This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hi, my name is Eri... I'm, err, computer-dumb

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am back again Eri.
The last round toook out some more junk and let me know where we stand. Both Nail, Qoologic and Elite toolbar are still there. It also gave me the name of some of the Qoologic and Elit Bar files that we will use in a lter post.

We will go after Elite Toolbar first using a tool developed by miekiemoes and then Nail using a fix by Swandog46 and miekiemoes

We will need some tools to get at these infections.

1. Download Pocket Killbox and unzip it; save it to your Desktop. Do not use it yet. This is a preparation for the next fix we will have to do.

2. Download this tool: http://home.filternet.nl/~hansp21/LQFix.bat
Unzip it to your Desktop.
Don't use it yet!

3. Please download the free version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files. Do NOT run a scan yet.

4. Please go to the following website
http://www.noidea.us/easyfile/file.php?download=20050515010747824 ://http://www.noidea.us/easyfile/file….50515010747824 ://http://www.noidea.us/easyfile/file….50515010747824
. Click on Spyware Utilities.
. Then click on Nail/Aurora Fix
download Nailfix.exe
Unzip it to the desktop but please do NOT run it yet.

5. Next, please reboot your computer in Safe Mode. This is important as at least one tool will not work correctly in Normal mode.

6. While in Safe Mode, Doubleclick LQfix.bat that you saved on your desktop before.
A dos window will open and close again, that is normal.

7. Still in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

7. Then please run Ewido, and run a full scan. Save the logfile from the scan.

8. Next please run HijackThis, click Scan, and put a check mark beside:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HijackThis and click Fix Checked.

9. Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

Regarding your question. No I do not believe that our work is threatning to let more junk into your computer. However the less you use it at the moment the better it is.

Elrond :)
Hi Elrond,

Welcome back. Here are the log files. (Please excuse the default Japanese lang.)
———————————————————
ewido security suite - スキャンリポート
———————————————————

+ 作成場所: 6:00:03 PM, 5/22/2005
+ レポートチェックサム: 2AB8AEFD

+ データベースの日時: 5/22/2005
+ スキャンエンジンのバージョン: v3.0

+ 期間: 173 min
+ スキャンしたファイル: 124887
+ スピード: 11.96 ファイル/秒
+ 感染ファイル: 84
+ 削除したファイル: 84
+ 保管庫のファイル: 84
+ 開くことのできないファイル: 0
+ 削除できないファイル: 0

+ 隠れプログラム Yes
+ 暗号: Yes
+ 書庫: Yes

+ スキャンしたアイテム:
C:\

+ スキャン結果:
C:\Documents and Settings\えり\Cookies\えり@atdmt[2].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Cookies\えり@doubleclick[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Cookies\えり@mediaplex[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Cookies\えり@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@ads.monster[2].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@adsremote.scripps[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@cookie.monster[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@search.msn[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@www.xzoomy[2].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Te\Cookies\えり@xiti[1].txt -> Spyware.Tracking-Cookie -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\4PAB0L67\svcproc[1].exe -> Trojan.Stervis.c -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\8BZLUN1A\DrPMon[1].dll -> Trojan.Agent.db -> バックアップ後削除
C:\Documents and Settings\えり\Local Settings\Temporary Internet Files\Content.IE5\IL2JKPQJ\Nail[1].exe -> Trojan.Nail -> バックアップ後削除
C:\Program Files\Microsoft AntiSpyware\Quarantine\28EEFF9D-35B8-4079-9794-19CF5B\1B3EF17C-008D-4EAE-A808-9181BF -> TrojanDownloader.Braidupdate.d -> バックアップ後削除
C:\Program Files\Microsoft AntiSpyware\Quarantine\73B09C0C-1B73-42D2-8CEE-D0BA40\B3502E0F-7A50-464A-B143-5D634B -> Trojan.Agent.db -> バックアップ後削除
C:\Program Files\Microsoft AntiSpyware\Quarantine\FE229109-56E6-47D3-92DF-8F5057\FB11D2B0-49C5-46F4-8225-4EB279 -> Spyware.Small.ez -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763510.dll -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763523.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763534.ax/C:/WINDOWS/System32/mscb.dll -> Spyware.BargainBuddy.i -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763534.ax/C:/Program Files/CashBack/bin/cashback.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763534.ax/C:/Program Files/CashBack/bin/cb.exe -> Spyware.CashBack.b -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763534.ax/C:/Program Files/CashBack/bin/flash.exe -> Spyware.CashBack.d -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/mqexdlm.srg -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/bbchk.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/msexreg.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763538.VXD/C:/WINDOWS/System32/exclean.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763542.idf/C:/WINDOWS/System32/msbe.dll -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763542.idf/C:/Program Files/BullsEye Network/bin/adv.exe -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763542.idf/C:/Program Files/BullsEye Network/bin/adx.exe -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/mqexdlm.srg -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/bbchk.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/msexreg.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763546.VXD/C:/WINDOWS/System32/exclean.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763742.ax/C:/WINDOWS/System32/mscb.dll -> Spyware.BargainBuddy.i -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763742.ax/C:/Program Files/CashBack/bin/cashback.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763742.ax/C:/Program Files/CashBack/bin/cb.exe -> Spyware.CashBack.b -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763742.ax/C:/Program Files/CashBack/bin/flash.exe -> Spyware.CashBack.d -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/mqexdlm.srg -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/bbchk.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/msexreg.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763746.VXD/C:/WINDOWS/System32/exclean.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763815.ax/C:/WINDOWS/System32/mscb.dll -> Spyware.BargainBuddy.i -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763815.ax/C:/Program Files/CashBack/bin/cashback.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763815.ax/C:/Program Files/CashBack/bin/cb.exe -> Spyware.CashBack.b -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763815.ax/C:/Program Files/CashBack/bin/flash.exe -> Spyware.CashBack.d -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/mqexdlm.srg -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/bbchk.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/msexreg.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763818.VXD/C:/WINDOWS/System32/exclean.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763847.idf/C:/WINDOWS/System32/msbe.dll -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763847.idf/C:/Program Files/BullsEye Network/bin/adv.exe -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763847.idf/C:/Program Files/BullsEye Network/bin/adx.exe -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763850.dll -> Spyware.BargainBuddy.n -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763856.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/exdl.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/mqexdlm.srg -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/exul.exe -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/javexulm.vxd -> Spyware.BargainBuddy.q -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/bbchk.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/msexreg.exe -> Spyware.Bargainbuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/instsrv.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\RECYCLER\NPROTECT\01763860.VXD/C:/WINDOWS/System32/exclean.exe -> Spyware.BargainBuddy -> バックアップ後削除
C:\WINDOWS\system32\Cache\VCM Q installer_282_190.exe -> TrojanDropper.Win32.Small.wc -> バックアップ後削除
C:\WINDOWS\system32\dqaau.dll -> TrojanDownloader.Qoologic.i -> バックアップ後削除
C:\WINDOWS\system32\dqobmac.exe -> TrojanDownloader.Qoologic.i -> バックアップ後削除
C:\WINDOWS\system32\sbgtryp.dll -> TrojanDownloader.Qoologic.i -> バックアップ後削除
C:\WINDOWS\system32\ynghzyz.exe -> Trojan.Agent.cp -> バックアップ後削除
C:\WINDOWS\unadbeh.exe -> TrojanDropper.Win32.Small.wc -> バックアップ後削除


::リポート終了


Logfile of HijackThis v1.99.1
Scan saved at 6:14:39 PM, on 5/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
C:\Program Files\LiquidView\lviewj.exe
C:\Program Files\MELCO INC\エアステーションユーティリティ\ABRECEIVER\ABReceiver.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\EzButton\DtcEMail.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\えり\デスクトップ\Hijack this\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [imjpmig] C:\Program Files\Common Files\Microsoft Shared\IME\IMJP\imjpmig.exe /RemAdvDef /AIMEREG /Migration /SetPreload
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe -nogui
O4 - HKLM\..\Run: [ABRECEIVER] "C:\Program Files\MELCO INC\?G?A?X?e?[?V?‡?“?†?[?e?B???e?B\ABRECEIVER\ABReceiver.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: Microsoft Excel にエクスポート(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: The翻訳_ページ翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O8 - Extra context menu item: The翻訳_範囲指定翻訳 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O8 - Extra context menu item: The翻訳_翻訳設定 - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O8 - Extra context menu item: The翻訳_辞書参照 - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: ???T?[?` - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra 'Tools' menuitem: The?|?o_?y?[?W?|?o - {D1A62E01-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_pagetran.htm
O9 - Extra button: (no name) - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra 'Tools' menuitem: The?|?o_?≪?‘?Q?A - {D1A62E07-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\ttp_showdic.htm
O9 - Extra button: (no name) - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra 'Tools' menuitem: The?|?o_”I?I?w’e?|?o - {D1A62E08-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_seltran.htm
O9 - Extra button: (no name) - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra 'Tools' menuitem: The?|?o_?|?o?Y’e - {D1A62E0A-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\addins\Ie\afi_setdlg.htm
O9 - Extra button: ?≪?‘?o?[ - {D1A62E0C-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandTate.dll
O9 - Extra button: ?|?o?o?[ - {D1A62E0E-C347-4344-A362-9BCE5FA7E31D} - C:\Program Files\TTI_V7_LE\IeTbandYoko.dll
O14 - IERESET.INF: START_PAGE_URL=http://dynabook.com/
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (32U?ET?A° On-Line Scan) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…271/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0FA2BDEB-D689-4770-BBA0-D43FCEB1022B}: NameServer = 210.196.3.183,210.141.112.163
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

How does this look? I'm not seeing popups anymore… I think we're clean!
Thanks so much.

Eri
Excellent Eri :D

The log looks clean. :)

This is IMPORTANT: You need to update your Windows. It is out of date. The version you should have at this time is Windows XP with SP2.

There have been some reports of problems with SP2 but by now you really need it.

If you have a high-speed internet connection, you can download SP2 from http://support.microsoft.com/kb/322389 .

However if you have a dialup connection I would advise you to order the CD as the download is huge and will take a VERY long time to download.
You can get the CD here .
Please inform me if you had any problems with the upgrade.


Once you have updated to SP2 there are somethings I want you to do to keep your computer clean.

Settings and maintenance

1. Clean out temporary files.
Download System Security Suite . Place the zip file into a folder of its own. Extract it to this folder. (You did this already just continue with a cleanup.)

Run System Security Suite by clicking the 3S icon in program manager.
Under "items to clear" check mark all. Then click "clear selected items"
This will cause your system to reboot.
You should do this every few weeks to avoid buildup of unnecessary junk.

Do not forget to empty Norton Protected Recycle bin.

2. Clean Out System Restore.
Malware could get backed up in System Restore.
For Win XP follow these instructions to delete all restore points.
a. Go to "Start" > "Control Panel".
b. Make sure the Control Panel is in "Classic View". If it is not, click "Switch to Classic View" towards the top-left of the screen.
c. Double-click "System" and go to the "System Restore" tab.
d. Check "Turn off System Restore" and click "OK" and then "Yes".

After restarting your computer you should turn it back on by following the above procedure and uncheck "Turn off System Restore".

You can find out more about this subject at
How to turn off or turn on Windows XP System Restore

3. You reconfigured Windows to show hidden files and you should reset this to its original state using the instructions from here except that
1. Under the "Hidden files and folders" heading put a mark for "Do not show hidden files and folders".
2. Uncheck "Display content of system folders"
3. Check the "Hide protected operating system files (recommended)" option.

4. Make your Internet Explorer more secure

a. Less restrictive but less secure:
Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more in
Internet Explorer Privacy & Security Settings
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you don't have to use it. Try a different browser like
Firefox . It is also worth trying
Thunderbird for controlling spam in your e-mail.

b. More secure but very restrictive.
This can be done by following these simple instructions that apply to all "Windows" except "Windows XP with SP2". In SP2 many of those setting are the default settings but check your settings anyhow. The settings can become restrictive but you should use them anyhow. If there are sites that will not show up right with those settings and that you rely on to be free of malware place them in the trusted zone.

1. Click "Start". Open "Control Panel".
2. Select the "Internet Options"
3. Select "Security" Tab and select the following settings.

* ActiveX controls and plug-ins
• Download signed ActiveX controls: Disable
• Download unsigned ActiveX controls: Disable
• Initialize and script ActiveX controls not marked as safe: Disable
• Run ActiveX controls and plug-ins: Disable
• Script ActiveX controls marked safe for scripting: Disable

* Downloads
• Font Download: Disable

* Microsoft VM
• Java permissions: Disable Java

* Miscellaneous
• Allow META REFRESH: Disable
• Display mixed content: Disable
• Drag and drop or copy and paste files: Disable
• Installation of desktop items: Disable
• Launching programs and files in an IFRAME: Disable
• Navigate sub-frames across different domains: Disable
• Software channel permissions: High Safety
• Userdata persistence: Disable

* Scripting
• Active scripting: Disable
• Allow paste operations via script: Disable
• Scripting of Java applets: Disable

* User Authentication
• Logon: Prompt for username and password
4. When all these settings have been made, click on the OK button.
5. If it prompts you as to whether or not you want to save the settings, press the Yes button.
6. Next press the Apply button and then the OK to exit the Internet Properties page.


These are a MUST to protect yourself from malware.
5. Always use a good anti-virus..
KEEP IT UPDATED

6. Always use a good firewall.
Be restrictive with access to the internet. If you are unsure if the program really needs the access, test it by denying the access and see if this has any negative effects. If not make the block permanent.

Never run two Antivirus programs or two Firewalls at the same time. The can interfere with each other and cause problems.

Download and install “SpywareBlaster” and "SpywareGuard".

You will find the addresses for the programs that I recommend at this website . It is important that you go to there. It is good source of information about computer security. It will give you recommendations for more security tools as well as tips about how to stay clean on the internet. PLEASE FOLLOW THE RECOMENDATIONS TO PROTECT YOURSELF.

7. MOST IMPORTANT for all versions: You Need to keep “Windows” and "Internet Explorer” updated. Open ‘Internet Explorer” and go to”Start”> "Tools" > "Windows Update" or go to Microsoft Windows and Internet Explorer Updates to get the critical updates.

8.If you are running Microsoft Office, or any portion thereof you must keep it updated as well. Go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed. Update MS Office here.

9. Keep your programs updated.

10. It is worth while to take a look at "So how did I get infected in the first place? for some good advice.

VERY IMPORTANT. Update all protective programs regularly - Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow these recommendations and your potential for being infected again will be dramatically reduced.

Do you have any problems with your computer? If so please post the details.

It has been a pleasure helping you. (Bowing Deeply)

Best of luck and clean computing

Elrond :)
Dear Elrond, Yes! The PC is running great and I will be sure to follow all your preventative measures to make sure it stays that way. I am amazed with the Tom Coyote community here… really do appreciate all your help. Many, many thanks from Tokyo, Eri
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI