This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trying to remove hijack

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

Well, much like everybody else I've been hit by a hijack and I've been trying to remove it.

I have Norton Anti Virus and Personal Firewall installed and running. Anti virus picked up adware.Iefeats and deleted them, I also ran their Iefeats removal tool but there is still activity going on. I also have Spyblaster, Spybot and Adaware SE (all up to date with Ad-watch running).

Since the Iefeats removal I get all these error messages on bootup because the .exe's have been deleted.

I desperately need your help to guide me in removing the bad files. I'm not too computer savvy but I'm a quick learner.

Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 12:05:05 AM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
C:\WINDOWS\system32\addby.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {1D4E16CB-FA36-C50A-24B0-0F1B77AAC063} - C:\WINDOWS\system32\d3qm32.dll (file missing)
O2 - BHO: Class - {25A009EF-9AD1-F48E-DE09-4FBF9D83EA16} - C:\WINDOWS\system32\d3oy.dll (file missing)
O2 - BHO: Class - {3A259714-8197-822B-1F45-481A82927866} - C:\WINDOWS\winzl.dll (file missing)
O2 - BHO: Class - {3F56B013-2968-2BEF-D3F5-EE7CB8690AC7} - C:\WINDOWS\appfb.dll (file missing)
O2 - BHO: Class - {6D64A390-DFBD-E0B5-5BCA-1E9FB2E735AC} - C:\WINDOWS\sysub.dll
O2 - BHO: Class - {7E562404-C395-FEAE-9587-21D1288BA8BF} - C:\WINDOWS\system32\ietz32.dll (file missing)
O2 - BHO: Class - {8551A6D4-FA39-105F-680E-05B3F49E4405} - C:\WINDOWS\atlgc.dll (file missing)
O2 - BHO: Class - {8B4F80A5-030A-D600-CFF9-AF38A44D6CBB} - C:\WINDOWS\system32\apptw.dll (file missing)
O2 - BHO: Class - {97117941-9F9B-7B77-FBDB-598CBAA2F96C} - C:\WINDOWS\addhc32.dll (file missing)
O2 - BHO: Class - {98529CC2-52A9-99EE-F7DF-D4FA46CD1BDA} - C:\WINDOWS\system32\sdkia32.dll
O2 - BHO: Class - {A8ED1EB9-4DCD-9FEF-5087-1F9CDCCE6B2B} - C:\WINDOWS\ntdv.dll (file missing)
O2 - BHO: Class - {A9B63F00-46F6-794A-3935-C204BC7E0785} - C:\WINDOWS\system32\atlgf32.dll (file missing)
O2 - BHO: Class - {AF46D2B7-38E9-C0AA-C63C-09D3CE5E7C0A} - C:\WINDOWS\ntac.dll (file missing)
O2 - BHO: Class - {B30E458E-D56C-F802-8A2F-D5FC73A16CAE} - C:\WINDOWS\system32\mfcyb32.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {BEE4D4B4-B9F5-A799-6F43-FECDC7D512FE} - C:\WINDOWS\winvj32.dll (file missing)
O2 - BHO: Class - {C5EA03C9-5E7C-3BB6-855D-C09FB9DA8FA7} - C:\WINDOWS\ntyb.dll (file missing)
O2 - BHO: Class - {D60F8F8E-F454-96F2-A434-9E44DA8D64C8} - C:\WINDOWS\system32\appxy.dll (file missing)
O2 - BHO: Class - {DB4F8C73-9882-05B9-A545-A1A794E29AA6} - C:\WINDOWS\ieih.dll (file missing)
O2 - BHO: Class - {E118F9B6-686E-47CF-3507-F787ADEDD0FF} - C:\WINDOWS\appla.dll (file missing)
O2 - BHO: Class - {E3828D84-4E06-2C16-3DD3-0FB832F75880} - C:\WINDOWS\msqq.dll (file missing)
O2 - BHO: Class - {EC15F4E3-8B04-146F-F290-13F33AB877B1} - C:\WINDOWS\ntut.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22f1364f0fab2b5f1b17/…ip/RdxIE601.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

Thanks in advance for your help
You have the newest version of About:Blank on your computer. Please post a fresh HijackThis log as a reply to this thread. After posting the reply, do not reboot the computer nor use Internet Explorer if possible. I'll receive an email notification of your reply and will respond with instructions as soon as possible.
Here we go:

Logfile of HijackThis v1.99.1
Scan saved at 10:04:20 AM, on 7/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\addby.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wfzun.dll/sp.html#36663
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wfzun.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {1BFC89A8-D9C3-8D1D-EA87-3F18E8BE3BA4} - C:\WINDOWS\system32\syswy.dll (file missing)
O2 - BHO: Class - {2C169854-899F-2A96-6742-CDEF2306E937} - C:\WINDOWS\msgm32.dll (file missing)
O2 - BHO: Class - {2C97FC81-7312-18D2-BB32-1F2573873654} - C:\WINDOWS\d3pp32.dll (file missing)
O2 - BHO: Class - {3BAEACBD-6D25-4282-0896-4FA149FAF324} - C:\WINDOWS\mstb32.dll
O2 - BHO: Class - {3C590378-0A5C-B10E-AF30-95DF78FBEABD} - C:\WINDOWS\apipu32.dll (file missing)
O2 - BHO: Class - {8EE335AE-CD27-C53A-397B-74E09FAD978A} - C:\WINDOWS\iequ32.dll (file missing)
O2 - BHO: Class - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - C:\WINDOWS\system32\addvr32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {C0B62884-9D9D-A9E4-7E45-B29002B6258A} - C:\WINDOWS\winzh32.dll (file missing)
O2 - BHO: Class - {D22869A8-8A72-A198-1150-D6A2F741CA3A} - C:\WINDOWS\ipmn32.dll
O2 - BHO: Class - {E8672AC7-8611-4002-4486-F4856A5C2E37} - C:\WINDOWS\javamb.dll (file missing)
O2 - BHO: Class - {F6ED913D-FAB1-F1A5-C359-4E2B2AC7B284} - C:\WINDOWS\system32\mfchl.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22f1364f0fab2b5f1b17/…ip/RdxIE601.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipzp32.exe" /s (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
Hello orbiter and welcome to TomCoyote. :wavey:

You have ad-aware's ad-watch running on your computer and that is good. But prior to doing the fix below with hijackthis it needs to be turned off.
Please do the following:
  • Open AdAware Se.
  • Click the Ad-Watch icon on the top of the screen.
  • Go to Tools and Preferences.
  • At the bottom of the screen you can see two checkable items called Active and Automatic.
    • Active: This will turn Ad-Watch On\Off without closing it
      Automatic: Suspicious activity will be blocked automatically
  • Please uncheck Automatic. Allow any changes during the fix.

Step#1:Getting Ready


Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.

After downloading the tools, you must disconnect from the internet totally, because staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection.

To replace Internet Explorer to use during this fix, please use Internet Explorer once to download and install FireFox, to be used as your alternate browser throughout this fix.

Close Outlook Express and Internet Explorer for the duration of this fix

Please start by downloading the tools you will need to clean this infection with FireFox. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you finally reply.


Step#2:Show All Hidden Files Very Important
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.

Step#3:Download CWShredder

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates but please Do NOT use it yet


Step#4:Download About Buster

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip.

2. Once it is downloaded extract it to c:\aboutbuster.

3. Check to make sure it is up-to-date. Please Do NOT use it yet


Step#5:Download Registrar Lite

Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use. Caution should be exercised when editing the registry as it is very easy to render a Computer unbootable by deleting the wrong key


Step#6:Download Ewido Security Suite
  • Download and install Ewido security suite
  • Right Click on the “E” icon in your taskbar and open Ewido Security Suite then click “update” to get the most recent definitions for it to use.
  • When it prompts you to update, click the OK button.
  • download the updates and when they are finished installing, close the window
  • Please Do Not Use It Yet

Step#7:Download A Registry File to Remove Registry Entries
  • Please download the following zip file to your desktop:
    HSfix
  • Double Click on HSfix.zip and it will unzip to a new folder it makes on your desktop, called HSfix
  • Do Not Use It Yet

Step#8:Create Registry file to Remove RunOnce Entries
  • Open Notepad and copy the following text into it. Go up to "File > Save As" and click the drop-down box to change the 'Save As Type' to 'All Files'. Save it as FixRO.reg on your desktop.
  • Do Not Use It Yet
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]





Please disconnect from the Internet

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE




Step#9:Disable The Bad Service ** Very Important!!**
  • Click on start > control panel > administrative programs > services. Look for a service called Network Security Service. Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.

Step#10:Stop The Running Processes

Press control-alt-delete to get into the task manager and end the following processes if they exist:

addby.exe



Step#11:Delete the Offending Files

I now need you to delete the following files:

C:\WINDOWS\ipmn32.dll
C:\WINDOWS\mstb32.dll
C:\WINDOWS\ipzp32.exe
C:\WINDOWS\system32\wfzun.dll
C:\WINDOWS\system32\geujx.dll
C:\WINDOWS\system32\addvr32.dll
C:\WINDOWS\system32\addby.exe



If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#12:Cleaning With HijackThis

Open HijackThis, run a scan and put a checkmark next to each of these entries (some may be gone after uninstalling some programs):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wfzun.dll/sp.html#36663
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\wfzun.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {1BFC89A8-D9C3-8D1D-EA87-3F18E8BE3BA4} - C:\WINDOWS\system32\syswy.dll (file missing)
O2 - BHO: Class - {2C169854-899F-2A96-6742-CDEF2306E937} - C:\WINDOWS\msgm32.dll (file missing)
O2 - BHO: Class - {2C97FC81-7312-18D2-BB32-1F2573873654} - C:\WINDOWS\d3pp32.dll (file missing)
O2 - BHO: Class - {3BAEACBD-6D25-4282-0896-4FA149FAF324} - C:\WINDOWS\mstb32.dll
O2 - BHO: Class - {3C590378-0A5C-B10E-AF30-95DF78FBEABD} - C:\WINDOWS\apipu32.dll (file missing)
O2 - BHO: Class - {8EE335AE-CD27-C53A-397B-74E09FAD978A} - C:\WINDOWS\iequ32.dll (file missing)
O2 - BHO: Class - {A963E875-BD23-4A38-7CEC-B5840D7C5CF0} - C:\WINDOWS\system32\addvr32.dll
O2 - BHO: Class - {C0B62884-9D9D-A9E4-7E45-B29002B6258A} - C:\WINDOWS\winzh32.dll (file missing)
O2 - BHO: Class - {D22869A8-8A72-A198-1150-D6A2F741CA3A} - C:\WINDOWS\ipmn32.dll
O2 - BHO: Class - {E8672AC7-8611-4002-4486-F4856A5C2E37} - C:\WINDOWS\javamb.dll (file missing)
O2 - BHO: Class - {F6ED913D-FAB1-F1A5-C359-4E2B2AC7B284} - C:\WINDOWS\system32\mfchl.dll (file missing)

O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22f1364f0fab2b5f1b17/…ip/RdxIE601.cab

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipzp32.exe" /s (file missing)


With all other programs and browsers closed, click Fix Checked.



Step#13: Backup The Registry

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)



Step#14: Use the FixRO.reg file
  • Double-click the FixRO.reg file on your Desktop.
  • When it prompts to merge say yes, and this will clear the RunOnce registry entries added by the infection.
  • If you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it




Step#15: Use the HSfix.reg file
  • Navigate to the HSfix folder on your Desktop
  • Then double-click on the HSfix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
  • If you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it

Step#16:Fixing With CWShredder
  • CLOSE ALL WINDOWS except CWShredder
  • Run the program by clicking 'fix' and letting it fix all CWS remnants.


Step#17:Fixing With About Buster

This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory
  • double-click on aboutbuster.exe
  • When the tool opens press the OK button, then Start button, then the OK button
  • then finally the Yes button. It will start scanning your computer for files.
  • If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply


Step#18:Scan With Ewido Security Suite
  • Launch Ewido again
  • Click on Scanner>Complete System Scan.
  • Let the program scan your PC.
  • When the scan asks to clean files click OK.
  • When scan is completed, click Save report. to your desktop.
  • Post the report in your next reply.

Reboot your computer back to normal mode


Step#19:Scan and Post a New HJT log with other logs
  • Scan again with HijackThis and save log.

    Reconnect To The Internet
  • Post your logs from HijackThis, About Buster, and Ewido Security Suite here in this thread with any questions or problems that you have run into.
  • There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.
Hi Alan,

Thanks for all your help so far.

Well, I've been following your instructions to the letter and so far I've reached Step 10 and 11.

While in safe mode I set the network security service startup to disabled and wrote down the path. I wasn't sure what "must be deleted below" meant but I thought maybe it was in the next step so I continued.

Next, I hit control-alt-delete and didn't find "addby.exe"

Step 11 is where I get lost.

I didn't see any of the listed files you mentioned in the task manager i.e. ipmn32.dll etc. Am I looking in the wrong place? All that was in task mananger was:

taskmgr.exe
mmc.exe
explorer.exe
svhost.exe
svhost.exe
svhost.exe
lsass.exe
sevices.exe
winlogon.exe
csrss.exe
smss.exe
system
system idle process SYSTEM

When rebooting in normal mode so I could post this message a prompt then came up asking if I want Explorer as my default browser (it isn't set as such and hence, never will be). I clicked no but it popped up briefly anyway. So, I will list the HT log again. I hope that is the right thing to do:

Logfile of HijackThis v1.99.1
Scan saved at 10:46:31 AM, on 7/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\addby.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\netom32.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\WINDOWS\javauz32.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xmfbq.dll/sp.html#36663
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xmfbq.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {D8DE090C-57F8-9A7F-58B1-260247595BBF} - C:\WINDOWS\ntwp.dll
O2 - BHO: Class - {F03BFCA4-5E99-2D98-5B24-36E07A96913C} - C:\WINDOWS\addzk.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22f1364f0fab2b5f1b17/…ip/RdxIE601.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipzp32.exe" /s (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

So Alan, I guess what I'm asking is where do I delete the "offending files" from?

Sorry if I sound stupid for not knowing, your instructions are very clear and I feel a little embarrased asking again.

Thanks for all your hard work.

Regards, Paul
Here is the fix with the new list of files that are present in your last log. Remember after going into Safe Mode, do not reboot the computer and do not use Internet Explorer or Outlook Express as this will cause the infection to morph. Work your way through all of the instructions then ask any questions at the end. If you can not locate any files listed, do not worry about them.

In Step 11, you must manually go to the location of the file (using Explorer) to delete it. For example C:\WINDOWS\ipzp32.exe:
Click Start < My Computer < (C:) < Windows then find and delete ipzp32.exe

You have ad-aware's ad-watch running on your computer and that is good. But prior to doing the fix below with hijackthis it needs to be turned off.
Please do the following:
  • Open AdAware Se.
  • Click the Ad-Watch icon on the top of the screen.
  • Go to Tools and Preferences.
  • At the bottom of the screen you can see two checkable items called Active and Automatic.
    • Active: This will turn Ad-Watch On\Off without closing it
      Automatic: Suspicious activity will be blocked automatically
  • Please uncheck Automatic. Allow any changes during the fix.

Step#1:Getting Ready


Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.

After downloading the tools, you must disconnect from the internet totally, because staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection.

Done already.

Close Outlook Express and Internet Explorer for the duration of this fix

Please start by downloading the tools you will need to clean this infection with FireFox. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you finally reply.


Step#2:Show All Hidden Files Very Important
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.

Step#3:Download CWShredder

Done already. Skip this step.


Step#4:Download About Buster

Done already. Skip this step.


Step#5:Download Registrar Lite

Done already. Skip this step.


Step#6:Download Ewido Security Suite

Done already. Skip this step.


Step#7:Download A Registry File to Remove Registry Entries

Done already. Skip this step.


Step#8:Create Registry file to Remove RunOnce Entries

Done already. Skip this step.


Step#9:Disable The Bad Service ** Very Important!!**
  • Click on start > control panel > administrative programs > services. Look for a service called Network Security Service. Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below ( in Step 11).

Step#10:Stop The Running Processes

Press control-alt-delete to get into the task manager and end the following processes if they exist:

C:\WINDOWS\system32\addby.exe
netom32.exe
javauz32.exe




Step#11:Delete the Offending Files

I now need you to delete the following files if present:

.
C:\WINDOWS\system32\xmfbq.dll
C:\WINDOWS\system32\geujx.dll
C:\WINDOWS\system32\addby.exe
C:\WINDOWS\system32\netom32.exe
C:\WINDOWS\javauz32.exe
C:\WINDOWS\ntwp.dll
C:\WINDOWS\addzk.dll
C:\WINDOWS\ipzp32.exe

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#12:Cleaning With HijackThis

Open HijackThis, run a scan and put a checkmark next to each of these entries (some may be gone after uninstalling some programs):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xmfbq.dll/sp.html#36663
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\xmfbq.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {D8DE090C-57F8-9A7F-58B1-260247595BBF} - C:\WINDOWS\ntwp.dll
O2 - BHO: Class - {F03BFCA4-5E99-2D98-5B24-36E07A96913C} - C:\WINDOWS\addzk.dll

O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/22f1364f0fab2b5f1b17/…ip/RdxIE601.cab

O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\ipzp32.exe" /s (file missing)


With all other programs and browsers closed, click Fix Checked.



Step#13: Backup The Registry

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)



Step#14: Use the FixRO.reg file
  • Double-click the FixRO.reg file on your Desktop.
  • When it prompts to merge say yes, and this will clear the RunOnce registry entries added by the infection.
  • If you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it




Step#15: Use the HSfix.reg file
  • Navigate to the HSfix folder on your Desktop
  • Then double-click on the HSfix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
  • If you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it

Step#16:Fixing With CWShredder
  • CLOSE ALL WINDOWS except CWShredder
  • Run the program by clicking 'fix' and letting it fix all CWS remnants.


Step#17:Fixing With About Buster

This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory
  • double-click on aboutbuster.exe
  • When the tool opens press the OK button, then Start button, then the OK button
  • then finally the Yes button. It will start scanning your computer for files.
  • If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply


Step#18:Scan With Ewido Security Suite
  • Launch Ewido again
  • Click on Scanner>Complete System Scan.
  • Let the program scan your PC.
  • When the scan asks to clean files click OK.
  • When scan is completed, click Save report. to your desktop.
  • Post the report in your next reply.

Reboot your computer back to normal mode


Step#19:Scan and Post a New HJT log with other logs
  • Scan again with HijackThis and save log.

    Reconnect To The Internet
  • Post your logs from HijackThis, About Buster, and Ewido Security Suite here in this thread with any questions or problems that you have run into.
  • There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.
Oh Alan, I could simply cry, I really could.

I followed your instructions and it took me almost 4 hours to complete the deletions and scans. I couldn't find the ipzp32.exe but most of the others I found and deleted.

The only trouble I seemed to have was that RegisterLite wouldn't let me export that file but I continued.

All seemed well but when I rebooted it appeared to reboot in diagnostic mode. I'm now in normal and all the carp** is still on my PC. I fear that diagnosic mode allowed this to happen and now I'm back to square one. Here are the logs, the HJT and about buster are here, the EWIDO will be on the next post.

Logfile of HijackThis v1.99.1
Scan saved at 3:21:58 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
C:\Program Files\Norton Personal Firewall\ccEmFlSv.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {09419588-4A35-B532-FA96-5DD0086ED758} - C:\WINDOWS\addka32.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {CB62CFC5-A504-C4EF-3373-D9BABA7029F7} - C:\WINDOWS\crki32.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe


AboutBuster:

AboutBuster 5.0 reference file 31
Scan started on [7/25/2005] at [12:20:49 PM]
————————————————
Removed Stream! C:\WINDOWS\bootstat.dat:gqwpzr
Removed Stream! C:\WINDOWS\cmsetacl.log:brcnl
Removed Stream! C:\WINDOWS\ctransit.COR:jrzzvm
Removed Stream! C:\WINDOWS\dahotfix.log:cssnxo
Removed Stream! C:\WINDOWS\dasetup.log:ynoxw
Removed Stream! C:\WINDOWS\DtcInstall.log:zkirmg
Removed Stream! C:\WINDOWS\dzruk.dat:vjkdd
Removed Stream! C:\WINDOWS\explorer.scf:jugwz
Removed Stream! C:\WINDOWS\imsins.log:qbbaa
Removed Stream! C:\WINDOWS\intuprof.ini:hgadr
Removed Stream! C:\WINDOWS\iokmbdm.drv:cvkmv
Removed Stream! C:\WINDOWS\KB822603.log:geupw
Removed Stream! C:\WINDOWS\KB824105.log:pxpnf
Removed Stream! C:\WINDOWS\KB825119.log:ryfhs
Removed Stream! C:\WINDOWS\KB883939.log:nknix
Removed Stream! C:\WINDOWS\KB887472.log:baxdg
Removed Stream! C:\WINDOWS\KB887742.log:skdvo
Removed Stream! C:\WINDOWS\KB888113.log:atpzu
Removed Stream! C:\WINDOWS\KB891781.log:dtmcw
Removed Stream! C:\WINDOWS\ntdtcsetup.log:psdpj
Removed Stream! C:\WINDOWS\OEWABLog.txt:gzopr
Removed Stream! C:\WINDOWS\Q307271.log:msyvd
Removed Stream! C:\WINDOWS\Q307274.log:cosyr
Removed Stream! C:\WINDOWS\Q314147.log:rapsa
Removed Stream! C:\WINDOWS\Q329390.log:duorm
Removed Stream! C:\WINDOWS\Q811493.log:dsuvz
Removed Stream! C:\WINDOWS\Q819696.log:wjwoy
Removed Stream! C:\WINDOWS\REGLOCS.OLD:iwtyp
Removed Stream! C:\WINDOWS\Rhododendron.bmp:ymnxs
Removed Stream! C:\WINDOWS\setupapi.log:fyejw
Removed Stream! C:\WINDOWS\svcpack.log:odpvp
Removed Stream! C:\WINDOWS\VAIO Brezza Wallpaper TrueColor 1024x768.bmp:zfaom
Removed Stream! C:\WINDOWS\VAIO Serenus Wallpaper TrueColor 1280X768.bmp:vhawt
Removed Stream! C:\WINDOWS\VAIO Serenus Wallpaper TrueColor 1600x1200.bmp:obmyz
Removed Stream! C:\WINDOWS\winnt256.bmp:ymfho
Removed Stream! C:\WINDOWS\WMSysPrx.prx:glxev
Removed Stream! C:\WINDOWS\WORDPAD.INI:jdjgh
Removed Stream! C:\WINDOWS\_default.pif:agceb
————————————————
Removed File! : C:\Windows\ggqho.dat
Removed File! : C:\Windows\kvmuz.dat
Removed File! : C:\Windows\lyzoq.dat
Removed File! : C:\Windows\System32\ardfn.dat
Removed File! : C:\Windows\System32\axsfo.dat
Removed File! : C:\Windows\System32\lnakm.dat
Removed File! : C:\Windows\System32\mjfge.dat
Removed File! : C:\Windows\System32\taysk.dat
Removed File! : C:\Windows\System32\wuwzp.dat
Removed File! : C:\Windows\System32\wxkmz.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 12:26:25 PM
——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 2:39:44 PM, 7/25/2005 + Report-Checksum: ADB2EEE1 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{04EDA6A5-3C09-E146-8F75-5684DDB4E2A7} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{07FF232E-41D0-38A2-6073-6847AD3E6453} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1228458E-6B19-48F4-5449-A00AEE93F0FC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{15E6172A-5F7D-3085-1E94-14DA8D1A4479} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{18DF9808-F6C9-984B-EDE3-0B7624EC452A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1DE20533-9118-BF9A-A6C6-F8E881A5FD4B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1E920882-80EF-BD61-DBBD-0847C13D1197} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1EA0CE66-D6D5-2CEB-D734-97906011F9A8} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1F846F72-8833-7B85-FBF7-B2D81D30AB82} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{22E7067A-283F-CF1C-4373-210A97C38BDB} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2621D1BF-0A92-2D9C-E595-02A9C3F76F46} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{29CDA41A-A8EB-6A68-BBF5-2877418D55C7} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2FB10B1F-E342-08A1-CBAA-D4A2CD2ABAC6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3684B1D1-C737-AA3A-00B8-83FE7FF3C058} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3EA8A165-1EE8-2BEF-A8D1-9CDBD760FC43} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4095AAF5-BAD2-A97D-D64C-566A52E35C2E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{43372D0D-6EAD-977A-99EE-8DFB043153ED} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{43F226F3-3EDD-1F6E-B1F9-426F80DAB07E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{491288EB-D314-5571-9C18-B1EAC89ADE09} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4A5DA6C7-CAFA-ADBE-1CBD-9DB325C4EB88} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4C96C433-2EDC-3926-B873-410DB1199685} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5932F9CB-E60E-11C7-5BA5-2CD8198CBDB4} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5E60DAD4-D59A-D1EA-A0B3-BD226EE43523} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5FA0CF1E-5FF7-5212-6D7D-5710E683BABB} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{64AB146B-0C39-DEC3-5AED-E2DA773C655F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{66DEB589-B6D4-E95E-2E36-26287464CD11} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{67654C62-B847-D47B-7386-202E338F4761} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{67D02480-710B-80D7-0624-27BB57B32CDE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6BE5CD97-C2FD-46BB-5C0A-9634487B916D} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{742CF04D-EE46-1423-E899-B91C547ABC20} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{76518006-D7C5-4C71-68F4-DA79559FA482} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{792A038A-9C16-9885-5B25-CE939788172A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7D1F318F-6264-F55E-366B-93087AE94B29} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7DA446BF-5485-78F9-CC9A-2A02C93519E4} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7DFA112F-21B6-72CE-A5DE-09FEAF22C151} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{818D123D-B7CF-1169-DD32-2310AD262479} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{821C8BB3-C516-BEE5-C6A4-ECF0D92BF426} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{865E2CEC-DCDC-CF30-C932-8A491F233655} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8CD1D4D3-8260-44A7-67DD-A71E995AB77F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8D1DF6CE-07E4-C211-83F6-537E054EDC98} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{905BD5E4-261C-4EFD-5456-CD124D7B9D18} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{97E37285-B9D3-035E-821F-3EBE4F849C3D} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9EDC0D8F-954E-A638-C240-D52042910A62} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9FF47B90-35D9-6F6F-3BC1-027BAA23833E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A01394EE-8B14-B1D4-AE65-22E7424A71D0} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A1BC7CDD-070B-7E5C-FEAD-F4789795AD1A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A4405AD1-A13C-E10B-4B57-D5092B102F2B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A6BFC374-18DF-B761-3902-53957EFA4847} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A94D3AA0-A235-876E-2DCD-617E08BD8301} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B063B761-34B8-42D9-CBCD-08B0A1D3E8D4} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B30EFD56-F6AF-2F6B-C3AB-6571E5627F1F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B7ABD257-6E0C-E7F0-26F5-0315127E44C2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BA5E5B3E-BB1D-2938-3E93-1C81F766E7AB} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BC0FE7F5-AD1D-A795-C683-F3EB54072EFE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C092CEA0-FB34-5E12-83ED-47942941DECC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C39816D8-BA82-0890-929F-D27B4B0A27F0} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C53D27E6-2A68-7CD9-A09F-541EF27B2319} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C6984483-D454-B316-4040-575B9FB13D11} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C81EDEFC-5AB9-55D2-CDED-3C677E07B4E6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C927A651-6768-ED9E-C3ED-CBD9A6CF4B22} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CC6A9DFF-521F-7DD3-E624-B30C0B9FF83A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CC6B2B65-2D60-CC2D-B4A6-7C0945964771} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D3E61C7F-BD83-EA01-13F4-464C2595C096} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D7B5394E-D013-3545-35D0-45376236A8DC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DF7066E9-8EE8-8682-F43E-2BF8E7E7D760} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DF74F87A-B7C0-F480-1D25-D81A257B3152} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E4E0C452-0B6D-5B6B-E0AD-5D2B7C054116} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E5C23746-741A-FEC7-C517-86E204C95729} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E5E59618-FEBB-174D-3A09-E2EF1B2CDA17} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EA8D7DFA-04BF-99E7-595C-535DC7F0EFBA} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F065E398-2ACB-9034-8B2A-28A827FF521F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F1E91259-92C0-8767-A2E0-85139867622A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F99D5FC9-1F47-B6F5-F1D5-55AFEAD2853A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FA986CDE-0FA2-33A9-ECFD-8291DFA81985} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FB277F1B-89B6-A114-DD01-EC507A933F39} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FC92C3DE-F786-C2A4-4565-359ECF140E14} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B063B761-34B8-42D9-CBCD-08B0A1D3E8D4} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-2541319435-247674877-3292285946-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1BFC89A8-D9C3-8D1D-EA87-3F18E8BE3BA4} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-2541319435-247674877-3292285946-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7E562404-C395-FEAE-9587-21D1288BA8BF} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-2541319435-247674877-3292285946-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B063B761-34B8-42D9-CBCD-08B0A1D3E8D4} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-2541319435-247674877-3292285946-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F6ED913D-FAB1-F1A5-C359-4E2B2AC7B284} -> Spyware.CoolWebSearch : Cleaned with backup :mozilla.41:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.55:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.56:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.63:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.64:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.65:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.66:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Firefox\Profiles\i5501gzw.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.39:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.53:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.54:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.61:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.62:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.63:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.64:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup :mozilla.11:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\Default User\cczd8ak4.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.13:C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\Default User\cczd8ak4.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup C:\RECYCLER\S-1-5-21-2541319435-247674877-3292285946-1005\Dc10.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\RECYCLER\S-1-5-21-2541319435-247674877-3292285946-1005\Dc6.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\RECYCLER\S-1-5-21-2541319435-247674877-3292285946-1005\Dc7.exe -> Trojan.Agent.bi : Cleaned with backup C:\RECYCLER\S-1-5-21-2541319435-247674877-3292285946-1005\Dc8.exe -> Trojan.Agent.bi : Cleaned with backup C:\RECYCLER\S-1-5-21-2541319435-247674877-3292285946-1005\Dc9.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addcf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addcw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addeh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addfk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addfs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addgg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addhf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addhp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addid.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addka32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addkh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addkw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addln32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addlq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addmb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addmi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addpr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addrw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addst32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addta.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addte.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addun.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adduo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adduw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addvu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addwa.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addwh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addxo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addzk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apial32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiaq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiaw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apibb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apidc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apidh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apidw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apief32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apieo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apier32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apigd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apihy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiie.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apikw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apile32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apimk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apipk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiqm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apirb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apirs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apitx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiuy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apivo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiwk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appae.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appal32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appao.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appfy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appgo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apphn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apphw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appid32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appig32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appii32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appiw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appix32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appje32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appke.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\applg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\applw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appnp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appqk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appqo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apprl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appte32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appwu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appyw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appzp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlar32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlbf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlcb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlch.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atldo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atled32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlen.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlgf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlin32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atliq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlkl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atllu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlnn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlpj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlps.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlpt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlqs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlqs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlqt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlqx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlte32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atltw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlvx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlwb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlxa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlyc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlzh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlzl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlzw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\control.ini:cvcix -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\control.ini:mrqis -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\control.ini:skatv -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\control.ini:xzzgu -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crer.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crex32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crez.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crki32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crkn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crlt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crmw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crmy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crnv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\croc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crop32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\croz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crpb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crps.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crpz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crqf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crre.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cruz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crvx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crvx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crwy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ctransit.ini:aofql -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ctransit.ini:bfjqa -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ctransit.ini:gnlhl -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ctransit.ini:hktch -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ctransit.ini:ragve -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ctransit.ini:wfcji -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ctransit.ini:wwbpa -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3bk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3dn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ec32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3fi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3gg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3hd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3hw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3in.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ji.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3jj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3jx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3kl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ko32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3kz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ld.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3mc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3nk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3oo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3pc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3qt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ss.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3st32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ue32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3uk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3vc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3vg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\designer.ini:cjjtb -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\designer.ini:gxggn -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\designer.ini:scnuf -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\designer.ini:tlkqp -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\desktop.ini:dpiii -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\desktop.ini:kxxqt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\desktop.ini:nourk -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\desktop.ini:skwsf -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\desktop.ini:yvmyi -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\desktop.ini:zxmaw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSP925.ini:chfbm -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSP925.ini:gfubl -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\EPSP925.ini:tsxge -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:bczlq -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:ddqnb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:eblqv -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:frreq -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:nludy -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:pdrybr -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:tkcsb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:yccrd -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\EPSTPLOG.TXT:ypdzb -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\Film Factory.scr:czrus -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\Film Factory.scr:gbkjy -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\Film Factory.scr:gdnna -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\gefph.txt:dmbux -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:lilud -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\gefph.txt:ojwmw -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:rhxuh -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\gefph.txt:riytc -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:ucayw -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:ugwew -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:vjmsu -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\gefph.txt:xmfao -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieat.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieav32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iedk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iees.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieew.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieez.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iegx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iehh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iejh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iejm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iekf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iekj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iemc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iemw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iepo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieqh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ierx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ietm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieun32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieuq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ievy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieyp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieyw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iezw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\intuprof.ini:gxbmj -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\intuprof.ini:jdscm -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\intuprof.ini:jlagi -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\intuprof.ini:oryyh -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\intuprof.ini:rluxz -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\intuprof.ini:ukcqt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\intuprof.ini:wskhmo -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\intuprof.ini:xrawm -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipah32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipay32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipcw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipcz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipdb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipdi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipep32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipfb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipig.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipil32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipiq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iply.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipmn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipmn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ippp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ippp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipqt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipsr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iptx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipub32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipue.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipva.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipwk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javabb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaco.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javacx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javadz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javafh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javafx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaho32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaia.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaih.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaip.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javakj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javalk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaqp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javarr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javarx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javask.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javath32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaup32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javauz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javawr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javawv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaxj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javazg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javazo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javazw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\KPCMS.INI:daacd -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\KPCMS.INI:dwlur -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\KPCMS.INI:fkrma -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\KPCMS.INI:jnfec -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\KPCMS.INI:ksocn -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\KPCMS.INI:limjx -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\KPCMS.INI:loicu -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\KPCMS.INI:wdtrp -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\lvzbd.txt:tmlqr -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\lvzbd.txt:zpmsh -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\lvzbd.txt:zvlxo -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcbd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcbn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcdl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfchs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfchu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcjg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcjh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcki32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcks.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfckw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfclj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfclz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcmg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcmo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcnp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcos.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcpb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcse32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfctd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfctk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfctz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcvc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcvm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcxq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcxs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcxu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcxz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcyo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcyr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcyr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ModemLog_Lucent Technologies Soft Modem AMR.txt:bkzib -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ModemLog_Lucent Technologies Soft Modem AMR.txt:mivyu -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ModemLog_Lucent Technologies Soft Modem AMR.txt:oounh -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ModemLog_Lucent Technologies Soft Modem AMR.txt:sgrvm -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ModemLog_Lucent Technologies Soft Modem AMR.txt:vnmgc -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msae.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msbg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msby.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msdb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msdfmap.ini:fblnz -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msdfmap.ini:kcsgh -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msdfmap.ini:liafe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msdfmap.ini:pegmk -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msdfmap.ini:upixr -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msdfmap.ini:vmotk -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msdfmap.ini:wplui -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msdfmap.ini:zsrfw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msgo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msgs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mshg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msjh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msju32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msmk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msn.hta:biqhe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msn.hta:ncqvt -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msn.hta:pjrjt -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msn.hta:pmwhd -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msn.hta:qeoyd -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msn.hta:vwnkq -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msns.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mspa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mspb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mspn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mspx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msqm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msqr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msrp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mssb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mstb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msuk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msvi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mswv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mswy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msxj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msya32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netbj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netcs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netde32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netdm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netdp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netdr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\neteb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\neten.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netgq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netin32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netjw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netlx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netmt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netmy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netpf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netrt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netsr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netsz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\nettu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netuc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netux32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netvs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntai.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntcw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntdb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntdh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntdq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntgz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntha32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntig.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntiu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntkf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntlb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntmh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntqj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntqp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntul32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntyr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ODBCINST.INI:edytz -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ODBCINST.INI:qnhuv -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ODBCINST.INI:tgria -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ODBCINST.INI:uayuc -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ODBCINST.INI:ybkli -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ODBCINST.INI:zozaa -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\OEWABLog.txt:altdk -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\OEWABLog.txt:ejtzb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\OEWABLog.txt:macym -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\OEWABLog.txt:tgkcb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\OEWABLog.txt:vjphx -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\OEWABLog.txt:zwgpp -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\orun32.ini:bmzef -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\orun32.ini:demay -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\orun32.ini:dtedx -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\orun32.ini:hidlw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\orun32.ini:ntcyz -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\orun32.ini:pjvry -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\orun32.ini:uotzb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\orun32.ini:zgvhe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\QUICKEN.INI:duwmz -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\QUICKEN.INI:gofzx -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\QUICKEN.INI:jhyoc -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\QUICKEN.INI:pcqdm -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\QUICKEN.INI:pjwsz -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\QUICKEN.INI:prxos -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\QUICKEN.INI:qrkpo -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\qycut.txt:bbtgw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\qycut.txt:kjuvn -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\qycut.txt:qmdvm -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\qycut.txt:qxopn -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\qycut.txt:twfdo -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\qycut.txt:vergk -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\qycut.txt:ypeqq -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\rabsk.txt:beudv -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\rabsk.txt:bvrzg -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\rabsk.txt:fikdz -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\rabsk.txt:gbtwl -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\rabsk.txt:gthub -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\rabsk.txt:hdgtd -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\rabsk.txt:jibma -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\rabsk.txt:upwqw -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:afilk -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:bnoga -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:hndgu -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:jukfx -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:modsd -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:rjddf -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\SchedLgU.Txt:ruehh -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkaf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkah32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkdm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkgm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkhn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkjf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkkv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdklb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkle.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkny32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdksc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdksi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkso32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdktn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkuu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkvk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkxe32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkxk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkyv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\setuplog.txt:dnuev -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\setuplog.txt:eahbe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\setuplog.txt:etvpt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\setuplog.txt:hwbha -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\setuplog.txt:iibik -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\setuplog.txt:sogrq -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\setuplog.txt:xaghv -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:cdhvb -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\smscfg.ini:hklec -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\smscfg.ini:lglwg -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\smscfg.ini:nfsmd -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:owpwt -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:runxj -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:ufwem -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:uigwv -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:wroxt -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\smscfg.ini:yqiac -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\statuslog:afvbq -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\statuslog:lcymf -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\statuslog:uszof -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysai.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysbm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysfg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysfv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysfw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syshp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysib32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysjb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysjx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysla32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syslr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysmr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysou.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysqi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysrv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysrz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syssl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32:ueaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup C:\WINDOWS\system32\addbo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addcs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\adddd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\adddg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addfa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addfv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addhx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addij32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addld.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addlk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addod32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\adduj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addvr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addvr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addvs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addxv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addyc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addze.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiat.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apibs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apief32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiep.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apigv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiib.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiio.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiit32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apijh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apikc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apikj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apilp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apimz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apipx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiqc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apivd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apivi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apivt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apivx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiwh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiyz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apizh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appcg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appcq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appcw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appdh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDO
Remember that if Ad-Watch complains about any changes being made, to allow them all.

Step 1
Open HijackThis, run a scan, then check the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663

O2 - BHO: Class - {09419588-4A35-B532-FA96-5DD0086ED758} - C:\WINDOWS\addka32.dll (file missing)
O2 - BHO: Class - {CB62CFC5-A504-C4EF-3373-D9BABA7029F7} - C:\WINDOWS\crki32.dll (file missing)

O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe


With all other programs and browsers closed, click fix checked.


Step 2
Reboot the computer into Safe Mode and run Ewido again. Make sure to save the log and post it in your next reply.


Step 3
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread. Include the Ewido log.
Please let us know of any complications you had and how the computer is behaving.
Hi Alan,

I did as you requested. No complications but I'm still getting an unwanted Internet Explorer window opening on normal bootup. Opening programs seem slower since installing Ewido but I could be imagining things with that.

Here are the logs:

Logfile of HijackThis v1.99.1
Scan saved at 9:27:10 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 9:15:00 PM, 7/25/2005
+ Report-Checksum: AA699ED6

+ Scan result:

:mozilla.32:C:\Documents and Settings\Paul Davies\Application Data\Netscape\NSB\Profiles\rwk7yykr.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup


::Report End

Thanks as always
It looks like Ad-Watch is blocking the fix. Please uninstall Ad-Watch and Ad-Aware then delete the following folder:

C:\Program Files\Lavasoft.

Reboot the computer.

You can reinstall those programs once the computer is determined to be clean.

Step 1
Open HijackThis, run a scan, then check the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\geujx.dll/sp.html#36663

O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [addby.exe] C:\WINDOWS\system32\addby.exe
O4 - HKLM\..\RunOnce: [ipzp32.exe] C:\WINDOWS\ipzp32.exe
O4 - HKLM\..\RunOnce: [mfccn32.exe] C:\WINDOWS\system32\mfccn32.exe
O4 - HKLM\..\RunOnce: [nthp32.exe] C:\WINDOWS\system32\nthp32.exe
O4 - HKLM\..\RunOnce: [d3nv.exe] C:\WINDOWS\d3nv.exe
O4 - HKLM\..\RunOnce: [netns32.exe] C:\WINDOWS\system32\netns32.exe
O4 - HKLM\..\RunOnce: [sdkas32.exe] C:\WINDOWS\system32\sdkas32.exe
O4 - HKLM\..\RunOnce: [netih.exe] C:\WINDOWS\netih.exe
O4 - HKLM\..\RunOnce: [d3xf32.exe] C:\WINDOWS\system32\d3xf32.exe
O4 - HKLM\..\RunOnce: [sysnm.exe] C:\WINDOWS\system32\sysnm.exe
O4 - HKLM\..\RunOnce: [atlrq32.exe] C:\WINDOWS\atlrq32.exe
O4 - HKLM\..\RunOnce: [mfcup32.exe] C:\WINDOWS\system32\mfcup32.exe
O4 - HKLM\..\RunOnce: [apiux.exe] C:\WINDOWS\system32\apiux.exe
O4 - HKLM\..\RunOnce: [d3xh.exe] C:\WINDOWS\d3xh.exe
O4 - HKLM\..\RunOnce: [apiam32.exe] C:\WINDOWS\apiam32.exe
O4 - HKLM\..\RunOnce: [ieuq.exe] C:\WINDOWS\ieuq.exe
O4 - HKLM\..\RunOnce: [netlm32.exe] C:\WINDOWS\system32\netlm32.exe
O4 - HKLM\..\RunOnce: [systa.exe] C:\WINDOWS\systa.exe
O4 - HKLM\..\RunOnce: [sysol32.exe] C:\WINDOWS\sysol32.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\crtw32.exe
O4 - HKLM\..\RunOnce: [ntfg.exe] C:\WINDOWS\system32\ntfg.exe
O4 - HKLM\..\RunOnce: [crel32.exe] C:\WINDOWS\crel32.exe
O4 - HKLM\..\RunOnce: [appsa32.exe] C:\WINDOWS\appsa32.exe
O4 - HKLM\..\RunOnce: [atlpo32.exe] C:\WINDOWS\atlpo32.exe
O4 - HKLM\..\RunOnce: [javaml32.exe] C:\WINDOWS\system32\javaml32.exe
O4 - HKLM\..\RunOnce: [mfcgk.exe] C:\WINDOWS\system32\mfcgk.exe
O4 - HKLM\..\RunOnce: [iefa32.exe] C:\WINDOWS\system32\iefa32.exe
O4 - HKLM\..\RunOnce: [javavh.exe] C:\WINDOWS\javavh.exe
O4 - HKLM\..\RunOnce: [apirk32.exe] C:\WINDOWS\apirk32.exe
O4 - HKLM\..\RunOnce: [d3hz32.exe] C:\WINDOWS\d3hz32.exe
O4 - HKLM\..\RunOnce: [d3oh.exe] C:\WINDOWS\system32\d3oh.exe
O4 - HKLM\..\RunOnce: [crpi.exe] C:\WINDOWS\crpi.exe
O4 - HKLM\..\RunOnce: [addfx32.exe] C:\WINDOWS\system32\addfx32.exe
O4 - HKLM\..\RunOnce: [msxg32.exe] C:\WINDOWS\msxg32.exe
O4 - HKLM\..\RunOnce: [d3gm32.exe] C:\WINDOWS\d3gm32.exe
O4 - HKLM\..\RunOnce: [atlbg32.exe] C:\WINDOWS\atlbg32.exe
O4 - HKLM\..\RunOnce: [netoc32.exe] C:\WINDOWS\system32\netoc32.exe
O4 - HKLM\..\RunOnce: [ipid.exe] C:\WINDOWS\ipid.exe
O4 - HKLM\..\RunOnce: [addqh32.exe] C:\WINDOWS\system32\addqh32.exe
O4 - HKLM\..\RunOnce: [iptt.exe] C:\WINDOWS\iptt.exe
O4 - HKLM\..\RunOnce: [javayi.exe] C:\WINDOWS\system32\javayi.exe
O4 - HKLM\..\RunOnce: [addgi32.exe] C:\WINDOWS\addgi32.exe
O4 - HKLM\..\RunOnce: [ntcc.exe] C:\WINDOWS\ntcc.exe
O4 - HKLM\..\RunOnce: [ipty32.exe] C:\WINDOWS\system32\ipty32.exe
O4 - HKLM\..\RunOnce: [atlrg32.exe] C:\WINDOWS\atlrg32.exe
O4 - HKLM\..\RunOnce: [atlrw.exe] C:\WINDOWS\atlrw.exe
O4 - HKLM\..\RunOnce: [appaw.exe] C:\WINDOWS\system32\appaw.exe
O4 - HKLM\..\RunOnce: [appdw32.exe] C:\WINDOWS\system32\appdw32.exe
O4 - HKLM\..\RunOnce: [ieul.exe] C:\WINDOWS\ieul.exe
O4 - HKLM\..\RunOnce: [mfczy.exe] C:\WINDOWS\system32\mfczy.exe
O4 - HKLM\..\RunOnce: [javamb.exe] C:\WINDOWS\system32\javamb.exe
O4 - HKLM\..\RunOnce: [mszy32.exe] C:\WINDOWS\mszy32.exe
O4 - HKLM\..\RunOnce: [apizg.exe] C:\WINDOWS\system32\apizg.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [sdktq.exe] C:\WINDOWS\sdktq.exe
O4 - HKLM\..\RunOnce: [winrq32.exe] C:\WINDOWS\system32\winrq32.exe
O4 - HKLM\..\RunOnce: [apixu.exe] C:\WINDOWS\system32\apixu.exe
O4 - HKLM\..\RunOnce: [javawx32.exe] C:\WINDOWS\system32\javawx32.exe


With all other programs and browsers closed, click fix checked.


Step 2
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
Wow, I think you have cracked it!

I haven't re-installed Ad-Aware yet (waiting for you to tell me to do so).

Here is the log: :)

Logfile of HijackThis v1.99.1
Scan saved at 11:28:36 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
Hold off on Ad-Aware for a while yet as there will be some more work to do.

Step#1:Restore Deleted System Files

Now we need to see if we need to restore some deleted files:Please check for the following files using the Windows Search Engine:
  • control.exe
  • rundll32.exe
  • wmplayer.exe
  • msconfig.exe
  • notepad.exe
  • shell.dll
  • SDHelper.dll
If any are missing or not working properly then you can download new copies from
Merijn's Files and following the instructions at that site to have them where they belong for your OS.
  • If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in Win2K or XP. In XP there are two copies of this file, one in Windows (WINNT) and one in Windows\System32. It does not delete the one in Windows\System so it does not affect Win9x/ME. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows (WINNT) and Windows\System32 .
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
Step#2:Download CCleaner
Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Options < Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Click Run Cleaner to run the program.
  • After it has completed it's process, click Exit.
Caution : It is not recommended to use the 'Issues' tab as it is known to find legitimate items.



Step#3:Complete An Online AntiVirus Scan

Run an online antivirus scan at:

Trend Micro-Housecall Online AV

Reboot



Step#4:Find the Infected Files On Your Hard Drive
  • Navigate to C:\Windows
  • look for files that were created at the approximate time and date as the infection occurred.
  • look for those that end in exe, DAT and DLL and if found, right click on the file and check properties. Legitimate files should be copyrighted by Microsoft
  • if you determine they are bad files, right click on them and choose delete
  • Navigate to C:\Windows\System32 and repeat each of the above steps to check for those ending in exe, DAT and/or DLL
  • If the above files will not delete, then make a new folder on your desktop by right clicking on the desktop and choosing New > Folder. Name the folder CWS Files.
  • Move the files from C:\Windows or C:\Windows\System or C:\Windows\system32
    to the new folder CWS Files.
Step#5:Scan And Post a New HijackThis Log

1. Scan again with HijackThis

2. POST your log file using Add Reply to see what is left to fix.
I had a couple of obstacles, this is what happened.

Step #1: No problems, all files were found.

Step #2: No problems, everything cleaned.

Step #3: I couldn't get Houescall to run, I got 3 green lights on navigator 7, navigator 8 and Firefox but an hour went by with only a red X in the java window.

I updated Norton Anti-Virus and did a full system scan, no infections were found.

Step #4: Found no infected files in C:\Windows\System, deleted files in C:\Windows (all had "unknown application" on them with no microsoft or known label. C:\Windows\system32 could not be entered, I made sure "Hide file extensions" and "hide potected" were unchecked and I had "Show hidden files" selected.

Step #5: Did HJT scan.

Logfile of HijackThis v1.99.1
Scan saved at 2:22:10 PM, on 7/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Personal Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Paul Davies\Desktop\hijack_this\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Paul Davies\Application Data\Mozilla\Profiles\default\5s57nrmj.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TIxDSL] C:\PROGRA~1\TIADSL~1\bin\win2k\tidslmon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) - http://142.36.244.87:8888/kxhcm10.ocx
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (Application) (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe

Thank you!
You need to use Internet Explorer or the Netscape browser to run the online Antivirus scan.
If you still have problems running this scan, here is one that can be run using Firefox:

http://fr.trendmicro-europe.com/consumer/p…call_launch.php


Step 1
Open HijackThis, run a scan, then check the following:

Optional items to check with HijackThis for improved performance.
Automatic updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc) Recommended to check here and remove with Add/Remove Programs.
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

With all other programs and browsers closed, click fix checked.


Step 2
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI