This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help please =(

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 4:09:13 PM, on 5/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Scotts\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
Hello , welcome to the TC.


I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe

O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)

O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"

Open C:\WINDOWS\wkssvc.exe <–Delete file if listed.

Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.
Virus detection window keeps popping up still for win32/Parite… (nonstop) cannot heal files. so i just leave the box on screen and move it to the edge. other then that i can tell there is significant slow down.


Logfile of HijackThis v1.99.1
Scan saved at 4:34:08 PM, on 5/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Scotts\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Please do NOT run a scan yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.



Then please run Ewido security suite, and perform a full scan. Remove anything found, and please save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan
ok its running in safe mode fully updated.. its going very slow so it appears it may take several hours to complete… took like 10 minutes or more to get to 2% scanned. ill post both scans when its done, which will prolly be late tonight or in the morning. thanks for the help so far.. talk to you soon
that scan cleaned half of them i think… found 78 total. here are both logs:


Logfile of HijackThis v1.99.1
Scan saved at 9:19:58 PM, on 5/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Documents and Settings\Scotts\My Documents\hjt and backup fiels\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE











———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 9:17:10 PM, 5/29/2005
+ Report-Checksum: 26064622

+ Date of database: 5/29/2005
+ Version of scan engine: v3.0

+ Duration: 239 min
+ Scanned Files: 272958
+ Speed: 19.02 Files/Second
+ Infected files: 78
+ Removed files: 41
+ Files put in quarantine: 41
+ Files that could not be opened: 0
+ Files that could not be cleaned: 37

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\
C:\

+ Scan result:
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@bfast[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@zedo[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\C123SHUJ\downloaddll[1].htm -> Spyware.DealHelper.ab -> Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5YF0PAN\download[1].htm -> Trojan.Popmon.a -> Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5YF0PAN\MediaAccC[1].dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\7F44C8ED-D602-4B90-89B4-0F4759\461B25F1-1B06-4FD8-8FB3-3704AA -> Spyware.SideFind -> Cleaned with backup
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\9CCB45DD-7829-4A7E-A40E-B2B8CA -> Spyware.Wintol.y -> Cleaned with backup
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\DEE699F7-05CF-4EAF-984F-A36B93 -> TrojanDownloader.Wintool.e -> Cleaned with backup
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\FA0B1C27-867B-412E-898A-599035 -> Spyware.Wintol.y -> Cleaned with backup
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\E10C53E4-E7C2-4E90-BCF8-838404\0AFDB1C7-F082-4C47-8BD6-E486DB -> Spyware.POP.dl -> Cleaned with backup
C:\Documents and Settings\Scotts\Local Settings\Temp\temp.frBF8D\MediaAccC.dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\hh.exe/re11.REG -> Trojan.LowZones.a -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnUS10.exe -> Dialer.Generic -> Cleaned with backup
C:\WINDOWS\hosts -> Trojan.Qhost.k -> Cleaned with backup
C:\WINDOWS\system32\6toim.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\adptwiz.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\bbchk.exe -> Spyware.Bargainbuddy -> Cleaned with backup
C:\WINDOWS\system32\instsrv.exe -> Spyware.BargainBuddy -> Cleaned with backup
C:\WINDOWS\system32\psapcsvc.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\rdriv.sys -> Trojan.Rootkit.k -> Cleaned with backup
C:\WINDOWS\system32\rds_hp.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\resochk.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\Temp\Del1C.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\WINDOWS\Temp\Del32.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\WINDOWS\Temp\DelC0.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\WINDOWS\Temp\iinstall.exe -> TrojanDownloader.IstBar.jj -> Cleaned with backup
C:\WINDOWS\Temp\res1D.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\WINDOWS\Temp\res33.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\WINDOWS\Temp\xxa1A.tmp/re11.REG -> Trojan.LowZones.a -> Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Cookies\system@bfast[1].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Cookies\system@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Cookies\system@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Cookies\system@zedo[2].txt -> Spyware.Tracking-Cookie -> Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\C123SHUJ\downloaddll[1].htm -> Spyware.DealHelper.ab -> Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5YF0PAN\download[1].htm -> Trojan.Popmon.a -> Error during cleaning
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5YF0PAN\MediaAccC[1].dll -> Spyware.WinAD.ag -> Error during cleaning
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\7F44C8ED-D602-4B90-89B4-0F4759\461B25F1-1B06-4FD8-8FB3-3704AA -> Spyware.SideFind -> Error during cleaning
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\9CCB45DD-7829-4A7E-A40E-B2B8CA -> Spyware.Wintol.y -> Error during cleaning
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\DEE699F7-05CF-4EAF-984F-A36B93 -> TrojanDownloader.Wintool.e -> Error during cleaning
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\8EB77348-3F81-42C1-94D0-FDF513\FA0B1C27-867B-412E-898A-599035 -> Spyware.Wintol.y -> Error during cleaning
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\Quarantine\E10C53E4-E7C2-4E90-BCF8-838404\0AFDB1C7-F082-4C47-8BD6-E486DB -> Spyware.POP.dl -> Error during cleaning
C:\Documents and Settings\Scotts\Local Settings\Temp\temp.frBF8D\MediaAccC.dll -> Spyware.WinAD.ag -> Error during cleaning
C:\hh.exe/re11.REG -> Trojan.LowZones.a -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\Downloaded Program Files\gdnUS10.exe -> Dialer.Generic -> Error during cleaning
C:\WINDOWS\hosts -> Trojan.Qhost.k -> Error during cleaning
C:\WINDOWS\system32\6toim.exe -> Trojan.AproposAd -> Error during cleaning
C:\WINDOWS\system32\adptwiz.exe -> Trojan.AproposAd -> Error during cleaning
C:\WINDOWS\system32\bbchk.exe -> Spyware.Bargainbuddy -> Error during cleaning
C:\WINDOWS\system32\instsrv.exe -> Spyware.BargainBuddy -> Error during cleaning
C:\WINDOWS\system32\psapcsvc.exe -> Trojan.AproposAd -> Error during cleaning
C:\WINDOWS\system32\rdriv.sys -> Trojan.Rootkit.k -> Error during cleaning
C:\WINDOWS\system32\rds_hp.exe -> Trojan.AproposAd -> Error during cleaning
C:\WINDOWS\system32\resochk.exe -> Trojan.AproposAd -> Error during cleaning
C:\WINDOWS\Temp\Del1C.tmp -> TrojanDownloader.Small.asf -> Error during cleaning
C:\WINDOWS\Temp\Del32.tmp -> TrojanDownloader.Small.asf -> Error during cleaning
C:\WINDOWS\Temp\DelC0.tmp -> TrojanDownloader.Small.asf -> Error during cleaning
C:\WINDOWS\Temp\iinstall.exe -> TrojanDownloader.IstBar.jj -> Error during cleaning
C:\WINDOWS\Temp\res1D.tmp -> Spyware.180Solutions -> Error during cleaning
C:\WINDOWS\Temp\res33.tmp -> Spyware.180Solutions -> Error during cleaning
C:\WINDOWS\Temp\xxa1A.tmp/re11.REG -> Trojan.LowZones.a -> Cleaned with backup


::Report End
Delete these files if listed

C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS10.exe
C:\WINDOWS\system32\6toim.exe
C:\WINDOWS\system32\adptwiz.exe
C:\WINDOWS\system32\bbchk.exe g
C:\WINDOWS\system32\instsrv.exe
C:\WINDOWS\system32\psapcsvc.exe
C:\WINDOWS\system32\rdriv.sys
C:\WINDOWS\system32\rds_hp.exe
C:\WINDOWS\system32\resochk.exe


Delete all files in these folders
Open C:\WINDOWS\Temp\ <–Delete all Files
Open C:\Documents and Settings\LocalService\Cookies\<–Delete all Files


Run MS AntiSpyware and empty the Quarantined files


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I could not find any of the files from the top of your post.

I did delete all the files in:
C:\WINDOWS\Temp\ <–Delete all Files
C:\Documents and Settings\LocalService\Cookies\<–Delete all Files
(over 24,000 files)

MS antispyware had no files remaining in the quarantine.

Recycle bin was then emptied.

Rebooted to normal mode. I think its still a bit slow but hard to say because i cant do much. All my usual programs are still unusable. the error comes up that "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."

On reboot MS antispyware did detect a new web browser trying to install to IE… i blocked it. Then MS antispyware detected something trying to change my IE intranet security settings to low which i blocked as well.

Ewido had a window pop up when i opened the program.. it said that at least one file was changed or damaged and to run an update to repair any files. Which i could NOT do since i cannot access the internet on the infected computer still.

so… here is the latest hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 12:42:32 AM, on 5/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Scotts\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe
O23 - Service: ewido security suite control - Unknown owner - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - Unknown owner - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe
O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Documents and Settings\Scotts\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

Important: Do this before this fix. We need to remove ALL temp files / folders.

Please put your HijackThis in it's own folder, (I create a new folder in C:\ named HJT).
You can do a Right Click on any open area on the desktop, New> Folder, then rename the folder HJT.

Go to where your HijackThis is and Right Click on HijackThis.exe, select Cut, then open the new folder you just created (HJT) Right Click in the folder and select paste.

Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED Profile USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

On the computer that has internet working:
Download LSPfix here: http://www.cexx.org/lspfix.htm
Download LSP fix and put the file on a floppy or cd.
Make sure you get the LSPFix.exe and Not the .Zip

Check the Box I know what i'm doing, then click finish



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
ok did all that

the lsp fix did not appear to do anything but i just checked the box and hit finish.

here is the new log post reboot



Logfile of HijackThis v1.99.1
Scan saved at 10:09:35 AM, on 5/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Hijack This\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe
O23 - Service: ewido security suite control - Unknown owner - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - Unknown owner - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe
O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
it doesnt matter what program i try to run i get the same message. The message you get when trying to run anything is: " Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." the isp file C:\Program Files\Verizon Online\VOLSW\Verizon Online.exe has been infected by W32\Parite AVG was also taken over and unusable so i just reinstalled it from the CD i made but lacks the updates. It is popping windows up nonstop about W32\Parite infections. I couldnt even uninstall AVG in Add/Remove programs at first, i had to manually delete the exe files that were infected then do the uninstall with add/remove programs. Then reinstalling it worked fine but is lacking the updates. WinsockxpFix did make some changes to the registry apparently but still getting the same problem with that exe file to start my isp dialer… i thought maybe i could copy that exe file from this computer and try it on that one or try reinstalling the dialer/modem completely. That was the only way i got any of my other programs to work again.
while waiting for your reply i swapped 3 exe files for my isp from the working computer to replace the 3 infected. it worked and im connected now on this infected one… but it may get reinfected again as other programs have been.. im running that exe fix you posted now… then while i wait for your response im going to run the online panda active scan again since last time you asked me too i had no internet access. ill let you know if the exe files get fixed also..

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI