This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ABI,Aurora, Winfixer and...........

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please look at my log.
Getting popups fron Winfixer,Aurora and ABI network and others. Let me thank you in advance ,the services provided are greatly appreciated. :(


Logfile of HijackThis v1.99.1
Scan saved at 7:06:22 PM, on 8/17/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\qucyaq.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\zvrxouvp.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [sgenfyu] C:\WINDOWS\System32\qucyaq.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107301280175
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
Hi double bonus, I will be handling your log to help you get cleaned up. Please give me some time to look it over and I will get back to you as soon as possible.
Fix created by didom
————————

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit ewido. DO NOT scan yet.
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates

Download CleanUp
Install the program, dont run it yet, we will later.

Please download this file: Nailfix Utility
Save it to your desktop.
DO NOT run it yet.

Download dsrfix.zip
Save it to your desktop.
  • Unzip dsrfix.zip and extract it to your desktop.
  • This will create a new folder on your desktop named dsrfix.
  • Do Not open that folder yet.
Please download APT and unzip the contents to a new folder on your desktop.
  • Open the folder you just created and click on apt.exe and search in the window for sgenfyu.
  • Open your C:\Windows\system32 folder and search for qucyaq.exe.
    Don't delete it yet, just leave the system32 folder open so you can see the bad file.
  • In APT again, Select sgenfyu and Click Kill3
  • Then immediately delete qucyaq.exe from your system32 folder.
Close APT.

To reboot into SafeMode with Windows XP, you can follow these steps from Microsoft:

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, start tapping press F8 key.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Once in Safe Mode, please double-click on nailfix.exe.
Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish".
Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Now open ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Now scan with HJT and place a checkmark next to each of the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\zvrxouvp.dll
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [sgenfyu] C:\WINDOWS\System32\qucyaq.exe r

Close all open windows except for HJT, then click the Fix Checked button. Close HJT.

Now open the folder dsrfix on your desktop.
  • Double-Click on dsrfix.bat
  • A window will pop up briefly then close, this is normal.
Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK

Now using Windows Explorer find and remove the following folders/files:


Now run the CleanUp program:

*IMPORTANT NOTE*
CleanUp deletes EVERYTHING out of your temp/temporary folders, it does not make backups.
If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp

Running CleanUp
  • Start CleanUp by double-clicking the icon on your desktop (or from the Start > All Programs menu).
  • When CleanUp starts go to the Options button (right side of CleanUp screen)
  • Move the arrow down to "Custom CleanUp!"
  • Now place a checkmark next to the following (Make sure nothing else is checked!):
    • Delete Cookies
      This is optional, if you leave the box checked it will remove all of your cookies, at this point removing cookies is a good idea
    • Empty Recycle Bins
    • Delete Prefetch files
    • Cleanup! All Users
  • Click OK
  • Then click on the CleanUp button. This will take a short while, let it do its thing.
  • When asked to reboot system select No
  • Close CleanUp
Finally, restart your computer back into Normal Mode and please post a new HJT log, as well as the ewido report log from the Ewido scan by using Add Reply
Sorry I didn't respond sooner,my MB went south.

Logfile of HijackThis v1.99.1
Scan saved at 11:34:46 AM, on 9/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\qybuza.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\OLDD\Hijack This\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\OLDD\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\System32\pkshqfmh.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [cpfnspv] C:\WINDOWS\System32\qybuza.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\OLDD\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107301280175
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\vagbreg.exe (file missing)



+ Scan result:

[792] C:\WINDOWS\System32\ysfraq.exe -> Trojan.Agent.cp : Cleaned with backup
[1024] VM_00EA0000 -> Adware.BetterInternet : Error during cleaning
C:\WINDOWS\SYSTEM32\nsw20.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nso26.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsk32.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsi38.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsb46.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsw55.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsg1A.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsz2C.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsb3C.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsu4A.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\nsm5A.dll -> Spyware.Beginto : Cleaned with backup
C:\WINDOWS\SYSTEM32\ysfraq.exe -> Trojan.Agent.ay : Cleaned with backup
C:\WINDOWS\SYSTEM32\pkshqfmh.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\SYSTEM32\pshwr.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\offun.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\vagbreg.exe -> TrojanDropper.Agent.tb : Cleaned with backup
C:\WINDOWS\ydiokfy.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\WINDOWS\puigjppukjv.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Linda\Local Settings\Temp\sntaudio.tmp -> Spyware.SafeSurfing : Cleaned with backup
C:\Documents and Settings\Linda\Local Settings\Temporary Internet Files\Content.IE5\01234567\Nail[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Linda\Local Settings\Temporary Internet Files\Content.IE5\GLYRODAN\svcproc[1].exe -> Trojan.Stervis.f : Cleaned with backup
C:\Documents and Settings\Linda\Local Settings\Temporary Internet Files\Content.IE5\GLYRODAN\abiuninst[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Linda\Local Settings\Temporary Internet Files\Content.IE5\KZY98FQD\Poller[1].exe -> Trojan.Agent.ay : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\[removed][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022899.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022900.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022901.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022902.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022903.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022904.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022905.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022906.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022907.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0022909.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0023083.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0023084.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0023085.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP399\A0023086.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023342.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023343.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023344.exe -> Trojan.Stervis.f : Cleaned with backup
:mozilla.12:C:\RECYCLED\NPROTECT\00001716.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.13:C:\RECYCLED\NPROTECT\00001716.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.14:C:\RECYCLED\NPROTECT\00001716.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.15:C:\RECYCLED\NPROTECT\00001716.MOZ -> Spyware.Cookie.Falkag : Cleaned with backup


There was 4800 objects found in Ewido. It was to long to post all of it.
All the rest of the log continues with the last 4 lines displayed. All of them being basicly the same: mozilla….:C\RECYCLED\NPROTECT\000017…….MOZ->
The complete file is almost 1MB!!
Is what I posted sufficent or do you need all the rest?
BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

First, download Ewido Security Suite. <<–You already have this, so no need to download it again.

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in. Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.
Logfile of HijackThis v1.99.1
Scan saved at 6:26:22 AM, on 9/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wuauclt.exe
C:\OLDD\Hijack This\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\OLDD\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\System32\pkshqfmh.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\OLDD\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107301280175
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\vagbreg.exe (file missing)




ewido security suite - Scan report
———————————————————

+ Created on: 6:25:21 AM, 9/5/2005
+ Report-Checksum: 750E8BCC

+ Scan result:

[1124] C:\WINDOWS\System32\hhpeskt.exe -> Trojan.Agent.cp : Cleaned with backup
C:\WINDOWS\SYSTEM32\hhpeskt.exe -> Trojan.Agent.ay : Cleaned with backup
C:\WINDOWS\puigjppukjv.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023346.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023347.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023348.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023349.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023350.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023351.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023352.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023353.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023354.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023355.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023356.dll -> Spyware.Beginto : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023357.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023358.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023359.exe -> TrojanDownloader.VB.hw : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023360.exe -> TrojanDropper.Agent.tb : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023361.EXE -> TrojanDownloader.VB.hw : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023362.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023363.EXE -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023365.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023384.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023387.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023394.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023396.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023398.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023399.exe -> Trojan.Stervis.f : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023405.exe -> Trojan.Agent.ay : Cleaned with backup
click Start> Run> type in CMD tap enter. Copy/Paste the following into command prompt:

sc delete Windows Overlay Components

At the command prompt: type exit.


Use HijackThis to delete the service. You can click on Config, then Misc Tools, and then press the Delete an NT service.. button. When it opens you should then enter Windows Overlay Components and press OK.

Open C:\WINDOWS\vagbreg.exe <–Delete file if listed.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: PicShow Class - {4487598C-2EC7-43A2-870E-6D8D720FDD9F} - C:\WINDOWS\System32\pkshqfmh.dll (file missing

O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\vagbreg.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I've gone through these log enough times that I still see a couple of entries that I've been told to delete before!


Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\wvcvuu.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\OLDD\Hijack This\HijackThis.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\OLDD\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [imqjmd] C:\WINDOWS\System32\wvcvuu.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\OLDD\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107301280175
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
We are making headway :thumbup:
We need to run these again:


click Start> Run> type in CMD tap enter. Copy/Paste the following into command prompt:

sc delete SvcProc

At the command prompt: type exit.

Use HijackThis to delete the service. You can click on Config, then Misc Tools, and then press the Delete an NT service.. button. When it opens you should then enter the service name, SvcProc and press OK.

Open C:\WINDOWS\svcproc.exe <–Delete file if listed.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O4 - HKLM\..\Run: [imqjmd] C:\WINDOWS\System32\wvcvuu.exe r

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"

Open C:\WINDOWS\System32\wvcvuu.exe <–Delete File



Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • You don't need to install again, just run per instructions
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.

205060

Logfile of HijackThis v1.99.1
Scan saved at 7:29:08 PM, on 9/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
C:\WINDOWS\System32\wfxsnt40.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\OLDD\Hijack This\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\OLDD\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WINFAX\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - RES://C:\OLDD\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1107301280175
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe



———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 7:26:18 PM, 9/6/2005
+ Report-Checksum: F0ABC2A8

+ Scan result:

C:\WINDOWS\puigjppukjv.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Linda\Cookies\linda@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\yvecqtrb.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP407\A0023345.dll -> Trojan.Agent.db : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023400.dll -> Trojan.Agent.db : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023464.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023468.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023470.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023471.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023472.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP409\A0023479.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP410\A0023480.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP410\A0023486.exe -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP410\A0023487.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP411\A0023488.EXE -> Trojan.Stervis.f : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP411\A0023491.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP411\A0023492.dll -> Trojan.Agent.db : Cleaned with backup
C:\System Volume Information\_restore{1244E20A-D509-46E7-B7EE-A2D0E553698A}\RP411\A0023495.exe -> Trojan.Agent.ay : Cleaned with backup
C:\RECYCLED\Dc1.exe -> Trojan.Stervis.f : Cleaned with backup


::Report End
Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI