This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 7:47:05 PM, on 6/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\David_2\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKLM\..\RunOnce: [GIANTAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [irfw] C:\PROGRA~1\COMMON~1\irfw\irfwm.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\David\Desktop\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.addictivetechnologies.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.c4tdownload.com (HKLM)
O15 - Trusted Zone: *.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.megapornix.com (HKLM)
O15 - Trusted Zone: *.overpro.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119829779026
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/lo…3/bin/imvid.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

In the past I've been able to clean these myself but this is a particularly nasty case. I get get most of the trusted zones to clear but not crazywinnings.com, it just reappears. And windows update shows it needs about 10 security updates but they all fail to install, I think because the bad stuff takes over during the download.
Hello chipper1234, Welcome to TomCoyote forum. Sorry to keep you waiting, the site is very busy right now. It looks like you have the SpySheriff infection: O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
Thanks to bananafanafo and others I am sure who worked hard to provide a fix. Please follow these directions:

Download DelDomains: http://www.mvps.org/winhelp2002/DelDomains.inf
Save the file to the desktop.
Then go to the desktop, right click on DelDomains.inf, and choose Install.
You may not see any noticeable changes or prompts; this is normal.
**Note** This will remove all entries in the "Trusted Zone"

Note that since the Restricted Domains are deleted by this fix, SpywareBlaster protection must be re-enabled. Spybot's Immunize feature must be used again, and you will also have to re-install IE-SpyAd if installed.

______________________________________________________________

First, download and install CleanUp! but do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Download, install, and update Ewido Security Suite
  • Install ewido security suite
  • Launch ewido, there should be a big E icon on your desktop, double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
After the updates are installed, exit Ewido

Reboot into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options…"
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Scan local drives for temporary files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

After Cleanup! is finished:
  • Run Ewido
  • Click on scanner
  • Click Complete System Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean the first infected file it finds. Choose "clean", then put a check next to "Perform action on all infections" in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
  • Exit Ewido
Reboot into normal mode.

Go to Start > Control Panel > Add or Remove Programs and remove the following:

SpySheriff

Exit Add or Remove Programs.

Delete the following, in bold, if found:

C:\Documents and Settings\user account\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\user account\Application Data\Install.dat
C:\Program Files\SpySheriff <-whole folder
C:\Windows\Desktop.html
C:\winstall.exe

*NOTE* user account is not the actual name of that folder. The name of that folder will be the name of your computer profile.

Make sure you are disconnected from the Internet and that all programs and windows are closed. Run HiJackThis. Place a check next to the following items, if found, and click FIX CHECKED:


O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [irfw] C:\PROGRA~1\COMMON~1\irfw\irfwm.exe
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.addictivetechnologies.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.c4tdownload.com (HKLM)
O15 - Trusted Zone: *.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.megapornix.com (HKLM)
O15 - Trusted Zone: *.overpro.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)


Close HiJackThis.

RIGHT-CLICK HERE and go to Save As (in IE it's "Save Target As") in order to download the smitfraud reg to your desktop.

Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES.

After the merged successfully prompt, using Windows Explorer, navigate to the following folder:

C:\Windows\Prefetch

If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.)

Reboot your computer.

You should be able to change your desktop back to normal now.

Post the report from Ewido and a new HiJackThis log into this topic.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
I think you did it, but take a look to be sure. Thanks ever so much.

Logfile of HijackThis v1.99.1
Scan saved at 4:36:50 PM, on 7/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~1\MssCli.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\David_2\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\MssCli.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\David\Desktop\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1119829779026
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yimg.com/download.games.y…ctl_0_0_0_1.ocx
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {EE5CA45C-BFAC-48E6-BE6C-3C607620FF43} (IMViewerControl Class) - http://companion.logitech.com/companion/lo…3/bin/imvid.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - McAfee, Inc. - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 6:21:45 AM, 7/6/2005
+ Report-Checksum: 67E6CEE4

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{244D13BB-AFDB-11CE-85D1-00AA00695286} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{31CA5C07-7F5F-4502-8C77-99A91558ADD0} -> Spyware.TX4 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{4BB35A55-A91A-11CF-BA7C-00A0D1001A5A} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6B1BE803-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6B1BE807-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9DD19D39-2CDC-465B-BB21-1D433590BA3D} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F2A97FA2-714D-11CF-BA24-00A0D1001A5A} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{09CA52B3-703C-4B17-9690-C13F736E3DCD} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{223A26D8-9F91-42F6-8ED3-094B637DE020} -> Spyware.TX4 : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{6B1BE80A-567F-11D1-B652-0060976C699F} -> Spyware.BonziBuddy : Cleaned with backup
HKLM\SOFTWARE\DelFin -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\DelFin\PromulGate -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\LQ -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Security -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Enum -> Spyware.iSearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-21-1486478962-767898397-3041321373-1010\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1486478962-767898397-3041321373-1010\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{999A06FF-10EF-4A29-8640-69E99882C26B} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-1486478962-767898397-3041321373-1010\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A0269420-A638-4509-889C-8FC3CC85DA7E} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1486478962-767898397-3041321373-1010\Software\Support Software -> Spyware.NetworkEssentials : Cleaned with backup
HKU\S-1-5-21-1486478962-767898397-3041321373-1010\Software\Support Software\Params -> Spyware.NetworkEssentials : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C1-189F-421A-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{014DA6C9-189F-421A-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
C:\Documents and Settings\David\Cookies\david@66.220.17[2].txt -> Spyware.Cookie.66.220.17.154 : Cleaned with backup
C:\Documents and Settings\David\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\David\Cookies\[removed][1].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\David\Cookies\[removed][1].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\!update.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\180sainstaller.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\bmdlifmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\bw.exe -> TrojanDropper.Small.of : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\cfnpgmnd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\cpjopdod.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\eaccel_downloads\station_setup.exe -> Spyware.eAcceleration : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\jecafgmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\jgdopcmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\kifbhgmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temp\lidkmgmd.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\0DMJ0HUF\bridge-c22[1].cab/BridgeX.dll -> TrojanDownloader.Briss.a : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\7JTZB500\mtrslib2[1].js -> TrojanDownloader.Small : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CDIBOHAJ\popcaploader_v6[1].cab/PopCapLoader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CR7Z6SXL\rdgUS1742[1].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CR7Z6SXL\rdgUS1742[2].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CR7Z6SXL\rdgUS1742[3].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\CR7Z6SXL\rdgUS1742[4].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[2].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[4].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[5].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[6].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[7].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\rdgUS1742[8].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\EBIB29YV\serv[1].exe -> TrojanDropper.Agent.mm : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ID5MFEXO\stubinstaller4292[1].exe -> TrojanDownloader.Small.asf : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ID5MFEXO\ZangoInstaller[1].exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ID5MFEXO\ZangoInstaller[2].exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ID5MFEXO\ZangoInstaller[3].exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\ID5MFEXO\ZangoInstaller[4].exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\IJVXSDRF\dba[1].exe -> TrojanDropper.Agent.mm : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\IJVXSDRF\rdgUS1742[1].exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\M1M5GDE7\ZangoInstaller[1].exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MTZG58JU\rdgUS1742[1].exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MTZG58JU\rdgUS1742[2].exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\MTZG58JU\rdgUS1742[3].exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\NZHFJLGO\rdgUS1742[1].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\Local Settings\Temporary Internet Files\Content.IE5\OTSZC3WJ\ss_sscanner[1].exe -> TrojanDownloader.Wren.i : Cleaned with backup
C:\Documents and Settings\David\podrnodzone.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\David\sefe.exe -> Not-A-Virus.Hoax.Renos.a : Cleaned with backup
C:\Documents and Settings\David\sefer.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\David_2\convert.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\David_2\sefe.exe -> Not-A-Virus.Hoax.Renos.a : Cleaned with backup
C:\Documents and Settings\David_2\sex2.exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Katrina\Cookies\[removed][1].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk34.EXE/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk34.EXE/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk4.EXE/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk4.EXE/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk5.EXE/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk5.EXE/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk6.EXE/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temp\wnk6.EXE/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\exitpop[1].php -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\msvwinst[1].exe/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\msvwinst[1].exe/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\exitpoplight[1].php -> Trojan.NoClose.i : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\OT2JQP0H\msvwinst[1].exe/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Katrina\Local Settings\Temporary Internet Files\Content.IE5\OT2JQP0H\msvwinst[1].exe/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temp\bw.exe -> TrojanDropper.Small.of : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temp\FzTkUZ.dll -> Adware.MidADle : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temp\MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temp\wnk2d.EXE/MSView.dll -> Trojan.KeyHost.e : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temp\wnk2d.EXE/MSVprep.exe -> Spyware.BiSpy : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temporary Internet Files\Content.IE5\CT67412F\AppWrap[1].exe -> TrojanDropper.Small.of : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temporary Internet Files\Content.IE5\CT67412F\AppWrap[3].exe -> TrojanDropper.Small.of : Cleaned with backup
C:\Documents and Settings\Sue\Local Settings\Temporary Internet Files\Content.IE5\CT67412F\popinst[1].exe/monpop.exe -> Spyware.AproposMedia : Cleaned with backup
C:\Documents and Settings\Sue\protect.exe -> TrojanDownloader.Agent.nr : Cleaned with backup
C:\Documents and Settings\Sue\sefe.exe -> Not-A-Virus.Hoax.Renos.a : Cleaned with backup
C:\Documents and Settings\Sue\sefer.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\ed.exe -> TrojanDropper.Agent.mm : Cleaned with backup
C:\Program Files\Common Files\irfw\irfwp.exe -> Spyware.Xupiter : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\02DDF9F2-B864-4575-8BB9-83C43F\48FED344-214A-4022-83A1-FEE85D -> Spyware.SearchIt : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\08FBE4D8-56C4-4985-AE57-97CD12\98E1DEFB-9296-4B30-893A-D6CC97 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\08FBE4D8-56C4-4985-AE57-97CD12\FC742DC5-4E3C-43A8-B8D3-9C289E -> Spyware.HotSearchBar : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0EE37708-6638-48B3-BFBA-54BC83\2252B595-3EFF-44BC-A44F-30EA10 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\0F5B599D-98E2-49CE-B4DD-7FBF7E\80C52C6F-841C-4C8B-AB95-5F4922 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\18BC3C40-31E0-4EA0-B340-BEAB3E\98EF48CE-DB94-4E8F-9F67-4E4A70 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\31EF8903-B4CD-4BC8-9D07-06F035\02292210-83AD-4641-99C0-288D72/chrome/isearch.jar/content/isearch/isearch.js -> Spyware.iSearch : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\31EF8903-B4CD-4BC8-9D07-06F035\75C277D3-D1FA-4F52-9DBC-0E9F04 -> Trojan.Delprot.a : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\3FEDA704-32F7-47CD-BA9A-5ACB8B\DC7241C1-E017-47CB-BBF7-4666F8 -> Spyware.SearchIt : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\430C1226-C660-4B9F-8FF5-3CF158\5CBEF496-AE09-40FD-8DC4-1F777D -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\430C1226-C660-4B9F-8FF5-3CF158\DD19EDF1-4511-447F-B533-987299 -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\4AA67DF2-B28E-496D-91BF-5F5D86\37F32059-87D8-437D-9C0C-A3E06B -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\7ADA7BC0-85AD-4B70-97C5-8DCFA0\2D498667-A2FA-4472-9A87-8A8A7B -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\7BEDA5B3-CBFE-4266-AEEE-AFD7A2\A0FAADD8-7D0B-401E-8C52-A41904 -> TrojanDropper.Agent.mm : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\85F4E74C-F38A-48F8-864C-1A68C9\E9663657-F2D4-4807-86D5-B08840 -> Spyware.MediaPops : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\8D6E5075-B1C1-448B-825F-E6895D\453D94BA-6CD4-4BFD-A44C-8AAEC8 -> Spyware.HotBar : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9315984A-6AD2-4A83-BB01-846469\588F3D4C-1A2B-4327-B249-D882B7 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9C9E267F-C6C2-4B9E-A018-E702B6\CC60B844-6522-45E5-A0FE-A273DF -> TrojanDownloader.Agent.li : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\9FAE34F0-4C10-4361-8562-3EBC79\DE0AEEF6-B18B-4E31-ADDD-D6BBD4 -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C504127B-9915-4EA9-B324-E9BD78\A60AF13B-70B6-44B6-851D-CEF39E -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C504127B-9915-4EA9-B324-E9BD78\D4475851-498E-48B6-88D8-ECB8C0 -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\015A37C4-44DD-42E9-9AEB-433AD3 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\3E1B3A3D-FDE3-47CF-B381-54D6C9 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\8CF2D799-9437-4303-90AF-2F512B -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\C22335B6-894D-4523-842B-6C4C41 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\E0C2E937-D15D-4E4B-90F3-DE7A8F -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\C567E58B-4BBD-4A80-A1D0-BB054D\F93AE676-4934-4945-B34D-34AB09 -> Trojan.Pakes : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\CCD198B2-1873-43E6-8229-A8307B\508F9D74-BC84-451F-AA22-A7D769 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F3528277-D59C-47CF-A4E4-5CDF04\376EAB53-69C6-40D6-BBAE-2AB68D -> TrojanDownloader.Agent.li : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F4EE40F1-172F-4BCD-A3E8-24AB40\77A0C863-C9C1-4BE6-BF88-10F92A -> Spyware.Beginto : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F9927A6D-CCF8-456F-9145-5D1F19\0F61947F-C676-4142-A2B4-44A6D8 -> Spyware.Beginto : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/system32/lshosts32.exe -> Backdoor.SdBot : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Program Files/mysearch/bar/1.bin/npmysrch.dll -> Spyware.MyWay : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Program Files/mysearch/bar/1.bin/s42ns.exe -> Spyware.MyWay : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temp/SaveCmS.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temp/SaveCmS.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temp/SaveCmS.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temporary Internet Files/Content.IE5/CFW56RGZ/pictures[1].pif -> Backdoor.SdBot : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temporary Internet Files/Content.IE5/OTSZC3WJ/photos[1].pif -> Backdoor.SdBot : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/David/Local Settings/Temporary Internet Files/Content.IE5/CFW56RGZ/sp2ctr[1].exe -> TrojanDownloader.Dluca.ai : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/Sue/Local Settings/Temporary Internet Files/Content.IE5/69FSTON6/sp2ctr[1].exe -> TrojanDownloader.Dluca.ai : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/Documents and Settings/Sue/Local Settings/Temporary Internet Files/Content.IE5/CT67412F/sp2ctr[1].exe -> TrojanDownloader.Dluca.ai : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/extract.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/msbbi.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/SYSTEM32/ceealjxa.exe -> TrojanDownloader.Dluca : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/SYSTEM32/dskviajl.exe -> TrojanDownloader.Dluca : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/SYSTEM32/qriixfve.exe -> TrojanDownloader.Dluca : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/SYSTEM32/qwvxytxf.exe -> TrojanDownloader.Dluca : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050427110927.zip/WINDOWS/SYSTEM32/zwevozbe.exe -> TrojanDownloader.Dluca : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050626181656.zip/documents and settings/administrator/cookies/administrator@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050626181656.zip/documents and settings/administrator/cookies/administrator@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\q123.vbs -> TrojanDownloader.Iwill.g : Cleaned with backup
C:\StopSign_install-r.exe -> Spyware.eAcceleration : Cleaned with backup
C:\WINDOWS\aclasvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\bdggsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\ceizsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\dndxsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\rdgUS1742.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\rdgUS1742.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\rdgUS1742.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\rdgUS1742.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\rdgUS1742.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\rdgUS1742.exe -> TrojanDownloader.Small.ayl : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\rdgUS1742.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\elnssvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\folhsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\hbndsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\inst\3p_1.exe -> TrojanDownloader.Dyfuca.du : Cleaned with backup
C:\WINDOWS\NDNuninstall5_64.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_10.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_22.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\qiiksvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\rzdbdll.exe -> TrojanDownloader.VB.hj : Cleaned with backup
C:\WINDOWS\rzdbenc.exe -> TrojanDownloader.VB.hj : Cleaned with backup
C:\WINDOWS\STWSI\crmrest.ocx -> TrojanDownloader.Dyfuca.db : Cleaned with backup
C:\WINDOWS\SYSTEM\BHOmod.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\WINDOWS\SYSTEM32\AMSTREAM.exe -> Spyware.IEDriver : Cleaned with backup
C:\WINDOWS\SYSTEM32\bigtraffic.exe -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\biU.exe/bi.dll -> Trojan.Bispy.A : Cleaned with backup
C:\WINDOWS\SYSTEM32\biU.exe/preInsBI.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2802040113.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\bUS.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\c41bUs.dll/bi.dll -> Trojan.Bispy.A : Cleaned with backup
C:\WINDOWS\SYSTEM32\c41bUs.dll/preInsBI.exe -> Spyware.BiSpy : Cleaned with backup
C:\WINDOWS\SYSTEM32\c4t.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\WINDOWS\SYSTEM32\dload.exe -> TrojanDownloader.Small.mx : Cleaned with backup
C:\WINDOWS\SYSTEM32\DRIVERS\delprot.sys -> Trojan.Delprot.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\evapzmxe.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\ftvpjyug.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\grdyhrur.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\infus-uninstall.exe -> TrojanDownloader.Dluca.f : Cleaned with backup
C:\WINDOWS\SYSTEM32\mantsgcp.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\mhoukdon.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\nniscocu.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsa5A4.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsaA2.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsf5F.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsh577.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsi210.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsm519.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\nst558.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\SYSTEM32\protect.exe -> TrojanDownloader.Agent.nr : Cleaned with backup
C:\WINDOWS\SYSTEM32\qiyapbzo.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\qjtpkwmv.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\rxxodpgh.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\sefe.exe -> Not-A-Virus.Hoax.Renos.a : Cleaned with backup
C:\WINDOWS\SYSTEM32\sefer.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\urtofpld.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\vcyytuur.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\vpbtucxu.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\wgktiyzc.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\SYSTEM32\zyxggmbi.exe -> TrojanDownloader.Dluca.ae : Cleaned with backup
C:\WINDOWS\taiqsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\thin-143-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\vdazsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\WINDOWS\wfcxsvc.exe -> TrojanDropper.Agent.mu : Cleaned with backup
C:\winstall.exe -> Not-A-Virus.Hoax.Renos.a : Cleaned with backup


::Report End
Wasn't me, a bunch of great folks worked hard on the fix, and you executed it :) Your HJT log is clean. Lets look at the Ewido log together starting at the top:

David, You had a lot of junk hiding on your computer. Look where it was hiding, Temp Files and Temporary Internet files. Search these items out and delete them often. Cleanup! will get most of them for you but you need to keep an eye on those areas. We also need to wonder how this stuff is getting on board? I also believe you cut off some of the Ewido scan report, I should have had information about how many items were located and what was done with them. I also want you to look at the stuff that is quarantined in Microsoft AntiSpyware\Quarantine. You need to go to the MAS quarantine and delete everything in there. We also need to cleanout System Restore to make sure nothing is in there that could get back on the computer if you needed SR for a valid reason. Please do this:

MANUAL INSTRUCTIONS FOR SYSTEM RESTORE
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Good luck and safe surfing…Phil :wavey:
I will leave your thread open for a couple of days if you have questions.
Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI