This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows will not load completely - keeps crashing

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I'm having a bad problem with Windows. At start up it loads all the programs excepts for Norton Antivirus where a window pops up and says there was an error and could not run program. Then it loads the remaining startup files/programs and then the cursur just goes wild. The hour glass icon keeps coming up as if it is still loading programs or something and never quits. Windows is in standard operating mode eventually crashes everytime. I did manage to squeak out a log file. I already ran Norton AntiVirus on the drive from another computer on my home network and cleaned the drive of the found viruses. I used Norton2005 with the most current virus defs. The best operating mode for now is Windows2000 (Directory Services) Safe Mode.

Any help would be greatly appreciated. -Mark

Here is the log file.

Logfile of HijackThis v1.98.2
Scan saved at 8:08:54 PM, on 9/27/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\mgabg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\PDesk\PDesk.exe
C:\WINNT\system32\hgsiph.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\download\hijack this\HijackThis.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\OPLIMIT\ocrawr32.exe
C:\WINNT\etb\pokapoka70.exe
C:\WINNT\system32\xgh.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PVSW\Bin\w3dbsmgr.exe
C:\PROGRA~1\MICROS~2\Office\Winword.exe
C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seektheglobe.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seektheglobe.com/sp2.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINNT\dsr.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [wxecodg] C:\WINNT\system32\wxecodg.exe
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [System service70] C:\WINNT\etb\pokapoka70.exe
O4 - HKLM\..\Run: [rlutrlf] C:\WINNT\system32\hgsiph.exe r
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [kfmw] C:\PROGRA~1\COMMON~1\kfmw\kfmwm.exe
O4 - HKCU\..\Run: [xgh] C:\WINNT\system32\xgh.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\w3dbsmgr.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {A16C2BF4-501E-45FA-8A14-F26E022D5E16} (MidRadioCtrl Class) - http://adweb.music-eclub.com/php/adweb.php….cab&ptx=mratdl
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\MidRadio.ocx
Hello mjp,

Welcome to the forum, sorry about the delay, if you have not resolved your issue and still need my assistance, you need to update Hijackthis to the latest version and post a new log.

This will install the current version of Hijackthis 1.99.1 in the proper folder.

* It is extremly important that HIJACKTHIS resides in its own folder, we will use it to make changes
to your system, HIJACKTHIS will make backups of those changes. If HIJACKTHIS is not in its own folder,
those backups could be lost.

* Go to MY COMPUTER
* Your C: Drive
* In the column on the left, click on MAKE NEW FOLDER
* Name the folder HIJACKTHIS.
* Follow the link at the bottom of my post to download the current version.
* Download it to a folder that you can find.
* The file will be a zipped File , you will need an Unzipping utility to open it.
* you can download and install the evaluation version of WINZIP here… http://www.winzip.com/
* Use the BROWSE FUNCTION and unzip this file to your new Hijackthis folder on your C: Drive.
* So… it should reside in C:\ HIJACKTHIS\HIJACKTHIS.EXE

Ken :D
All Right here you go Ken. I was barely able to squeak out a log file again. Same problem persisting. Thanks for your help. -Mark

Logfile of HijackThis v1.99.1
Scan saved at 10:31:45 AM, on 10/4/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\mgabg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\yxcoffd.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\OPLIMIT\ocrawr32.exe
C:\WINNT\etb\pokapoka73.exe
C:\WINNT\system32\xgh.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PVSW\Bin\w3dbsmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
C:\HIJACKTHIS\Hijackthis\HijackThis.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seektheglobe.com/sp2.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seektheglobe.com/sp2.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [wxecodg] C:\WINNT\system32\wxecodg.exe
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [System service70] C:\WINNT\etb\pokapoka70.exe
O4 - HKLM\..\Run: [System service73] C:\WINNT\etb\pokapoka73.exe
O4 - HKLM\..\Run: [qabwwzk] C:\WINNT\system32\yxcoffd.exe r
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [kfmw] C:\PROGRA~1\COMMON~1\kfmw\kfmwm.exe
O4 - HKCU\..\Run: [xgh] C:\WINNT\system32\xgh.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\w3dbsmgr.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {A16C2BF4-501E-45FA-8A14-F26E022D5E16} (MidRadioCtrl Class) - http://adweb.music-eclub.com/php/adweb.php….cab&ptx=mratdl
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\MidRadio.ocx
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINNT\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello MJP, :D

You have quite an array of infections going on so for the fixes you may want to print this out so that it will be at your finger tips.

Lets start here….

Go to your ADD-REMOVE PROGRAMS in the CONTROL PANEL and look for this program and remove it if found.
C:\Program Files\SurfSideKick.

Now, download Ewido Security Suite.
http://www.ewido.net/en/
But don't install or run the program yet

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in.
Lavasoft's Ad-Aware
VX2 Cleaner Plug-in
Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

Now lets install and run Ewido.

1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
2. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
3. From the main ewido screen, click on update in the left menu, then click the Start update button.
4. After the update finishes (the status bar at the bottom will display "Update successful")
5. Now close out the program.
6. To run the scanner successfully, you need to reboot your computer into SAFEMODE.

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD
7. Now start the EWIDO Program
8. Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
9. If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
10. When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.


Now reboot normally….

Please download miekiemoes' LQfix batch here:
http://www.downloads.subratam.org/LQfix.zip
Unzip it to the desktop but do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please run LQfix.bat. It may seem like nothing happened, but it did. When finished, restart your computer in normal mode.



Now run HJT SCAN ONLY, put a checkmark in the following entries, close all open windows and your web browser and click on FIX CHECKED

* R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.seektheglobe.com/sp2.php
* R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seektheglobe.com/sp2.php
* R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.seektheglobe.com/sp2.php
* R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
* R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
* R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seektheglobe.com/sp2.php
* R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
* R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
* R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
* R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
* F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
* O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINNT\dsr.dll (file missing)
* O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
* O4 - HKLM\..\Run: [wxecodg] C:\WINNT\system32\wxecodg.exe
* O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
* O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
* O4 - HKLM\..\Run: [System service70] C:\WINNT\etb\pokapoka70.exe
* O4 - HKLM\..\Run: [rlutrlf] C:\WINNT\system32\hgsiph.exe r
* O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
* O4 - HKCU\..\Run: [kfmw] C:\PROGRA~1\COMMON~1\kfmw\kfmwm.exe
* O4 - HKCU\..\Run: [xgh] C:\WINNT\system32\xgh.exe
* O15 - Trusted Zone: http://www.neededware.com
* O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab


Now reboot back into Safemode and Enable windows to show all files and folders.

SHOW HIDDEN FILES AND FOLDERS

* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean


Now look for the following files and folders in RED and delete them

C:\PROGRA~1\COMMON~1\kfmw
C:\Program Files\SurfSideKick 3
C:\WINNT\Nail.exe
C:\WINNT\dinst.exe
C:\WINNT\system32\exp.exe
C:\WINNT\etb\pokapoka70.exe
C:\WINNT\system32\hgsiph.exe r
C:\WINNT\system32\xgh.exe


While in Safemode, lets clean out all your temp and internet temp files.

This process will clean out your TEMP FILES and your TEMPORARY INTERNET FILES. Please do both steps:

Step 1 - DELETE TEMP FILES

* This procedure should be run from SAFEMODE for better results.

* click on START/ RUN and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. You should do this for each user on your system. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others.

* Do this same process for %windir%\temp.

NOW RE-BOOT NORMALLY


Step 2 - DELETE TEMPORARY INTERNET FILES

* Now I want you to open up INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB, (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.

Now lets run a couple of online virus scanners, have them set to AUTO CLEAN OR FIX WHATEVER THEY FIND

http://www.bitdefender.com/scan/licence.php
http://housecall.trendmicro.com/
http://www.pandasoftware.com/activescan/

Now run HJT and post a new log please along with any reports from the virus scanners and let me know how your system is running at the moment.

MJP, you have some serious infections going on, so take your time and do all the fixes in the order listed. I will be online all day tomorrow so please be sure to post back if you run into a snag.

Ken :D
Ok Ken, Thanks for the help things are running a lot smoother.

Here is the Hijack log. I can't seem to get rid of O15 - Trusted Zone: http://www.neededware.com.

Logfile of HijackThis v1.99.1
Scan saved at 4:54:08 PM, on 10/5/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\mgabg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINNT\system32\xgh.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PVSW\Bin\w3dbsmgr.exe
C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HIJACKTHIS\Hijackthis\HijackThis.exe

F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [wxecodg] C:\WINNT\system32\wxecodg.exe
O4 - HKCU\..\Run: [xgh] C:\WINNT\system32\xgh.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\w3dbsmgr.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A16C2BF4-501E-45FA-8A14-F26E022D5E16} (MidRadioCtrl Class) - http://adweb.music-eclub.com/php/adweb.php….cab&ptx=mratdl
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\MidRadio.ocx
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Report for bitfinder

Identified Viruses
14

Infected Files
15

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
15

Report for Panda

Spyware:spyware/surfsidekick No disinfected Data\Sskcwrd.dll
Adware:adware/tvmedia No disinfected Data\tvmknwrd.dll
Adware:adware/pacimedia No disinfected
Bingo.url

Trend Micro was able to remove 2 viruses but the WINNT\system32\wxecodg.exe was undeletable know as
TROJ_DLOADER.XW

Thanks a bunch again

-Mark
MJP,

Glad your doing better, it look like you followed my instructions very well :thumbup: we are almost 90% there, just a few things to clean up and a scan or two to run.

Lets do this…

Open up Internet Explorer
Then go to TOOLS/ INTERNET OPTIONS/ SECURITY/ TRUSTED SITES/ SITES and look for http://www.neededware.com and remove it from the site. OK your way out.

Now reboot into Safemode and make sure that you still have windows enabled to show all files and folders, run HJT Scan ONLY, put a checkmark in the following entries, close all open windows, all you should have open is HJT, and click on FIX CHECKED.

O4 - HKLM\..\Run: [wxecodg] C:\WINNT\system32\wxecodg.exe
O4 - HKCU\..\Run: [xgh] C:\WINNT\system32\xgh.exe
O15 - Trusted Zone: http://www.neededware.com


Now look for and delete the files in RED

C:\WINNT\system32\wxecodg.exe
C:\WINNT\system32\xgh.exe

Search for these 2, I'm not sure where they will be.

Sskcwrd.dll
tvmknwrd.dll



Now reboot normally,

I would like you to install a couple of excellent free programs , Spybot Search and Destroy 1.4 and Ad-Aware SE Personal 1.06. Here are the instructions for both programs. You need to reboot after running one program before you run the other. These programs are not just for cleaning your log as part of the fix, these programs should be updated on a regular basis and run at least once aweek as part of your maintenence scheduale.


Please use the links in my signature to download and install both of the following free programs.

Spybot Search and Destroy 1.4

* If you have the older version 1.3, remove it via ADD-REMOVE PROGRAMS in the Control Panel.

Go to START/ CONTROL PANEL/ PERFORMANCE AND MAINTAINENCE/ ADD-REMOVE
PROGRAMS
scroll to that program and click on REMOVE.

* During Installation, just follow all the defaults.
* Go to MODE and click on ADVANCED MODE.
* Then to SETTINGS / FILE SETS and take the checkmark out of USAGE TRACKS.
* Then to TOOLS/ HOSTS FILE and then on the top click on ADD SPYBOT S & D HOSTS FILES.
* Then to TOOLS/ IE TWEAKS and put a checkmark in LOCK THE HOSTS FILES
* Then check for UPDATES.
* Then to Immunize. then up at the top by the GREEN SIGN, click on IMMUNIZE.
* Then go to the top to SPYBOT and run a FULL SYSTEM SCAN.
* Then to FIX PROBLEMS and fix all it finds.

Then RE-BOOT your computer.


AD-AWARE SE PERSONAL 1.06

If you have an older version of Ad-Aware, no need to uninstall it, it will prompt you to uninstall it during the set up process

* During installation, follow all the defaults.
* Start the program and CHECK FOR UPDATES
* Choose PERFORM FULL SYSTEM SCAN
* Take the checkmark out of SEARCH FOR NEGLIGIBLE RISK FILES
* Run the scan
* When it is done, RIGHT CLICK ON ONE OF THE ENTRIES/ SELECT ALL/ NEXT and let it remove all that if finds.

Now download and run CCleaner, run the scan and let it clean up everything it finds, this is a safe program to run, it will clean out all your temp and internet temp files and more garbage than you care to know about.

Lets run BitDefender again to make sure we didn't miss anything.

Now run HJT and post a new log please along with the results from Bitdefender.
Ok Ken

Bitdefender Results as follows

Identified Viruses
3

Infected Files
3

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
3

And here is the new HJL

Logfile of HijackThis v1.99.1
Scan saved at 2:56:31 AM, on 10/6/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\mgabg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PVSW\Bin\w3dbsmgr.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HIJACKTHIS\Hijackthis\HijackThis.exe

F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\w3dbsmgr.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A16C2BF4-501E-45FA-8A14-F26E022D5E16} (MidRadioCtrl Class) - http://adweb.music-eclub.com/php/adweb.php….cab&ptx=mratdl
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\MidRadio.ocx
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I Think there some stuff that Ewido caught that I ignored that I can take care of too. Here are the ignored files.

C:\WINNT\bsx32\ADBN3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ADTMI1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIB9894.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIC29667.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASID12180.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIE17070.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIF29819.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIF4502.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIFA15376.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIG21943.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIH21180.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIH7853.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASII21469.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIL18549.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASILS29399.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIM4381.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIM9740.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIS24110.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIS31590.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIT17011.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIT26116.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIW11211.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\BID1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\CARD2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\CARS3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\CASH2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\DATE4.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\EECH1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\EML1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\FAST1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\FINC3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\FINC5.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\FMND1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\HEBE3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\HOGAR3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\INK1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\MORT4.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\OPPR3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\TECH2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\TMP3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\TRVL6.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\VENUE1.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\WWW3.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Ignored
C:\WINNT\Downloaded Program Files\CONFLICT.1\EPXActiveX.ocx -> TrojanDownloader.Lastad.r : Ignored
C:\WINNT\dsr.dll -> Spyware.Hijacker.Generic : Ignored
C:\WINNT\dsr.exe -> Trojan.Imiserv.c : Ignored
C:\WINNT\gvqjdmc.exe -> Adware.BetterInternet : Ignored
C:\WINNT\qrxbbqcaz.exe -> Adware.BetterInternet : Ignored
C:\WINNT\system32\bns.exe -> TrojanDownloader.Lastad.p : Ignored
C:\WINNT\system32\epx30106.exe -> TrojanDownloader.Lastad.r : Ignored
C:\WINNT\system32\hcmpchndw30102lib.dll -> TrojanDownloader.Lastad.h : Ignored
C:\WINNT\system32\medgs1.exe -> Spyware.Hijacker.Generic : Ignored
C:\WINNT\system32\MTE2ODM6ODoxNg.exe -> Spyware.ISearch : Ignored
C:\WINNT\system32\NNSCAA638.EXE -> Spyware.NewDotNet : Ignored
C:\WINNT\system32\qool3.exe -> TrojanDropper.Agent.hl : Ignored
C:\WINNT\system32\sav2.exe -> TrojanDownloader.Agent.vp : Ignored
C:\WINNT\system32\wxecodg.exe -> TrojanDownloader.Lastad.r : Ignored
C:\WINNT\system32\wxecodgaeg06.dll -> TrojanDownloader.Lastad.r : Ignored
C:\WINNT\Temp\ClrSch\FNuninstaller.EXE -> Spyware.ClearSearch : Ignored
E:\WINDOWS\fash.exe -> Backdoor.Agent.bg : Ignored
E:\WINDOWS\SYSTEM32\sub2b.exe -> Spyware.FastFind : Ignored
E:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\wt\wtupdates\WTWebDriver\files\2.2.0.100\wtvh.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\wt\wtupdates\WTWebDriver\files\3.0.0.173\wtvh.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\wt\wtupdates\WTWebDriver\files\3.0.0.173\npwthost.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\wt\wtupdates\WTWebDriver\files\3.1.0.037\wtvh.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\wt\wtupdates\WTWebDriver\files\3.1.0.037\npwthost.dll -> Spyware.WildTangent : Ignored
E:\WINDOWS\NDNuninstall4_50.exe -> Spyware.NewDotNet : Ignored
E:\WINDOWS\NDNuninstall4_80.exe -> Spyware.NewDotNet : Ignored
E:\WINDOWS\NDNuninstall5_20.exe -> Spyware.NewDotNet : Ignored
E:\WINDOWS\NDNuninstall5_40.exe -> Spyware.NewDotNet : Ignored
E:\WINDOWS\NDNuninstall5_64.exe -> Spyware.NewDotNet : Ignored
E:\WINDOWS\NDNuninstall6_10.exe -> Spyware.NewDotNet : Ignored
E:\Program Files\Common Files\Presentia\pmr.exe -> Spyware.Suggestor : Ignored
E:\Program Files\Netscape\Communicator\Program\Plugins\npwthost.dll -> Spyware.WildTangent : Ignored
E:\Program Files\WildTangent\Components\SystemConfig0100.dll.mwt -> Spyware.WinAD : Ignored
E:\Program Files\NewDotNet\uninstall6_10.exe -> Spyware.NewDotNet : Ignored
E:\Program Files\Save\SaveUninst.exe.mwt -> Adware.SaveNow : Ignored
E:\Documents and Settings\Default\Cookies\default@com[1].txt -> Spyware.Cookie.Com : Ignored
E:\Documents and Settings\Default\Cookies\default@bankads[1].txt -> Spyware.Cookie.Bankads : Ignored
E:\Documents and Settings\Default\Cookies\default@preferences[1].txt -> Spyware.Cookie.Preferences : Ignored
E:\Documents and Settings\Default\Cookies\default@linkbuddies[2].txt -> Spyware.Cookie.Linkbuddies : Ignored
E:\Documents and Settings\Default\Cookies\default@click2net[2].txt -> Spyware.Cookie.Click2net : Ignored
E:\Documents and Settings\Default\Cookies\[removed][1].txt -> Spyware.Cookie.Preferences : Ignored
E:\Documents and Settings\Default\Cookies\default@ads.link4ads[1].txt -> Spyware.Cookie.Link4ads : Ignored
E:\Documents and Settings\Default\Cookies\[removed][2].txt -> Spyware.Cookie.Porntrack : Ignored
E:\Documents and Settings\Default\Cookies\default@enliven[1].txt -> Spyware.Cookie.Enliven : Ignored

Thanks

-Mark


Note that the Ewido scan was one of the first scans I ran so alot may have already been taken care of on the latter scans, but I know for sure the bsx32 folder is still there and looks like I can delete it.
Good Morning mjp,

Your log is looking real good, although some of these may be hidden. Wild Tangent usually comes bundled when downloading games, I know for a fact that it comes with AOL Instant Messenger. If you don't need that program, you can go to the ADD-REMOVE PROGRAMS in the CONTROL PANEL and remove it. Also look for NewDotNet and Save and definitly remove them.

E:\Program Files\WildTangent
E:\Program Files\NewDotNet
E:\Program Files\Save

Reboot back into Safemode and make sure that you still have windows enabled to SHOW ALL FILES AND FOLDERS These may be gone, but lets doublecheck. If found, delete the files and folders in RED


E:\Program Files\WildTangent
E:\Program Files\NewDotNet
E:\Program Files\Save
C:\WINNT\bsx32
C:\WINNT\dsr.dll
C:\WINNT\dsr.exe
C:\WINNT\gvqjdmc.exe
C:\WINNT\qrxbbqcaz.exe
C:\WINNT\system32\bns.exe
C:\WINNT\system32\epx30106.exe
C:\WINNT\system32\hcmpchndw30102lib.dll
C:\WINNT\system32\medgs1.exe
C:\WINNT\system32\MTE2ODM6ODoxNg.exe
C:\WINNT\system32\NNSCAA638.EXE
C:\WINNT\system32\qool3.exe
C:\WINNT\system32\sav2.exe
C:\WINNT\system32\wxecodg.exe
C:\WINNT\system32\wxecodgaeg06.dll

E:\WINDOWS\fash.exe
E:\WINDOWS\SYSTEM32\sub2b.exe
E:\WINDOWS\wt

Now download, install and run CCleaner It is a safe program to run, it will clean out all your Temp and Internet Temp files plus more garbage than you want to know about.

Post a new HJT log when done please
Ok Ken here is the latest HJL

Logfile of HijackThis v1.99.1
Scan saved at 11:48:48 AM, on 10/6/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\mgabg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ntvdm.exe
C:\WINNT\System32\PDesk\PDesk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\PVSW\Bin\w3dbsmgr.exe
C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HIJACKTHIS\Hijackthis\HijackThis.exe

F3 - REG:win.ini: load=C:\OPLIMIT\ocraware.exe
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINNT\System32\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\w3dbsmgr.exe
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Premier - Accountant Edition\Components\QBAgent\qbdagent2002.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A16C2BF4-501E-45FA-8A14-F26E022D5E16} (MidRadioCtrl Class) - http://adweb.music-eclub.com/php/adweb.php….cab&ptx=mratdl
O18 - Filter: text/x-mrml - {C51721BE-858B-4A66-A8BF-D2882FF49820} - C:\Program Files\YAMAHA\MidRadio Player\MidRadio.ocx
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: MGABGEXE - Matrox Graphics Inc. - C:\WINNT\System32\mgabg.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
mjp,

Your log looks very clean, no signs of either a malware or virus infection. :thumbup: There are some optional fixes we can take care of, but only if you feel that your computer is not running as smoothly as it once did.

I am going to post a bunch of tips and free programs that I urge you to install to help keep your system more secure. Some of the fixes you have done already like clean the temp folder, you can bypass that one and download and install CCleaner, it will do the job for you. One thing that you have to do for sure is follow the instructions for System Restore, because everything we (YOU) worked at cleaning off your system is backed up in System Restore and if you should ever try to use that program to revert your system to a prevous date, you will be infected all over again.

Here we go……..

Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

*Run CCleaner, this is a very safe program that will clean out all the crapola on your system. It will also remove cookies,
so go to OPTIONS/ COOKIES and move the ones you want to keep from the left window to the right window.

* Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.
* Clean out your TEMP FILES
* This procedure should be run from SAFEMODE for better results.

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD

Now, while in SAFEMODE,

* click on START/ RUN, and type %temp% and press the ok button.

This will open up the temp directory that your machine uses. GO TO EDIT/ SELECT ALL and delete all the contents of that folder.
* Do this for each user of your computer.
* Do this same process for%windir%\temp.

NOW RE-BOOT NORMALLY

DELETE TEMPORARY INTERNET FILES

* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB, (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.


Now Empty your Recycle Bin


* Now we need to TURN OFF> TURN BACK ON SYSTEM RESTORE .

This will remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent
any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points
which are likely to be infected)


Turn off System Restore.

* On the Desktop, right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore.
* Click Apply, and then click OK.


Reboot your System


Turn ON System Restore.

* On the Desktop, right-click My Computer.
* ClickProperties.
* Click the System Restore tab.
* UN-Check Turn off System Restore.
* Click Apply, and then click OK.
* Now while in System Restore, create a new Restore Point.

* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.
* If you want to use a free program, try this excellent one.
http://free.grisoft.com/doc/1

* Run SPYBOT SEARCH AND DESTROY 1.4 > CHECK FOR UPDATES > IMMUNIZEand run a full system scan on a regular basis.
http://www.safer-networking.org/en/mirrors/index.html

* Run AD-AWARE SE PERSONAL/ CHECK FOR UPDATES and run a FULL SYSTEM SCAN on a regular basis.
http://www.download.com/3000-2144-10045910…page&tag;=button

* Download and run SPYWARE BLASTER,
* Check for updates and enable all protection. This program will just sit in the background and help keep all the bad guys out.
http://www.javacoolsoftware.com/

* Download and install WINPATROL
* This program will warn you when any changes are being made to your system and give you the option to deny the change.
http://www.winpatrol.com/download.html

* IE-SPYAD is a one time install, it will put 1000s of bad sites in your Internet Explorer Restricted Zone.
http://www.pcworld.com/downloads/file_down…23332&fileidx;=1

* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER> GO TO PROPERTIES> AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.

* Consider surfing the net with the FireFox Browser
It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you use this for awhile, you will want to make it your default.
http://www.mozilla.org/products/firefox/

* There companion THUNDERBIRD MAIL program was highly favored in PCWorld Magazine,, this to has a good spam filter and is more secure than Outlook Express.
http://www.mozilla.org/products/thunderbird/

* Now go to START/ CONTROL PANEL> PERFROMANCE AND MAINTENANCE> REARRANGE ITEMS ON YOUR HARD DISK TO MAKE PROGRAMS RUN FASTER
This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good.
The first time you run it, it may take awhile.

* Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
http://www.pcworld.com/downloads/file_desc…fid,7228,00.asp

I will leave this thread open for a day or two in case you have any questions, otherwise, thanks for using Tom Coyote and we are happy we could help you.

Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI