This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help!

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi!

i think my system is infected with aurora. i have run several spyware/adware removal programs and followed instructions on manual removal but it's still there.
pls help. thanks!

here's the logfile:

Logfile of HijackThis v1.99.1
Scan saved at 5:31:21 PM, on 8/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GMTService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
c:\windows\system32\oaixva.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\Program Files\hjkthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ntu.edu.sg/proxy.pac
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsvA.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [filcdx] c:\windows\system32\oaixva.exe r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EasyDVDPlayer] "C:\Program Files\EasyDVD\EasyDVD.EXE /min"
O4 - Startup: RealJ.lnk = C:\Program Files\RealJ\RealJ.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab28578.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105024794216
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O23 - Service: GMT-Service - Unknown owner - C:\WINDOWS\System32\GMTService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Hello littlestar, welcome to the TC.

Download Ewido, install then from within the program check for updates BUT dont scan yet
ewido security suite: http://fileforum.betanews.com/detail/ewido…te/1098736486/1
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK.
We will fix this in a moment.
From the main ewido screen, click on update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful"), Now close the program.
Do NOT run a scan yet.

Notes: If you already have the program please make sure its version 3.5 you have and updated.
If the program just exits before it finishes start it again and set it up to do a custom scan:
Start the program click the scan button over to the left click custom scan, click add drive/directory/file
and add c:\documents and settings\
add c:\windows\
add c:\windows\system32\ also, then click start scan, have it remove everything found.

Please download Nailfix from here:
http://www.noidea.us/easyfile/file.php?dow…050711214630636
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

use Add/Remove Programs and remove:
Gain

Next please run HijackThis, click Scan, and check:

O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsvA.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe

O4 - HKLM\..\Run: [filcdx] c:\windows\system32\oaixva.exe r

O4 - Startup: RealJ.lnk = C:\Program Files\RealJ\RealJ.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe

O23 - Service: GMT-Service - Unknown owner - C:\WINDOWS\System32\GMTService.exe


Close all open windows except for HijackThis and click Fix Checked.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Hi LDTate. thanks for ur help! sorry i took a long time. had some problems with the procedure. i cant update ewido. it stays at the connecting status for a very long time and nothing happens. i also cant run nailfix. it says setup files are corrupted. have tried to download again but the same thing happens. pls help. thanks again!
Go ahead and run the Ewido scan without the update and the rest of the fix.

Restart your computer in Safe Mode.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

use Add/Remove Programs and remove: If listed
Gain
GMT
Gator


Next please run HijackThis, click Scan, and check:

O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsvA.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe

O4 - HKLM\..\Run: [filcdx] c:\windows\system32\oaixva.exe r

O4 - Startup: RealJ.lnk = C:\Program Files\RealJ\RealJ.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe

O23 - Service: GMT-Service - Unknown owner - C:\WINDOWS\System32\GMTService.exe


Close all open windows except for HijackThis and click Fix Checked.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
hi!

i cant find the files Gain, GMT or Gator in Add/Remove Programs.

here's the ewido scan report:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 1:03:50 AM, 9/1/2005
+ Report-Checksum: F2F6A7FC

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{04079851-5845-4dea-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0494D0D9-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\saap -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\saap -> Spyware.180Solutions : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-1454471165-1844237615-682003330-1003\Software\saap -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-1454471165-1844237615-682003330-1003\Software\SiteIcons -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1454471165-1844237615-682003330-1003\Software\SiteIcons\Dialers -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1454471165-1844237615-682003330-1003\Software\SiteIcons\Dialers\HotParty_sg -> Dialer.Generic : Cleaned with backup
[696] VM_00F80000 -> Adware.BetterInternet : Error during cleaning
[812] c:\windows\system32\svwdrq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nsvA.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\svwdrq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\zaootjq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\Q678340.exe -> TrojanDownloader.Small.rr : Cleaned with backup
C:\WINDOWS\NDNuninstall5_40.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall5_64.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_10.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_22.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_30.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\fuzaucfcds.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\webhdll.dll_tobedeleted -> Spyware.WebHancer : Cleaned with backup
C:\Documents and Settings\joker\Local Settings\Temporary Internet Files\Content.IE5\8LMV89AJ\thin-94-1-x-x[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\joker\Cookies\joker@oxcash[1].txt -> Spyware.Cookie.Oxcash : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][1].txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\joker\Cookies\joker@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][2].txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
C:\Documents and Settings\joker\Cookies\joker@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\joker\Cookies\[removed][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\joker\Cookies\joker@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\me!\Local Settings\Temp\Cookies\me!@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\me!\Local Settings\Temp\wh.exe/whAgent.exe -> Spyware.WebHancer : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz6.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@image.masterstats[2].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz4.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz9.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@vip.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz7.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz5.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz8.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@free.wegcash[2].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@as-us.falkag[2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@xxxcounter[1].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@www.myaffiliateprogram[2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@www.etracker[1].txt -> Spyware.Cookie.Etracker : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cz3.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@server.iad.liveperson[1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@programs.wegcash[1].txt -> Spyware.Cookie.Wegcash : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@paycounter[2].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\me!\Cookies\me!@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\me!\.jpi_cache\file\1.0\BlackBox.class-6b558204-129406a6.class -> Trojan.Java.ClassLoader.f : Cleaned with backup
C:\Documents and Settings\me!\.jpi_cache\file\1.0\Dummy.class-4ffef27c-76901d53.class -> Trojan.ClassLoader.Dummy.d : Cleaned with backup
C:\Documents and Settings\me!\.jpi_cache\file\1.0\VerifierBug.class-42ffba92-4a80096b.class -> Trojan.Byteverify : Cleaned with backup
C:\Program Files\Windows Media Player\wmplayer.exe.tmp -> TrojanDownloader.Small.ka : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\F3HTMLMU.DLL -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MY2NS.EXE -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MYWAYPLUGINPROXY.CLASS -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\NPMYWAY.DLL -> Spyware.MyWay : Cleaned with backup
C:\Program Files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP116\A0042463.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042505.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042509.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042515.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042548.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042556.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042579.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042581.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042600.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042601.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042651.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042657.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042691.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042696.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042702.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042708.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042724.dll -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042725.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042756.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP117\A0042761.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042778.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042818.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042845.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042852.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042856.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042876.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042882.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042902.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP118\A0042911.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP119\A0042921.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP119\A0042922.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP119\A0042923.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP119\A0042927.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP119\A0042930.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042942.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042955.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042961.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042973.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042975.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042986.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0042994.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043001.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043005.exe -> Spyware.180Solutions : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043014.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043016.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043027.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043033.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043036.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043042.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043052.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043053.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043056.dll -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043057.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043059.dll -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043064.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043091.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043098.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043128.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043161.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043177.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043187.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043188.dll -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043192.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043193.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043194.exe -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043196.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043197.dll -> Spyware.WebHancer : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043214.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0043216.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044210.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044233.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044239.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044255.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044262.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044264.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044299.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP120\A0044307.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044315.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044317.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044344.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044347.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044356.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044363.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044387.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044398.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0044405.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045400.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045407.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045430.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045431.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045447.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045449.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045456.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045466.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045473.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045479.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP121\A0045484.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045522.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045534.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045539.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045552.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045564.exe -> Adware.BetterInternet : Cleaned with backup
C:\Recycled\Q678340.exe -> TrojanDownloader.Small.rr : Cleaned with backup
C:\Recycled\Q330995.exe -> Trojan.Small.af : Cleaned with backup


::Report End




here's hijackthis logfile before fixing the checked items:

Logfile of HijackThis v1.99.1
Scan saved at 1:07:06 AM, on 9/1/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\ctfmon.exe
c:\windows\system32\tstctgl.exe
C:\Program Files\hjkthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ntu.edu.sg/proxy.pac
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsvA.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [nzvqawq] c:\windows\system32\tstctgl.exe r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EasyDVDPlayer] "C:\Program Files\EasyDVD\EasyDVD.EXE /min"
O4 - Startup: RealJ.lnk = C:\Program Files\RealJ\RealJ.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab28578.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105024794216
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: GMT-Service - Unknown owner - C:\WINDOWS\System32\GMTService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe

here's the logfile after fixing checked items:

Logfile of HijackThis v1.99.1
Scan saved at 1:17:19 AM, on 9/1/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\Explorer.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINDOWS\System32\ctfmon.exe
c:\windows\system32\vyvuie.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\hjkthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ntu.edu.sg/proxy.pac
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [hsonqdo] c:\windows\system32\vyvuie.exe r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EasyDVDPlayer] "C:\Program Files\EasyDVD\EasyDVD.EXE /min"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab28578.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105024794216
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe


pls tell me what to do next. thanks!
Download Process Explorer from http://www.sysinternals.com/Utilities/ProcessExplorer.html

Run Process Explorer and find the Process in the list of Processes:
vyvuie.exe
Select the process and click Process > Suspend.

Then in HijackThis click Config > Misc Tools > Delete a file on reboot…
In the explorer Window select the file

When prompted if you want to reboot click YES
Leave Process explorer running with the process suspended.

After the reboot check the following items in HijackThis.
Close all windows except HijackThis and click Fix checked:


F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [hsonqdo] c:\windows\system32\vyvuie.exe r
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Delete these files if listed:
C:\WINDOWS\Nail.exe
c:\windows\system32\vyvuie.exe r
C:\WINDOWS\svcproc.exe


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Post removed

ONLY authorized members are allowed to reply to topics in this forum. This is due to damage that can be caused by improper advice.
Hi LDTate. I cant find hsonqdo in process explorer as well. i assume i dont have to boot into safe mode? i did all these in normal mode.

In HijackThis: Config > Misc Tools > Delete a file on reboot, i cant find the file
i cant find this item in HijackThis also:
O4 - HKLM\..\Run: [hsonqdo] c:\windows\system32\vyvuie.exe r

and lastly, when i try to fix the items, the HijackThis screen became blank and nothing happens even after a long time. then i tried to scan again and the checked items appear again.

i have deleted C:\WINDOWS\Nail.exe, and C:\WINDOWS\svcproc.exe from windows explorer. but after reboot, they appear again. there's no c:\windows\system32\vyvuie.exe r

here's the most recent log. pls tell me what to do next. thanks!

Logfile of HijackThis v1.99.1
Scan saved at 11:36:34 PM, on 9/2/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
c:\windows\system32\tcgqhvw.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\hjkthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ntu.edu.sg/proxy.pac
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [xnznegw] c:\windows\system32\tcgqhvw.exe r
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EasyDVDPlayer] "C:\Program Files\EasyDVD\EasyDVD.EXE /min"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab28578.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105024794216
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

First, download Ewido Security Suite. You already have this.

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in. Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.
Hi LDTate. i cant seem to update any of those wares. but i run them anyway. here's the log from ewido:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 1:41:02 AM, 9/4/2005
+ Report-Checksum: 71B85104

+ Scan result:

C:\Documents and Settings\me!\Cookies\me!@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045570.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045571.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045572.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045573.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045574.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045575.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045576.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045577.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045578.exe -> Spyware.NewDotNet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045579.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045580.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045581.EXE -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045582.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045583.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045584.DLL -> Spyware.MyWay : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045585.exe -> TrojanDownloader.Small.rr : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045586.exe -> Trojan.Small.af : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045598.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045613.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045626.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045638.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045650.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045666.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045672.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045678.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045690.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045708.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045728.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{DC0CDC7D-7F5A-4E1F-86E2-3A5E3A0632E2}\RP122\A0045732.exe -> Adware.BetterInternet : Cleaned with backup


::Report End


here's hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 1:43:30 AM, on 9/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
C:\Program Files\Norton Internet Security\IAMAPP.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\Program Files\hjkthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.ntu.edu.sg/proxy.pac
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EasyTuneIV] C:\Program Files\Gigabyte\EasyTune4\ET4Tray.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EasyDVDPlayer] "C:\Program Files\EasyDVD\EasyDVD.EXE /min"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab28578.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105024794216
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D


You need to update both Windows XP and Internet Explorere as they are both well behind in updates. They are both missing Service Pack 1 which is leaving you open to all kinds of problems.


Service Pack 1 for XP

http://www.microsoft.com/windowsxp/downloa…p1/default.mspx

Service Pack 1 for Internet Explorer.

http://www.microsoft.com/windows/ie/downlo…p1/default.mspx

Install then Reboot and "copy/paste" a new log file into this thread.
Thank you so much LDTate! my com looks like its running fine now. It'll take me some time to do the windows update (that's why i rarely do that). once it's installed i'll post my log. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI