This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

attacked by IE ads

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I accidentally clicked and downloaded something (possibly 180 solutions or SearchForIt…don't quite remember) in IE a while ago (I don't usually use IE, I usually use Mozilla) and now my computer is plagued with all these ads. I tried to uninstall and delete everything I could by running AdAware and SpySeeker, but I don't think it worked because the ads are still here. I've tried to fix all the internet settings to high, but to no avail. I'm pretty much computer illiterate, so I might need extremely detailed solutions (step by step style) - sorry in advance for the hassle. I ran HijackThis and got a copy of my computer log; let me know if you need it. Please help me! I'm about to go bonkers! THANK YOU!
Logfile of HijackThis v1.99.1
Scan saved at 9:22:33 PM, on 07/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\msxct.exe
C:\WINDOWS\System32\wintask.exe
C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\WINDOWS\System32\picsvr\picsvr.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msst\msst.exe
C:\WINDOWS\System32\urrkkr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\COMMON~1\kfro\kfrom.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\system32\msCMTSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PeDevice\PeDev.exe
C:\PROGRA~1\eBlocs\SpyBlocs\GLF64.exe
C:\PROGRA~1\COMMON~1\kfro\kfroa.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Data\Christina\aim convos\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://mail.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
O2 - BHO: Cas - {B5F3970B-745E-46AC-B890-E08F69777D80} - C:\WINDOWS\System32\ca.dll
O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Phase One Media Reader] C:\PROGRA~1\PHASEO~1\CAPTUR~1\DCIMImp.exe /noscan
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteuzw32.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\urrkkr.exe reg_run
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [kfro] C:\PROGRA~1\COMMON~1\kfro\kfrom.exe
O4 - HKCU\..\Run: [SpyBlocs] C:\Program Files\eBlocs\SpyBlocs\GLF64.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB\webserver\bin\win32\matlabserver.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
Hello gadzooks_help_me and welcome to TomCoyote. :wavey:
  • Install and Update Ewido:
    • Download and install Ewido security suite.
    • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    • Launch Ewido, there should be an icon on your desktop for it to double-click.
      • The program will prompt you to update, click the OK button.
      • The program will now go to the main screen.
    • You will need to update ewido to the latest definition files.
      • On the left hand side of the main screen click update.
      • Click on Start Update.
      • The update will start and a progress bar will show the updates being installed.
    • Once the updates are installed, close the program.
  • Download this tool : LQfix.zip
    • Unzip it to your Desktop.
    • Don't use it yet!

Reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').
  • Doubleclick LQfix.bat that you saved on your desktop before.
    • A dos window will open and close again, that is normal.
  • Scanning With Ewido:
    • Launch Ewido again.
    • Click on scanner
    • Click on Complete System Scan and the scan will begin.
    • While the scan is in progress you will be prompted to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the boxes that say "Perform action on all infections"and "Create encrypted backup" then choose clean and click OK.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report.
    • Save the report .txt file to your desktop.
  • Now close ewido security suite.
Reboot into normal mode and scan with HijackThis. Post the new log as a reply to this thread.
Logfile of HijackThis v1.99.1
Scan saved at 8:59:28 PM, on 07/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\msst\msst.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Data\Christina\aim convos\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://mail.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
O2 - BHO: Cas - {B5F3970B-745E-46AC-B890-E08F69777D80} - C:\WINDOWS\System32\ca.dll
O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\urrkkr.exe reg_run
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [kfro] C:\PROGRA~1\COMMON~1\kfro\kfrom.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB\webserver\bin\win32\matlabserver.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe


Hope I did it correctly, and thanks so much for your detailed instructions. Let me know if you need the Ewido report. Thanks again!
Please post the Ewido log so I can verify what was removed. I'm looking at your log now. Will have the next set of instructions shortly. :)
Step 1
Open HijackThis, run a scan, then check the following:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

O2 - BHO: Cas - {B5F3970B-745E-46AC-B890-E08F69777D80} - C:\WINDOWS\System32\ca.dll
O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll

O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [msst] C:\Documents and Settings\All Users\Application Data\msst\mssts.exe
O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\System32\picsvr\picsvr.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\urrkkr.exe reg_run
O4 - HKCU\..\Run: [sf] C:\Program Files\sf\sf.exe
O4 - HKCU\..\Run: [sfita] C:\WINDOWS\sfita.exe
O4 - HKCU\..\Run: [kfro] C:\PROGRA~1\COMMON~1\kfro\kfrom.exe

O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com

O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/…rCabInstall.cab


With all other programs and browsers closed, click fix checked.


Step 2
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 3
Please delete the following files/folders:

C:\WINDOWS\System32\exp.exe << File Only
C:\WINDOWS\System32\wintask.exe << File Only
C:\WINDOWS\System32\urrkkr.exe << File Only
C:\WINDOWS\seeve.exe << File Only
C:\WINDOWS\sfita.exe << File Only

C:\WINDOWS\System32\nsvsvc << Whole Folder
C:\WINDOWS\System32\picsvr << Whole Folder
C:\Documents and Settings\All Users\Application Data\msst << Whole Folder
C:\Program Files\PeDevice << Whole Folder
C:\Program Files\sf << Whole Folder
C:\Program Files\Common Files\kfro << Whole Folder

You'll need to search for these files with Explorer to delete. They may be in C:\WINDOWS\system32\ or C:\WINDOWS\
(Start > Search > All files and folders > More advanced options place a check in the first three boxes)

AUNPS2.DLL
msxct.exe


If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 4
Reboot normally and run a scan with Panda Activescan.
Save the log after the scan as I will need to see it.


Step 5
Scan with HijackThis and post the new log as a reply to this thread. Be sure to include the log from Panda.
——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 8:40:33 PM, 07/11/2005 + Report-Checksum: 8F5C0111 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup HKLM\SOFTWARE\Dvx -> Spyware.Delfin : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup HKLM\SOFTWARE\motoin -> Spyware.Delfin : Cleaned with backup HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup HKLM\SOFTWARE\picsvr -> Spyware.Delfin : Cleaned with backup HKU\S-1-5-21-744570386-3102852870-508063931-1003\Software\Mvu -> Spyware.Delfin : Cleaned with backup HKU\S-1-5-21-744570386-3102852870-508063931-1003\Software\picsvr -> Spyware.Delfin : Cleaned with backup HKU\S-1-5-21-744570386-3102852870-508063931-1003\Software\WinUpdt -> Spyware.SecondThought : Cleaned with backup HKU\S-1-5-21-744570386-3102852870-508063931-1003\Software\{12EE7A5E-0674-42f9-A76B-000000004D00} -> Spyware.BrowserAid : Cleaned with backup C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rddk.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup :mozilla.11:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.12:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.13:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.14:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.15:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.16:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.21:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.22:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.23:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.24:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.25:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.26:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.27:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.28:C:\Documents and Settings\Guest\Application Data\Mozilla\Profiles\default\x0cglyg3.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.9:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.24:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.28:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Linkbuddies : Cleaned with backup :mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.40:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.41:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.54:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.55:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.56:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.59:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.65:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.67:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.68:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.79:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.106:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.113:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.135:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.136:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.137:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.138:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.140:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.141:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.175:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.176:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.207:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.208:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.209:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.210:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.242:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.256:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.257:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.258:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.259:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.279:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.280:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.281:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.282:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.283:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup :mozilla.15:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.17:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.24:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.25:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.26:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.28:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.40:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.41:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.54:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.55:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.56:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.59:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.65:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.67:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.68:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.79:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.99:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.100:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.101:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.102:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.103:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.104:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.105:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.106:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup :mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.140:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.141:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.142:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.143:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.159:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.160:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.204:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.205:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.206:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.228:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.250:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.265:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.266:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\Default User\gk3u5yku.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Enigmasoftwaregroup : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\180SAInstaller.exe/clientax.dll -> Spyware.180Solutions : Error during cleaning C:\Documents and Settings\Owner\Local Settings\Temp\GLF118GLF118.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\GLF11GLF11.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\GLF12GLF12.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\GLF15GLF15.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\GLF26GLF26.EXE -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\toc_0015.exe -> TrojanDownloader.Agent.jq : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\tp7543.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\ts_8_new.exe -> TrojanDownloader.TSUpdate.f : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\FEG7Z9S9\banner[1].cab/banner.dll -> Spyware.Banex : Error during cleaning C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OP4NO7CR\aun_0015[1].exe -> TrojanDownloader.Small.akz : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\OP4NO7CR\dotreg3[1].htm -> Spyware.BookedSpace : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\W1AZ49AF\CursorManiaInitialSetup1.0.0.6[1].exe -> Spyware.MySearch : Cleaned with backup C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup C:\Program Files\Common Files\kfro\kfrol.exe -> TrojanDownloader.TSUpdate.j : Cleaned with backup C:\Program Files\Common Files\kfro\kfrom.exe -> TrojanDownloader.TSUpdate.k : Cleaned with backup C:\Program Files\Common Files\kfro\kfrop.exe -> Spyware.Xupiter : Cleaned with backup C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe -> Spyware.Delfin : Cleaned with backup C:\Program Files\FwBarTemp\searchbar.exe -> TrojanDownloader.VB.eu : Cleaned with backup C:\Program Files\Netscape\Netscape\Plugins\npwthost.dll -> Spyware.WildTangent : Cleaned with backup C:\temporary\aun_0015.exe -> TrojanDownloader.Small.akz : Cleaned with backup C:\WINDOWS\Downloaded Program Files\m67m.ocx -> Spyware.MediaMotor : Cleaned with backup C:\WINDOWS\Helper101.dll -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\mm15201518.Stub.exe -> Adware.eZula : Cleaned with backup C:\WINDOWS\seeve.exe -> Spyware.MediaMotor : Cleaned with backup C:\WINDOWS\system32\AUNPS2.dll -> Spyware.Hijacker.Generic : Cleaned with backup C:\WINDOWS\system32\Cache\cxtpls_loader.exe -> TrojanDownloader.Apropo.ab : Cleaned with backup C:\WINDOWS\system32\Cache\dist006.exe -> TrojanDownloader.VB.eu : Cleaned with backup C:\WINDOWS\system32\Cache\HelperInstall.exe -> TrojanDropper.Delf.z : Cleaned with backup C:\WINDOWS\system32\Cache\setup1024.exe -> TrojanDropper.Agent.hl : Cleaned with backup C:\WINDOWS\system32\Cache\ven_d1.exe -> TrojanDownloader.IstBar : Cleaned with backup C:\WINDOWS\system32\dccnncr.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup C:\WINDOWS\system32\msCMTsrvc.exe -> TrojanDownloader.Presario : Cleaned with backup C:\WINDOWS\system32\msxct.exe -> Spyware.BargainBuddy : Cleaned with backup C:\WINDOWS\system32\nsvsvc\nsv.ocx -> Spyware.Delfin : Cleaned with backup C:\WINDOWS\system32\nsvsvc\nsvs.dll -> Spyware.Delfin : Cleaned with backup C:\WINDOWS\system32\nsvsvc\nsvsvc.exe -> Spyware.Delfin : Cleaned with backup C:\WINDOWS\system32\oppiiph.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup C:\WINDOWS\system32\picsvr\picsvr.exe -> TrojanDownloader.Delmed.b : Cleaned with backup C:\WINDOWS\system32\redit.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup C:\WINDOWS\system32\urrkkr.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup C:\WINDOWS\system32\wintask.exe -> TrojanDownloader.Small.abd : Cleaned with backup ::Report End
Logfile of HijackThis v1.99.1
Scan saved at 3:43:47 PM, on 07/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\System32\urrkkr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\Program Files\AIM\aim.exe
C:\Data\Christina\aim convos\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://mail.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\urrkkr.exe reg_run
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB\webserver\bin\win32\matlabserver.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
I couldn't find AUNPS2.dll, but I think I got to all the others. I also couldn't scan with Panda because it required an IE browser (I usually use Mozilla because somehow my IE messes up all the formats). I did try with IE anyway, but all I can get is a blank window with "Done" in the lower left, on the bottom bar that usually tells you if something is downloading from the site or not. I got my laptop's IE to successfully start downloading, but then I couldn't figure out how to transfer the program to this computer (email? USB device?). Not sure if I'm going about this in the right way - I've IMed a few friends to see if they can think up a way to get the online scanner to my computer; still waiting for their response. Is there another way to access Panda? Or if it's more effective, any way to fix the settings on my IE? Sorry for the complications, and thanks so much for your detailed responses. :)
Do you have the original install disks for Windows XP?


Try this scanner instead as it will work with your browser.

http://fr.trendmicro-europe.com/consumer/p…call_launch.php

Hopefully it will show the files we need to find.


Download rkfiles.zip from here.
UNZIP the contents to a permanent folder.

Reboot in SAFE MODE !! Important !!
To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key

Please set your system to show all files.
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Doubleclick rkfiles.bat.
It will scan for a while, so please be patient.
Wait till the dos window closes and reboot back to normal mode.

Post the contents of C:\log.txt in your next reply along with the results of the Trendmicro online scan.
rkfiles.bat log:

C:\Data\Christina\aim convos\rkfiles

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Files Found in system Folder…………
————————
C:\WINDOWS\system32\oppiiph.dll: UPX!
C:\WINDOWS\system32\urrkkr.exe: UPX!
C:\WINDOWS\system32\wqqaa.dat: UPX!
C:\WINDOWS\system32\DivXdec.ax: FSg!
C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213
C:\WINDOWS\system32\Dwapilib.tlb: dwProvSpec2
C:\WINDOWS\system32\MFC42.PDB: dwProvSpec2
C:\WINDOWS\system32\MFC42D.PDB: dwProvSpec2
C:\WINDOWS\system32\MFCD42D.PDB: dwProvSpec2
C:\WINDOWS\system32\MFCN42D.PDB: dwProvSpec2
C:\WINDOWS\system32\MFCO42D.PDB: dwProvSpec2
C:\WINDOWS\MEMORY.DMP: Input_Spec280x10

Files Found in all users startup Folder…………
————————
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rddk.exe: UPX!
Files Found in all users windows Folder…………
————————
C:\WINDOWS\del.tmp: UPX!
Finished
bye

trendmicro scan:

It ran its scan successfully, but I didn't know where to click to find the log, so I saved a printscreen jpg image of it. Let me know if you want to see the image or if you want me to rescan. The two infections it found:

EXPL_IFRAMEBO.A
JOKE_150ALERTS

Both in C:\Documents and Settings\Owner\Local\Settings\Tempo

thanks for your patience. as for the IE issue, I'll put that on hold as another future thread. thanks again

Do you have the original install disks for Windows XP?

You didn't answer that question yet.

  • Please download the Killbox.
  • Unzip it to the desktop but do NOT run it yet.
  • Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.
  • Once in Safe Mode, please run Killbox.
  • Click "Replace on Reboot" and check the "Use Dummy" box.
  • Paste the following into the top "Full Path of File to Delete" box.
    • C:\WINDOWS\system32\oppiiph.dll
  • Click the red-and-white "Delete File".
  • Click "Yes" at the Replace on Reboot prompt.
  • Click "No" at the Pending Operations prompt.
  • Repeat steps 5-9 above for these files:C:\WINDOWS\system32\urrkkr.exe
    C:\WINDOWS\system32\wqqaa.dat
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rddk.exe
  • Click "Replace on Reboot" and check the "Use Dummy" box.
  • Paste the following file into the top "Full Path of File to Delete" box.C:\WINDOWS\del.tmp
  • Click the red-and-white "Delete File" button.
  • Click "Yes" at the Replace on Reboot prompt.
  • Click "Yes" at the Pending Operations prompt to restart your computer. You do not need to reboot into Safe Mode this time.
  • When your computer reboots, please run RKfiles again and post the new log here along with a fresh HijackThis log.
Sorry for the delay - I've been trying to search for the disks. Still working on it…if I don't find them by tomorrow, I don't think I'll ever be able to find them. :(

Anyhow, here's the hijackthis log…


Logfile of HijackThis v1.99.1
Scan saved at 3:05:59 PM, on 07/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\paarra.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\cmd.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\strings.exe
C:\WINDOWS\system32\find.exe
C:\Data\Christina\project ad killing\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://mail.yahoo.com"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\lbgeq8f9.slt\prefs.js)
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\paarra.exe reg_run
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: strings.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB\webserver\bin\win32\matlabserver.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\CompuPicPro\ScsiAccess.exe




the rkfiles log is on its way

thanks
C:\Data\Christina\project ad killing\rkfiles PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. Files Found in system Folder………… ———————— C:\WINDOWS\system32\DivXdec.ax: FSg! C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213 C:\WINDOWS\system32\Dwapilib.tlb: dwProvSpec2 C:\WINDOWS\system32\MFC42.PDB: dwProvSpec2 C:\WINDOWS\system32\MFC42D.PDB: dwProvSpec2 C:\WINDOWS\system32\MFCD42D.PDB: dwProvSpec2 C:\WINDOWS\system32\MFCN42D.PDB: dwProvSpec2 C:\WINDOWS\system32\MFCO42D.PDB: dwProvSpec2 C:\WINDOWS\MEMORY.DMP: Input_Spec280x10 Files Found in all users startup Folder………… ———————— Files Found in all users windows Folder………… ———————— Finished bye
The Qoologic infection has changed to the newest variant now so it will take different programs to detect it.

Please Download the following tools to assist us in removing this infection!
  • Download WinPFind
    • Right Click the Zip Folder and Select "Extract All"
    • Extract it somewhere you will remember like the Desktop
    • Dont do anything with it yet!
  • Download Track qoo
    • Save it somewhere you will remember like the Desktop
Reboot into Safe Mode
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Doubleclick WinPFind.exe
  • Click "Start Scan"
  • It will scan the entire System, so please be patient!
  • Once the Scan is Complete
  • Go to the WinPFind folder
  • Locate WinPFind.txt
  • Place those results in the next post!
Reboot back to Normal Mode!

Double Click on "Track qoo.vbs"

Note - If you Antivirus has Script Blocking, you will get a Pop Up Windows asking you what to do. Allow this Entire Script to Run, its harmless!

Wait a few seconds and a notepad page will pop up, Copy & Paste those results and place them in the next post along with the results of WinPFind!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI