This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please help, I'm going insane!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I'm new to the forum, please forgive any mistakes. I've been trying to remove these malware for days now. every time I think I have it licked, it comes right back. please help, I don't think I can take much more. :rant:

Thanks for your help,
DTF

Logfile of HijackThis v1.99.1
Scan saved at 12:04:50 PM, on 5/22/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\catntutl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\c_itext.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\DEFEND~1\DEFEND~1\PopUp.dll
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsy1C.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eqddic] c:\windows\system32\eqddic.exe
O4 - HKLM\..\Run: [3IqiQUA] C:\WINDOWS\tqqqbufs.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [nzclbyc] c:\windows\system32\inzknl.exe
O4 - HKLM\..\Run: [sFrT38U] catntutl.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [do03RUYnR] c_itext.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Hello,

It's me again. Since my last post I have run EMCO malware bouncer. It seems to have cured the problem. Just in case though, her is my new hjt file.

Thanks again,
DTF <_<

Logfile of HijackThis v1.99.1
Scan saved at 9:04:01 PM, on 5/22/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\catntutl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\c_itext.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\DEFEND~1\DEFEND~1\PopUp.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eqddic] c:\windows\system32\eqddic.exe
O4 - HKLM\..\Run: [3IqiQUA] C:\WINDOWS\tqqqbufs.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [nzclbyc] c:\windows\system32\inzknl.exe
O4 - HKLM\..\Run: [sFrT38U] catntutl.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [do03RUYnR] c_itext.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Hello,

I followed all steps except for the panda virus scan. the parental controls on my computer blocked it as obscene. Is there another option? Here is my new hjt log.

Thanks again for your help,

DTF
Logfile of HijackThis v1.99.1
Scan saved at 12:48:51 PM, on 5/28/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\lfpstr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\javawex.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eqddic] c:\windows\system32\eqddic.exe
O4 - HKLM\..\Run: [3IqiQUA] C:\WINDOWS\tqqqbufs.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [nzclbyc] c:\windows\system32\inzknl.exe
O4 - HKLM\..\Run: [sFrT38U] lfpstr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [do03RUYnR] javawex.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Scan with hijackthis and put a check beside these lines and choose FIX

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [eqddic] c:\windows\system32\eqddic.exe
O4 - HKLM\..\Run: [3IqiQUA] C:\WINDOWS\tqqqbufs.exe
O4 - HKLM\..\Run: [nzclbyc] c:\windows\system32\inzknl.exe
O4 - HKLM\..\Run: [sFrT38U] lfpstr.exe
O4 - HKCU\..\Run: [do03RUYnR] javawex.exe

O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)


Then reboot and post a new log please. You can try online virus scans here

Trend Micro http://housecall.antivirus.com/

E Trust http://www3.ca.com/virusinfo/virusscan.aspx

Rav http://www.ravantivirus.com/scan/

Pc Pitstop http://www.pcpitstop.com/antivirus/AV.asp

Panda http://www.pandasoftware.com/activescan/co…n_principal.htm

Bitdefender http://www.bitdefender.com/scan/Msie/index.php
Thanks for getting back to me so fast. Here's my new HJT log.

Thank you,

DTF
Logfile of HijackThis v1.99.1
Scan saved at 4:58:50 PM, on 5/28/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
It seemed to run fine. However, Microsoft antispyware runs a scan every night, and when I checked it this morning it had found the same spyware it has been finding for the past few day. Now there is also a possible browser hijack. sorry to keep bothering you. I thank you for the help. here's a new hjt log.

DTF

Logfile of HijackThis v1.99.1
Scan saved at 7:05:50 AM, on 5/29/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Hello, I forgot to mention the names of the spyware. I'm just going from my memory here, so forgive any mistakes. Apropos Ist people on page I hope this helps some. let me know if you need any more information. A million thanks, DTF
Download MicroWorld virus scan here >>> Micro World http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added) then click on scan clean. When the scan is complete hilight all the files in the LOWER box. Then ctrl + c and paste them into the thread ctrl + v.

I warn you the scan will take a long time to run and will not fix anything just identifies bad files.
Here is MW log. WOW! What a mess! :o In your debt, DTF Object "IBIS Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "HuntBar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "mxoaldr Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\YSBactivex.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\msxml3a.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\plugincpl131.cpl". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\MSPress\Training\lsingle.CNT". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Air&car.ab2". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Gvtoffcl.ab2". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Health.ab2". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Hotels.ab2". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Majcorps.ab2". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Broderbund\UMM\Print60.dat". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\YSBactivex.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C370527A-24A7-4583-BE01-72E59000EB17}" refers to invalid object "C:\WINDOWS\system32\n.dll". Action Taken: No Action Taken. Entry "HKCR\PopUp.xpTuner Pro" refers to invalid object "{49E0E0F0-5C30-11D4-945D-000000000003}". Action Taken: No Action Taken. Entry "HKCR\ToolBand.ToolBandHelper" refers to invalid object "{441354C5-911B-409B-9A66-A11D6D4E1A22}". Action Taken: No Action Taken. Entry "HKCR\ToolBand.ToolBandHelper.1" refers to invalid object "{441354C5-911B-409B-9A66-A11D6D4E1A22}". Action Taken: No Action Taken. File C:\WINDOWS\cpbrkpie.ocx tagged as "not-a-virus:AdWare.Coupons". Action Taken: No Action Taken. File C:\WINDOWS\ddnkzsf.exe tagged as "not-a-virus:AdWare.BetterInternet.c". Action Taken: No Action Taken. File C:\WINDOWS\Nail.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken. File C:\WINDOWS\System32\javawex.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\WINDOWS\System32\lfpstr.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\WINDOWS\System32\nsy1C.dll tagged as "not-a-virus:AdWare.ToolBar.HotSearchBar.g". Action Taken: No Action Taken. File C:\WINDOWS\System32\ps1.exe tagged as "not-a-virus:AdWare.Pacer.h". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\Temp\1.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\Temp\Del34.tmp tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\Temp\drp4D.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\Temp\drp98.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\Temp\drp9E.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\TEMPOR~1\Content.IE5\M3YF46HE\a072aa[1].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken. File C:\DOCUME~1\Tanya\LOCALS~1\TEMPOR~1\Content.IE5\YL7SXO3M\a072aa[1].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temp\1.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temp\Del34.tmp tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temp\drp4D.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temp\drp98.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temp\drp9E.tmp\thnall2c.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temporary Internet Files\Content.IE5\M3YF46HE\a072aa[1].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\Tanya\Local Settings\Temporary Internet Files\Content.IE5\YL7SXO3M\a072aa[1].js infected by "Trojan-Downloader.JS.Small.aq" Virus! Action Taken: No Action Taken. File C:\Program Files\Broderbund\The Print Shop\Unlock\SSD\SS4DlxDl.EXE tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\Program Files\Windows Media Player\wmplayer.exe.tmp tagged as "not-a-virus:AdWare.Pacer.e". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP144\A0024628.exe infected by "Trojan.Win32.Dialer.dw" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP147\A0025844.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP147\A0025885.exe tagged as "not-a-virus:AdWare.Pacer.e". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025926.exe tagged as "not-a-virus:AdWare.Wintol.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025927.exe infected by "Trojan-Downloader.Win32.Apropo.ab" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025928.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025929.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025930.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025931.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025932.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025933.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025934.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025935.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025936.exe tagged as "not-a-virus:AdWare.BookedSpace.e". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025939.exe infected by "Trojan.Win32.Stervis.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025941.exe infected by "Trojan-Downloader.Win32.VB.eu" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025946.dll tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025958.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025959.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025977.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025981.exe infected by "Trojan-Downloader.Win32.Apropo.ab" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0025983.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026045.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026069.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026070.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026071.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026073.exe infected by "Trojan-Downloader.Win32.Intexp.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026175.exe infected by "Trojan.Win32.Stervis.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026176.exe tagged as "not-a-virus:AdWare.BetterInternet.c". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026177.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026178.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026218.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026224.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026226.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026228.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026229.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026243.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026244.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026246.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026247.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026254.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026255.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026256.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026259.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026290.exe tagged as "not-a-virus:AdWare.BookedSpace.e". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026291.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026292.exe infected by "Trojan-Downloader.Win32.Adload.a" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026293.exe tagged as "not-a-virus:AdWare.ToolBar.HotSearchBar.g". Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026295.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026302.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026309.exe infected by "Trojan-Downloader.Win32.Small.aly" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026312.dll infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026313.exe infected by "Trojan.Win32.Registrator.b" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026334.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP148\A0026335.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP149\A0026533.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP149\A0026534.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026577.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026578.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026579.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026580.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026586.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026587.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026588.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026589.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026590.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026591.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026592.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP152\A0026593.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026643.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026644.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026645.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026646.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026647.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026648.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026649.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026650.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026682.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026683.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026684.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026685.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026689.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026690.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026691.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026692.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026693.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026694.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026695.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP154\A0026696.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026736.exe infected by "Trojan.Win32.StartPage.yq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026738.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026739.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026817.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026818.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026819.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026820.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026821.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026822.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026823.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{1DF014E9-2A7C-4277-BD8A-14E12CE58FD5}\RP156\A0026824.dll infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\WINDOWS\cpbrkpie.ocx tagged as "not-a-virus:AdWare.Coupons". Action Taken: No Action Taken. File C:\WINDOWS\ddnkzsf.exe tagged as "not-a-virus:AdWare.BetterInternet.c". Action Taken: No Action Taken. File C:\WINDOWS\Nail.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken. File C:\WINDOWS\system32\javawex.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\lfpstr.exe infected by "Trojan.Win32.Pakes" Virus! Action Taken: No Action Taken. File C:\WINDOWS\system32\nsy1C.dll tagged as "not-a-virus:AdWare.ToolBar.HotSearchBar.g". Action Taken: No Action Taken. File C:\WINDOWS\system32\ps1.exe tagged as "not-a-virus:AdWare.Pacer.h". Action Taken: No Action Taken.
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please go to the following website
http://www.noidea.us/easyfile/file.php?dow…050515010747824
. Click on Spyware Utilities.
. Then click on Nail/Aurora Fix
download Nailfix.exe
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml



Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Hello,

Sorry it took so long to get back to you, I just got home from work. I am posting the two logs requested. I also wanted to mention an error I'm getting every time I reboot. It says:

RUNDLL

Error loading C:\WINDOWS\cfgmgr52.dll
The specified module could not be found.

I don't know this helps, I just thought I would mention it.
below are the two log files you need.

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 5:54:43 PM, 5/31/2005
+ Report-Checksum: 4E2BE602

+ Date of database: 5/31/2005
+ Version of scan engine: v3.0

+ Duration: 92 min
+ Scanned Files: 131282
+ Speed: 23.64 Files/Second
+ Infected files: 36
+ Removed files: 36
+ Files put in quarantine: 36
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\Documents and Settings\Tanya\Cookies\tanya@71875316[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@bannerspace[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@burstnet[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@dcskqeg2voifwznnd6alhtnei_8f3u[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@geocities[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@gostats[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@lancelot_google[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@link[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@network[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@S129915[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\[removed][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Cookies\tanya@xiti[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Tanya\Local Settings\Temp\Del34.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\Documents and Settings\Tanya\Local Settings\Temp\drp4D.tmp\thnall2c.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Tanya\Local Settings\Temp\drp98.tmp\thnall2c.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Tanya\Local Settings\Temp\drp9E.tmp\thnall2c.exe -> Spyware.BetterInternet -> Cleaned with backup
C:\Documents and Settings\Tanya\Local Settings\Temporary Internet Files\Content.IE5\NQ8ZZPOT\1x1pixel[1].gif -> TrojanDownloader.Agent.am -> Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\A3031878-47B7-4053-9DF8-B36C50\61531003-30EE-4E81-AD4C-29C815 -> TrojanDownloader.IstBar.jm -> Cleaned with backup
C:\Program Files\Windows Media Player\wmplayer.exe.tmp -> Spyware.Pacer.e -> Cleaned with backup
C:\temp\optimize.exe -> TrojanDownloader.Dyfuca.dx -> Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace -> Cleaned with backup
C:\WINDOWS\cpbrkpie.ocx -> Spyware.Coupons -> Cleaned with backup
C:\WINDOWS\system32\bszip.dll -> Worm.Wurmark.c -> Cleaned with backup
C:\WINDOWS\system32\javawex.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\lfpstr.exe -> Trojan.AproposAd -> Cleaned with backup
C:\WINDOWS\system32\nsy1C.dll -> Spyware.HotBar -> Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 6:04:09 PM, on 5/31/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centurytel.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
Scan with hijackthsi and put a heck beside these lines and choose FIX

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html

O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun

O16 - DPF: {2564B8E6-7D84-11D4-A689-30475BC10000} (Tkweb Control) - http://www.toolkitcma.com/tkweb/tkweb.cab

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
Then reboot and post a new log please.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI