThis, but you will also need to set it not to load in RealPlayer itself to keep it from resetting itself: (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
This is the item to check mark in HijackThis:

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Quick launch System Tray Icon for Quicktime Player. Not needed unless you use Quicktime regularly. Will reappear every time you use the player though unless you start Quicktime player, click on Edit> Preferences> Quicktime Preferences and Uncheck 'Quicktime System Tray Icon'."
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

Close all open windows except HijackThis and then click the "Fix checked" button.

5. Reboot in safe mode.

6. Using Windows Explorer, locate the following files and delete them:
C:\WINDOWS\Nail.exe
C:\windows\system32\elitentu32.exe
Exit Explorer, and reboot as normal afterwards.

7. Please do a search:
"Run "Start">"Search">"All Files and Folders"> enter D0CE0C16B1 in "All or part of file name". Select "More advanced options". Check-mark "Search System Folders", "Search hidden files and folders", and "Search subfolders". Click "Search". If found please right-click it and delete it.

8. Post a new HijackThis log together with the other logs requested.

Elrond :)
Hi Elrond,

Oh no, I'm embarassed to have caught Nail… I now realize that just one or two scanners can't be relied on to catch these things, and prevention is key to keeping a PC healthy. Oh boy, I see that clearly now. I've followed your instructions 1 - 6 but have a few questions so will wait to proceed.

1. AntiSpy turned off

2. Ran the System Security Suite

3. Regarding gflerae.exe and asew.exe, they don't seem to appear on my PC in the specified locations. Hidden system files are viewable, but these could not be found when browsing their respective folders.

With Jotti Malware Scan:
Tried to upload the following by pasting in the links as shown in HijackThis as well as browsing for the files.
Received the following message:
"The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file"

4. The link to FindQoologic-Narrator.zip was not found, so I searched Net-Integration and found FindQoologic2.zip from the following post at:

http://forums.net-integration.net/index.ph…ndpost&p;=146944

I ran it and received an error messages similar to
"autoexec.nt the system file is not suitable for running ms-dos etc etc , or a 16 bit app error etc etc" (but in Japanese).
I clicked close each time, as opposed to ignore. Upon trying it again, I notice that I get an alert from Norton AntiVirus regarding a "File System Object" trying to "GetSpecialFolder". Shall I disable Norton (or allow the script to run) and try again? I've included the log just in case.


PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
ササササササササササササササササササササササササ Files found ササササササササササササササササササササササササササササササササササ


ササササササササササササササササササササササササ startup filesサササササササササササササササササササササササササササササササササ


ササササササササササササササササササササササササ Checking Global Startup ササササササササササササササササササササササ

(fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48

Global Startup:
C:\Documents and Settings\All Users\スタート メニュー\プログラム\スタートアップ
.
..
Adobe Gamma Loader.exe.lnk
desktop.ini

User Startup:
C:\Documents and Settings\えり\スタート メニュー\プログラム\スタートアップ
.
..
desktop.ini

ササササササササササササササササササササササササ Registry Entries Found サササササササササササササササササササササササ

! REG.EXE VERSION 3.0

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mkqfxygg
<名前なし> REG{c4e5576a-4684-44ab-b8e1-c2823bc62731}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
<名前なし> REG{750fdf0e-2a26-11d1-a3ea-080036587f03}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
<名前なし> REG{09799AFB-AD67-11d1-ABCD-00C04FC30936}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
<名前なし> REG{A470F8CF-A1E8-4f65-8335-227475AA5C46}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\StuffIt Compress Menu
<名前なし> REG{3FBFD0B0-EB46-4797-9101-615610E87DA6}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
<名前なし> REG{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinRAR
<名前なし> REG{B41DB860-8EE4-11D2-9906-E49FADC173CA}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
<名前なし> REG{E0D79300-84BE-11CE-9641-444553540000}

HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
<名前なし> REGStart Menu Pin

サササササササササササササササササササササササササ Active setup ササササササササササササササササササササササササササササササササ


So… I think I will wait to do the next step until I hear from you. Please hurry back! :P Thanks!

Eri
No problems Eri
This happens sometimes. Continue with the other scans. They should tell me if there are any parts of the infection left.

After point 4 above continue as follows:

5. Download and install Agent Ransack a free search tool. http://www.mythicsoft.com/agentransack/default.aspx
Install the program.
Start the program. Start > Programs > Agent Ransack > Agent Ransack
Check expert user if it is not already checked.

Copy (Ctrl+c)/paste(ctrl+v) the following
(Qoologic|Aspack|narrator)+
into the "Containing Text" field.

Copy the following:
C:\windows;C:\windows\start menu\programs\Startup
into the "Look in" field.

Uncheck the box "Search subfolders"

Click "Start search"

Once the scan is finished please go to "File" (at the top of the screen) and click it. Select "Save results from the menu.
Clipboard is checked by default. Leave it as it is.
At the bottom of the screen under "Information" uncheck "Contents". Now click "Save". This copies it to your clipboard.
Right-click in the reply area below the last log and paste that information into the post. Again do not assume all thats is being found is bad.

6. Download FindRK-files.zip from here. http://skads.org/special/rkfiles.zip
Extract the FindRK-files.zip folder from zip to your desktop. (it cannot be run from the zip)

Reboot into safe mode. Open the FindRK-files folder.
Double click on the RKFILES.BAT file. It will take a few minutes to run.
When the cmd.exe window closes reboot your computer to normal mode.
A log file was created. It is found at C:\Log.txt.

Locate the log and add it to your next post.

7. Open HiJackThis, click "Open the Misc Tools Section", and click "Open process manager". Highlight c:\windows\system32\gflerae.exe if it is there and click "kill Process". Do not kill any other process

8. Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button that is OK.) When the scan is finished put a check mark by the items that are listed in below. If you can not find an item just continue but inform me with your next post. Do not click fix until instructed to do so:
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [fynemq] c:\windows\system32\gflerae.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe
O4 - HKCU\..\Run: [Tooc] C:\Documents and Settings\?|?e\Application Data\asew.exe

This is optional but you could also have HijackThis fix these entries as they are not needed and they can slow down your PC when starting up
Application Scheduler is installed along with RealOne Player and is running in startup, and is not needed. Once installed, it runs independently of RealOne Player and consumes resources. You can fix this with HJT, but you will also need to set it not to load in RealPlayer itself to keep it from resetting itself: (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK
This is the item to check mark in HJT:

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Quick launch System Tray Icon for Quicktime Player. Not needed unless you use Quicktime regularly. Will reappear every time you use the player though unless you start Quicktime player, click on Edit> Preferences> Quicktime Preferences and Uncheck 'Quicktime System Tray Icon'."
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

Close all open windows except HijackThis and then click the "Fix checked" button.

9. Reboot in safe mode.

10. Using Windows Explorer, locate the following files and delete them:
c:\windows\system32\gflerae.exe
C:\WINDOWS\Nail.exe
C:\windows\system32\elitentu32.exe
C:\Documents and Settings\?|?e\Application Data\asew.exe
Exit Explorer, and reboot as normal afterwards.

Let me know which files you could not delete and we will try to take care of them in due time.

11. Please do a search:
"Run "Start">"Search">"All Files and Folders"> enter D0CE0C16B1 in "All or part of file name". Select "More advanced options". Check-mark "Search System Folders", "Search hidden files and folders", and "Search subfolders". Click "Search". If found please right-click it and delete it. If you can not delete it make a note of the path.

Post back a fresh HijackThis log together with the results of the scans and we will take another look.
Hello Eri. Sorry but will not be avaiable for the next 25 hors. :( Will look at your answers then. No shame getting infected with Nail. One of the most common infections now. :rant2: We will discuss protection once your computer clean. Elrond :)
Hi Elrond,
Thanks for your quick reply! I followed the rest of your instructions and am posting the results.

5. Agent Ransack results:

C:\windows\LPT$VPN.635 (14605 KB, 5/19/2005 7:51:54 PM)
C:\windows\mvkjz.dll (4 KB, 5/20/2005 12:05:42 AM)
C:\windows\Nail.exe (73 KB, 4/25/2002 8:23:44 PM)
C:\windows\Q810565.log (22 KB, 6/17/2003 10:34:20 PM)
C:\windows\VPTNFILE.635 (14605 KB, 5/19/2005 7:51:54 PM)


6. RKFILES.BAT log:

C:\Documents and Settings\?|?e\?f?X?N?g?b?v

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder…………
————————
C:\WINDOWS\system32\ddcyqej.exe: UPX!
C:\WINDOWS\system32\dqaau.dll: UPX!
C:\WINDOWS\system32\elitentu32.exe: FSG!
C:\WINDOWS\system32\elitezyv32.exe: FSG!
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\MEMORY.DMP: ScannerLineupAB-Spec2-NK.lnk
C:\WINDOWS\MEMORY.DMP: pec2-N.lnk

Files Found in all users startup Folder…………
————————
C:\WINDOWS\system32\ddcyqej.exe: UPX!
C:\WINDOWS\system32\dqaau.dll: UPX!
C:\WINDOWS\system32\elitentu32.exe: FSG!
C:\WINDOWS\system32\elitezyv32.exe: FSG!
Files Found in all users windows Folder…………
————————
C:\WINDOWS\del.tmp: UPX!
C:\WINDOWS\MEMORY.DMP: UPX!-
C:\WINDOWS\svcproc.exe: UPX!
C:\WINDOWS\tsc.exe: UPX!
C:\WINDOWS\vsapi32.dll: UPX!t4
C:\WINDOWS\MEMORY.DMP: efsg!>!#ztuf#
Finished
bye


7/8. Fixed specified items (including recommendations) in HijackThis except for:
O4 - HKLM\..\Run: [fynemq] c:\windows\system32\gflerae.exe
Was not in list.

9/10. Deleted said files, but could not locate the following (windows search found nothing, too):
c:\windows\system32\gflerae.exe
C:\Documents and Settings\?|?e\Application Data\asew.exe
(FYI: in the system32 folder when deleting elitentu.exe, there were two other similar files, elitexyv.exe and another, which I didn't touch. After finishing this whole process I went back to check, and they aren't there anymore.)

11. Deleted D0CE0C16B1.dll

New HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 2:25:20 PM, on 5/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\LiquidView\lviewj.exe
C:\Program Files\MELCO INC\エアステーションユーティリティ\ABRECEIVER\ABReceiver.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
c:\windows\system32\nauuhet.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\conime.exe
C:\PROGRA~1\EzButton\DtcEMail.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\えり\デスクトップ\Hijack this\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [imjpmig] C:\Program Files\Common Files\Microsoft Shared\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe -nogui
O4 - HKLM\..\Run: [ABRECEIVER] "C:\Program Files\MELCO INC\?G?A?X?e?[?V?‡?“?†?[?e?B???e?B\ABRECEIVER\ABReceiver.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [yloqqh] c:\windows\system32\nauuhet.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitentu32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: The翻訳_ページ翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O8 - Extra context menu item: The翻訳_範囲指定翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O8 - Extra context menu item: The翻訳_翻訳設定 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O8 - Extra context menu item: The翻訳_辞書参照 - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: ???T?[?` - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra 'Tools' menuitem: The?|?o_?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra button: (no name) - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra 'Tools' menuitem: The?|?o_?≪?‘?Q?A - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: (no name) - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra 'Tools' menuitem: The?|?o_”I?I?w’e?|?o - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra button: (no name) - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra 'Tools' menuitem: The?|?o_?|?o?Y’e - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra button: ?≪?‘?o?[ - {D1A62E0C-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandTate.dll
O9 - Extra button: ?|?o?o?[ - {D1A62E0E-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandYoko.dll
O14 - IERESET.INF: START_PAGE_URL=http://dynabook.com/
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (32U?ET?A° On-Line Scan) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…271/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FA2BDEB-D689-4770-BBA0-D43FCEB1022B}: NameServer = 210.196.3.183,210.141.112.163
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks in advance for your help! And you deserve a break… please do take your time. My PC can wait a few days…

Enjoy your weekend,
Eri

PS. A quick question: Could posting these various log files on the Web make my PC vulnerable in any way?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI