This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Continual Redirected Browser, Browser opens by itself

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 8:47:48 PM, on 26/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Jowie\Desktop\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\System32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Miranda IM.lnk = C:\Program Files\Miranda IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110518650500
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\irnsl5571.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sm93aWUA\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Unknown owner - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe (file missing)
O23 - Service: Panda anti-virus service (PAVSRV) - Unknown owner - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

If someone could check this and reply would be greatly appreciated… Dave
Hello jowie53,

Welcome to Tom Coyote, it looks like you have a couple of infections going on, so lets get out ducks in a row by downloading the following programs before we get started.

DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix,
* just go to MY COMPUTER > YOUR C:\ DRIVE and create a new folder and name it HIJACKTHIS .
* Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
* Now open the new folder you just created and right click within that folder and select PASTE .
* Now HJT should reside in C:\HIJACKTHIS\HIJACKTHIS.EXE



Download Pocket Killboxand put it on your desktop

Download CCleanerand install it.
Don't run it yet.

You already have Ewido installed so start the program/ check for updates/ then close out the program.

Reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key (or F5 on some computers)
Use the arrow keys to highlight Safe Mode and press the Enter key.


When your computer is booted into Safe Mode, then continue.

Now Click Start>> Run>> Type in Services.msc and Click OK!

Scroll that list and locate

Command Service (cmdService)

Right Click that entry and Select "Properties">> Click "Stop">> Go up and Change the "Startup Type" to "Disabled"

Now run HJT/ Misc Tools/ Delete a NT Service and paste this into the box

cmdService

Run HJT Scan Only, close all windows except HJT, put a checkmark in the following entries and click on Fix Checked

R3 - Default URLSearchHook is missing
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\irnsl5571.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sm93aWUA\command.exe (file missing)


Open Killbox and copy and paste this entire path into the top most box, choose Delete file on Reboot, click on the red X, to confirm the deletion, and them when it asks you to reboot , say yes

C:\WINDOWS\Sm93aWUA\command.exe


Then run Ewido , when a window pops up and asks you for remove a entry, say yes for all entries found.
Then save report, I will need that later.

Reboot Normally

You may have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

I would like…

1. New HJT log
2. Ewido Report
3. Log from L2mfix
Thanks very much for helping. Just to let you know, after those instructions, the problem still occurs.



Logfile of HijackThis v1.99.1
Scan saved at 5:24:10 AM, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack This\HijackThis.exe

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\System32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Miranda IM.lnk = C:\Program Files\Miranda IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110518650500
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\jt8007lme.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 5:08:06 AM, 27/10/2005
+ Report-Checksum: DBBAD4D9

+ Scan result:

[712] C:\WINDOWS\system32\kndkaz.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\Cache\9C933101d01 -> Not-A-Virus.Downloader.Agent.f : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Jowie\Application Data\Mozilla\Firefox\Profiles\q555bpfq.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temp\Cookies\jowie@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temp\Cookies\jowie@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temp\Cookies\jowie@microsoftwga.112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temporary Internet Files\Content.IE5\6IXT6OXY\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temporary Internet Files\Content.IE5\6IXT6OXY\AppWrap[2].exe -> Spyware.Zestyfind : Cleaned with backup
C:\Documents and Settings\Jowie\Local Settings\Temporary Internet Files\Content.IE5\DY4FO5CA\AppWrap[1].exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\system32\iqetcomm.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kndkaz.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\seellstyle.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\syrialui.dll -> Spyware.Look2Me : Cleaned with backup


::Report End


L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\policies]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\jt8007lme.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6730F84F-7CAD-8BDF-E641-0488C0CA51D3}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
"{48F45200-91E6-11CE-8A4F-0080C81A28D4}"="TMD Shell Extension"
"{771A9DA0-731A-11CE-993C-00AA004ADB6C}"="VBPropSheet"
"{A4F1778C-C915-4134-AF35-03279553ACFD}"=""
"{9C32DF69-54BA-4EB8-BD30-814E47D60DC0}"=""
"{B8CA60C7-2BC4-4034-A440-C3A32BBEDB29}"=""
"{899483FA-C1C2-4045-8525-901E7E00FEE7}"=""
"{0DA83BA3-B9E3-4042-903E-79EB2D371725}"=""
"{D949186C-09C9-4A01-B543-B4E5AD42DA60}"=""
"{8F578998-1880-4606-8B9E-AA186F039E7A}"=""
"{2EADCBAC-B198-4687-85DA-E23D3611F5A5}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9C32DF69-54BA-4EB8-BD30-814E47D60DC0}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C32DF69-54BA-4EB8-BD30-814E47D60DC0}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C32DF69-54BA-4EB8-BD30-814E47D60DC0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C32DF69-54BA-4EB8-BD30-814E47D60DC0}\InprocServer32]
@="C:\\WINDOWS\\system32\\ckusapi.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B8CA60C7-2BC4-4034-A440-C3A32BBEDB29}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8CA60C7-2BC4-4034-A440-C3A32BBEDB29}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8CA60C7-2BC4-4034-A440-C3A32BBEDB29}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8CA60C7-2BC4-4034-A440-C3A32BBEDB29}\InprocServer32]
@="C:\\WINDOWS\\system32\\mvtime.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{899483FA-C1C2-4045-8525-901E7E00FEE7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{899483FA-C1C2-4045-8525-901E7E00FEE7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{899483FA-C1C2-4045-8525-901E7E00FEE7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{899483FA-C1C2-4045-8525-901E7E00FEE7}\InprocServer32]
@="C:\\WINDOWS\\system32\\mroert2.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{0DA83BA3-B9E3-4042-903E-79EB2D371725}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0DA83BA3-B9E3-4042-903E-79EB2D371725}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0DA83BA3-B9E3-4042-903E-79EB2D371725}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0DA83BA3-B9E3-4042-903E-79EB2D371725}\InprocServer32]
@="C:\\WINDOWS\\system32\\wvi.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D949186C-09C9-4A01-B543-B4E5AD42DA60}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D949186C-09C9-4A01-B543-B4E5AD42DA60}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D949186C-09C9-4A01-B543-B4E5AD42DA60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D949186C-09C9-4A01-B543-B4E5AD42DA60}\InprocServer32]
@="C:\\WINDOWS\\system32\\seellstyle.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8F578998-1880-4606-8B9E-AA186F039E7A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F578998-1880-4606-8B9E-AA186F039E7A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F578998-1880-4606-8B9E-AA186F039E7A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8F578998-1880-4606-8B9E-AA186F039E7A}\InprocServer32]
@="C:\\WINDOWS\\system32\\iqetcomm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2EADCBAC-B198-4687-85DA-E23D3611F5A5}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2EADCBAC-B198-4687-85DA-E23D3611F5A5}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2EADCBAC-B198-4687-85DA-E23D3611F5A5}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2EADCBAC-B198-4687-85DA-E23D3611F5A5}\InprocServer32]
@="C:\\WINDOWS\\system32\\kndkaz.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Tue 25 Oct 2005 17:25:34 A…. 687,592 671.48 K
browseui.dll Sat 3 Sep 2005 9:52:04 A…. 1,019,904 996.00 K
cdfview.dll Sat 3 Sep 2005 9:52:04 A…. 151,040 147.50 K
cdosys.dll Sat 10 Sep 2005 11:53:42 A…. 2,067,968 1.97 M
danim.dll Sat 3 Sep 2005 9:52:04 A…. 1,053,696 1.00 M
dxtrans.dll Sat 3 Sep 2005 9:52:04 A…. 205,312 200.50 K
extmgr.dll Sat 3 Sep 2005 9:52:04 ….. 55,808 54.50 K
fplm03~1.dll Thu 27 Oct 2005 5:12:44 ..S.R 235,217 229.70 K
iepeers.dll Sat 3 Sep 2005 9:52:04 A…. 251,392 245.50 K
inseng.dll Sat 3 Sep 2005 9:52:04 A…. 96,256 94.00 K
jt8007~1.dll Thu 27 Oct 2005 5:11:04 ..S.R 235,084 229.57 K
legitc~1.dll Mon 29 Aug 2005 13:27:12 A…. 520,968 508.76 K
linkinfo.dll Thu 1 Sep 2005 11:41:54 A…. 19,968 19.50 K
mshtml.dll Tue 4 Oct 2005 17:26:00 A…. 3,015,168 2.88 M
mshtmled.dll Sat 3 Sep 2005 9:52:06 A…. 448,512 438.00 K
msrating.dll Sat 3 Sep 2005 9:52:06 A…. 146,432 143.00 K
mstime.dll Sat 3 Sep 2005 9:52:06 A…. 530,432 518.00 K
netman.dll Tue 23 Aug 2005 4:29:46 A…. 197,632 193.00 K
nv4_disp.dll Tue 2 Aug 2005 16:35:00 A…. 3,908,864 3.73 M
nvcod.dll Tue 2 Aug 2005 16:35:00 A…. 32,768 32.00 K
nvcodins.dll Tue 2 Aug 2005 16:35:00 A…. 32,768 32.00 K
nvcpl.dll Tue 2 Aug 2005 16:35:00 A…. 7,110,656 6.78 M
nvhwvid.dll Tue 2 Aug 2005 16:35:00 A…. 540,672 528.00 K
nview.dll Tue 2 Aug 2005 16:35:00 A…. 1,466,368 1.40 M
nvmctray.dll Tue 2 Aug 2005 16:35:00 A…. 86,016 84.00 K
nvnt4cpl.dll Tue 2 Aug 2005 16:35:00 A…. 286,720 280.00 K
nvoglnt.dll Tue 2 Aug 2005 16:35:00 A…. 5,140,480 4.90 M
nvrsar.dll Tue 2 Aug 2005 16:35:00 A…. 315,392 308.00 K
nvrscs.dll Tue 2 Aug 2005 16:35:00 A…. 233,472 228.00 K
nvrsda.dll Tue 2 Aug 2005 16:35:00 A…. 241,664 236.00 K
nvrsde.dll Tue 2 Aug 2005 16:35:00 A…. 266,240 260.00 K
nvrsel.dll Tue 2 Aug 2005 16:35:00 A…. 270,336 264.00 K
nvrseng.dll Tue 2 Aug 2005 16:35:00 A…. 237,568 232.00 K
nvrses.dll Tue 2 Aug 2005 16:35:00 A…. 270,336 264.00 K
nvrsesm.dll Tue 2 Aug 2005 16:35:00 A…. 262,144 256.00 K
nvrsfi.dll Tue 2 Aug 2005 16:35:00 A…. 237,568 232.00 K
nvrsfr.dll Tue 2 Aug 2005 16:35:00 A…. 270,336 264.00 K
nvrshe.dll Tue 2 Aug 2005 16:35:00 A…. 311,296 304.00 K
nvrshu.dll Tue 2 Aug 2005 16:35:00 A…. 245,760 240.00 K
nvrsit.dll Tue 2 Aug 2005 16:35:00 A…. 270,336 264.00 K
nvrsja.dll Tue 2 Aug 2005 16:35:00 A…. 253,952 248.00 K
nvrsko.dll Tue 2 Aug 2005 16:35:00 A…. 249,856 244.00 K
nvrsnl.dll Tue 2 Aug 2005 16:35:00 A…. 262,144 256.00 K
nvrsno.dll Tue 2 Aug 2005 16:35:00 A…. 241,664 236.00 K
nvrspl.dll Tue 2 Aug 2005 16:35:00 A…. 241,664 236.00 K
nvrspt.dll Tue 2 Aug 2005 16:35:00 A…. 262,144 256.00 K
nvrsptb.dll Tue 2 Aug 2005 16:35:00 A…. 253,952 248.00 K
nvrsru.dll Tue 2 Aug 2005 16:35:00 A…. 258,048 252.00 K
nvrssk.dll Tue 2 Aug 2005 16:35:00 A…. 245,760 240.00 K
nvrssl.dll Tue 2 Aug 2005 16:35:00 A…. 241,664 236.00 K
nvrssv.dll Tue 2 Aug 2005 16:35:00 A…. 241,664 236.00 K
nvrstr.dll Tue 2 Aug 2005 16:35:00 A…. 245,760 240.00 K
nvrszhc.dll Tue 2 Aug 2005 16:35:00 A…. 212,992 208.00 K
nvrszht.dll Tue 2 Aug 2005 16:35:00 A…. 114,688 112.00 K
nvshell.dll Tue 2 Aug 2005 16:35:00 A…. 466,944 456.00 K
nvwddi.dll Tue 2 Aug 2005 16:35:00 A…. 81,920 80.00 K
nvwdmcpl.dll Tue 2 Aug 2005 16:35:00 A…. 1,662,976 1.59 M
nvwimg.dll Tue 2 Aug 2005 16:35:00 A…. 1,019,904 996.00 K
nvwrsar.dll Tue 2 Aug 2005 16:35:00 A…. 282,624 276.00 K
nvwrscs.dll Tue 2 Aug 2005 16:35:00 A…. 286,720 280.00 K
nvwrsda.dll Tue 2 Aug 2005 16:35:00 A…. 294,912 288.00 K
nvwrsde.dll Tue 2 Aug 2005 16:35:00 A…. 311,296 304.00 K
nvwrsel.dll Tue 2 Aug 2005 16:35:00 A…. 335,872 328.00 K
nvwrseng.dll Tue 2 Aug 2005 16:35:00 A…. 286,720 280.00 K
nvwrses.dll Tue 2 Aug 2005 16:35:00 A…. 335,872 328.00 K
nvwrsesm.dll Tue 2 Aug 2005 16:35:00 A…. 327,680 320.00 K
nvwrsfi.dll Tue 2 Aug 2005 16:35:00 A…. 303,104 296.00 K
nvwrsfr.dll Tue 2 Aug 2005 16:35:00 A…. 327,680 320.00 K
nvwrshe.dll Tue 2 Aug 2005 16:35:00 A…. 278,528 272.00 K
nvwrshu.dll Tue 2 Aug 2005 16:35:00 A…. 315,392 308.00 K
nvwrsit.dll Tue 2 Aug 2005 16:35:00 A…. 323,584 316.00 K
nvwrsja.dll Tue 2 Aug 2005 16:35:00 A…. 212,992 208.00 K
nvwrsko.dll Tue 2 Aug 2005 16:35:00 A…. 196,608 192.00 K
nvwrsnl.dll Tue 2 Aug 2005 16:35:00 A…. 319,488 312.00 K
nvwrsno.dll Tue 2 Aug 2005 16:35:00 A…. 299,008 292.00 K
nvwrspl.dll Tue 2 Aug 2005 16:35:00 A…. 294,912 288.00 K
nvwrspt.dll Tue 2 Aug 2005 16:35:00 A…. 323,584 316.00 K
nvwrsptb.dll Tue 2 Aug 2005 16:35:00 A…. 319,488 312.00 K
nvwrsru.dll Tue 2 Aug 2005 16:35:00 A…. 315,392 308.00 K
nvwrssk.dll Tue 2 Aug 2005 16:35:00 A…. 299,008 292.00 K
nvwrssl.dll Tue 2 Aug 2005 16:35:00 A…. 303,104 296.00 K
nvwrssv.dll Tue 2 Aug 2005 16:35:00 A…. 294,912 288.00 K
nvwrstr.dll Tue 2 Aug 2005 16:35:00 A…. 303,104 296.00 K
nvwrszhc.dll Tue 2 Aug 2005 16:35:00 A…. 163,840 160.00 K
nvwrszht.dll Tue 2 Aug 2005 16:35:00 A…. 167,936 164.00 K
nwwks.dll Fri 12 Aug 2005 1:10:00 A…. 65,024 63.50 K
pncrt.dll Sat 20 Aug 2005 0:59:52 A…. 278,528 272.00 K
pndx5016.dll Sat 20 Aug 2005 1:04:26 A…. 6,656 6.50 K
pndx5032.dll Sat 20 Aug 2005 1:04:26 A…. 5,632 5.50 K
pngfilt.dll Sat 3 Sep 2005 9:52:06 A…. 39,424 38.50 K
quartz.dll Tue 30 Aug 2005 13:54:26 A…. 1,287,168 1.23 M
rmoc3260.dll Sat 20 Aug 2005 1:04:32 A…. 176,167 172.04 K
shdocvw.dll Sat 3 Sep 2005 9:52:06 A…. 1,483,776 1.41 M
shell32.dll Fri 23 Sep 2005 13:05:30 A…. 8,450,560 8.06 M
shlwapi.dll Sat 3 Sep 2005 9:52:06 A…. 473,600 462.50 K
umpnpmgr.dll Tue 23 Aug 2005 13:35:42 A…. 123,392 120.50 K
urlmon.dll Sat 3 Sep 2005 9:52:06 A…. 608,768 594.50 K
wininet.dll Sat 3 Sep 2005 9:52:06 A…. 658,432 643.00 K
winsrv.dll Thu 1 Sep 2005 11:41:54 A…. 291,840 285.00 K
winsusrm.dll Mon 12 Sep 2005 2:23:12 A…. 264 0.26 K
wvi.dll Thu 27 Oct 2005 5:12:44 ..S.R 235,084 229.57 K

101 items found: 101 files (3 H/S), 0 directories.
Total of file sizes: 61,541,512 bytes 58.69 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C is Programs
Volume Serial Number is 34EC-CBD3

Directory of C:\WINDOWS\System32

27/10/2005 05:12 AM 235,084 wvi.dll
27/10/2005 05:12 AM 235,217 fplm0331e.dll
27/10/2005 05:11 AM 235,084 jt8007lme.dll
26/10/2005 09:10 PM dllcache
11/03/2005 02:57 PM Microsoft
3 File(s) 705,385 bytes
2 Dir(s) 14,417,936,384 bytes free
jowie53,

We got rid of a lot but we are not home yet….

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click
l2mfix.bat
Select option #2 for Run Fix by typing 2 and then pressing enter
Then press any key to reboot your computer.
After a reboot, your desktop and icons will appear, then disappear (this is normal).
L2mfix will continue to scan your computer and when it's finished, notepad will open with a log.
Save the log to a folder that you will remember as I will need you to post that log in a bit.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

If after the reboot the desktop icons dont dissappear or the log does not pop up then in the l2mfix folder double click the second.bat file to continue with the fix.

Then Download
CWShredder 2.15 to your desktop.
Update it but don't run it yet.

Run L2m fix with option2 to delete most of the files.

After the reboot run CWShredder it will ask to reboot allow it.

Run L2m fix again with option 2 to restore the reg keys.


Now please do the following:

Download the trial version of Spy Sweeper


Install SpySweeper v4.5
Follow the prompts and do a Typical installation

Update the program definitions
Select: Sweep
It will take a while to scan the computer.

When the scan is done, remove whatever it finds.

Then, press the Results button
Select the Session Log tab
Select: Save to File
Save wherever is convenient
Copy/Paste the results in your response.

Post the SpySweeper Session log, the log from L2mfix and a new HijackThis log.
Cool… I acted on your instructions prior to your edit, so what I did was carry out what you said but did not receive the log from the l2mfix. I continued on with the other instructions following that point and then when you edited the post I then ran the second.bat file after carrying out the whole instructions. Hopefully this has not affected my computer or the process that you are taking me through… I possibly should have stopped there and posted that I didn't receive the log. I thought I'd get the other two logs and post those and say that I didn't receive the log from l2mfix, however now I have all three.

Please note, as of yet I haven't had a browser hijack, which I possibly should have had about 10 by now..

********
7:27 AM: | Start of Session, Thursday, 27 October 2005 |
7:27 AM: Spy Sweeper started
7:27 AM: Sweep initiated using definitions version 562
7:27 AM: Starting Memory Sweep
7:27 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:27 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:27 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:27 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:28 AM: Found Adware: icannnews
7:28 AM: Detected running threat: C:\WINDOWS\system32\lv2409fqe.dll (ID = 83)
7:28 AM: Detected running threat: C:\WINDOWS\system32\gci32.dll (ID = 83)
7:28 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:28 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:28 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:28 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:29 AM: Memory Sweep Complete, Elapsed Time: 00:01:36
7:29 AM: Starting Registry Sweep
7:29 AM: Registry Sweep Complete, Elapsed Time:00:00:06
7:29 AM: Starting Cookie Sweep
7:29 AM: Found Spy Cookie: moviemonster cookie
7:29 AM: jowie@moviemonster[2].txt (ID = 3010)
7:29 AM: Found Spy Cookie: xren_cj cookie
7:29 AM: jowie@xren_cj[1].txt (ID = 3723)
7:29 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
7:29 AM: Starting File Sweep
7:29 AM: Found Adware: targetsaver
7:29 AM: 113_dollarrevenue_4_0_3_9[1].exe (ID = 166444)
7:29 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:29 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:31 AM: Found Adware: hotbar
7:31 AM: icons2[1].xip (ID = 121862)
7:31 AM: d_icons_buttons_2000[1].xip (ID = 114390)
7:31 AM: d_icons_buttons_3000[1].xip (ID = 114353)
7:31 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:31 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:32 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:33 AM: Found Adware: apropos
7:33 AM: atmtd.dll._ (ID = 166754)
7:33 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:33 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:33 AM: d_icons_weather[1].xip (ID = 121860)
7:33 AM: tsd_bg[1].xip (ID = 62383)
7:33 AM: t2_bg[1].xip (ID = 121869)
7:33 AM: d_icons_buttons_bbar1[1].xip (ID = 114354)
7:33 AM: country[1].xip (ID = 121857)
7:33 AM: atmtd.dll (ID = 166754)
7:33 AM: d_icons_buttons_1000[1].xip (ID = 114339)
7:34 AM: linkpathlegal[1].xip (ID = 121866)
7:34 AM: d_icons_buttons_logos[1].xip (ID = 62296)
7:34 AM: d_icons_buttons_other[1].xip (ID = 62296)
7:34 AM: progress[1].xip (ID = 62368)
7:34 AM: d_icons_buttons_bar[1].xip (ID = 62296)
7:34 AM: business_promo[1].xip (ID = 121856)
7:34 AM: hotbar_promo[1].xip (ID = 114346)
7:34 AM: ads[1].xip (ID = 121855)
7:34 AM: hotbar-premium[1].xip (ID = 114359)
7:34 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:34 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:35 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:35 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:35 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:35 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:36 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:36 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:36 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:36 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:36 AM: File Sweep Complete, Elapsed Time: 00:07:08
7:36 AM: Full Sweep has completed. Elapsed time 00:08:53
7:36 AM: Traces Found: 25
7:37 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:37 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
7:37 AM: Removal process initiated
7:37 AM: Quarantining All Traces: apropos
7:37 AM: Quarantining All Traces: hotbar
7:38 AM: Quarantining All Traces: icannnews
7:38 AM: icannnews is in use. It will be removed on reboot.
7:38 AM: C:\WINDOWS\system32\lv2409fqe.dll is in use. It will be removed on reboot.
7:38 AM: C:\WINDOWS\system32\gci32.dll is in use. It will be removed on reboot.
7:38 AM: Quarantining All Traces: targetsaver
7:38 AM: Quarantining All Traces: moviemonster cookie
7:38 AM: Quarantining All Traces: xren_cj cookie
7:38 AM: Warning: Launched explorer.exe
7:38 AM: Warning: Quarantine process could not restart Explorer.
7:38 AM: Preparing to restart your computer. Please wait…
7:38 AM: Removal process completed. Elapsed time 00:00:35
********
7:26 AM: | Start of Session, Thursday, 27 October 2005 |
7:26 AM: Spy Sweeper started
7:27 AM: Your spyware definitions have been updated.
7:27 AM: | End of Session, Thursday, 27 October 2005 |



C:\
Setting Directory
C:\
C:\
System Rebooted!

Running From:
C:\

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1616 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 1652 'rundll32.exe'

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!

Zipping up files for submission:
adding: clear.reg (188 bytes security) (deflated 2%)
adding: lo2.txt (188 bytes security) (deflated 49%)
adding: test.txt (188 bytes security) (stored 0%)
adding: test2.txt (188 bytes security) (stored 0%)
adding: test3.txt (188 bytes security) (stored 0%)
adding: test5.txt (188 bytes security) (stored 0%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators … successful

Restoring Windows Update Certificates.:


The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
"Asynchronous"=dword:00000000
"DllName"="WRLogonNTF.dll"
"Impersonate"=dword:00000001
"Lock"="WRLock"
"StartScreenSaver"="WRStartScreenSaver"
"StartShell"="WRStartShell"
"Startup"="WRStartup"
"StopScreenSaver"="WRStopScreenSaver"
"Unlock"="WRUnlock"
"Shutdown"="WRShutdown"
"Logoff"="WRLogoff"
"Logon"="WRLogon"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000


The following are the files found:
****************************************************************************

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************



Logfile of HijackThis v1.99.1
Scan saved at 8:00:13 AM, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack This\HijackThis.exe

R3 - Default URLSearchHook is missing
O1 - Hosts: d.net
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\System32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Miranda IM.lnk = C:\Program Files\Miranda IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110518650500
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Hello again jowie53,

Things are looking up :D

Just a little ways to go.

Please download Hoster

* Unzip Hoster.zip to your Desktop
* Open Hoster.exe.
* Close all Open Windows.
* Then click on Restore Original Hosts
* Close program when complete.

Run HJT Scan Only and put a checkmark in the following entries, close all windows and your browser and click on Fix Checked.

R3 - Default URLSearchHook is missing
O1 - Hosts: d.net


Now download, install and run CCleaner, after install, click on Run Cleaner, then run the Issues Scan and when it asks you if you want to back up your registry…Say Yes

Now enable windows to show all files and folders


* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean


Navigate to

C:\ windows\ Prefetch and delete all the contents of that folder ...But not the Prefetch folder itself.
C:\ windows\ temp and delete all the contents of that folder
C:\ Documents and Settings\ Every User of your computer Local Settings\ Temp and delete all the contents of that folder.



Open up IE, go to Tools/ Internet Options/ General Tab and click on Delete Files, put a checkmark in Delete Offline Content


TURN Off then TURN ON SYSTEM RESTORE

Everytime you start WINDOWS, SYSTEM RESTORE creates a restore point, or if you
manually create a restore point on your own, all WINDOWS files are backed up including any that
we just cleaned that were infected with Malware or a Virus. This is the only way to clean out these files.

(You will lose all PREVIOUS RESTORE POINTS which are likely to be infected)

Turn off System Restore.

* Right Click on MY COMPUTER
* Click on PROPERTIES
* Click on the SYSTEM RESTORE TAB
* Check TURN OFF SYSTEM RESTORE ON ALL DRIVES
* Click APPLY / OK

RE-BOOT YOUR COMPUTER


TURN ON SYSTEM RESTORE

* Right Click on MY COMPUTER
* Click on PROPERTIES
* Click on the SYSTEM RESTORE TAB
* UN-Check TURN OFF SYSTEM RESTORE ON ALL DRIVES
* Click APPLY / OK

Now create a new RESTORE POINT

* Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like that you can remember

While where on a roll, use the links in my signature to download and run these two fine programs that are must haves if you want to stay clean.
Spybot Search and Destroy
Ad-Aware Se Personal 1.06


Here are the setup instructions for both programs

Spybot Search and Destroy 1.4

* If you have the older version 1.3, remove it via ADD-REMOVE PROGRAMS in the Control Panel.

Go to START/ CONTROL PANEL/ PERFORMANCE AND MAINTAINENCE/ ADD-REMOVE
PROGRAMS
scroll to that program and click on REMOVE.

* During Installation, just follow all the defaults.
* Go to MODE and click on ADVANCED MODE.
* Then to SETTINGS / FILE SETS and take the checkmark out of USAGE TRACKS.
* Then to TOOLS/ HOSTS FILE and then on the top click on ADD SPYBOT S & D HOSTS FILES.
* Then to TOOLS/ IE TWEAKS and put a checkmark in LOCK THE HOSTS FILES
* Then check for UPDATES.
* Then to Immunize. then up at the top by the GREEN SIGN, click on IMMUNIZE.
* Then go to the top to SPYBOT and run a FULL SYSTEM SCAN.
* Then to FIX PROBLEMS and fix all it finds.

Then RE-BOOT your computer.


AD-AWARE SE PERSONAL 1.06

If you have an older version of Ad-Aware, no need to uninstall it, it will prompt you to uninstall it during the set up process

* During installation, follow all the defaults.
* Start the program and CHECK FOR UPDATES
* Choose PERFORM FULL SYSTEM SCAN
* Take the checkmark out of SEARCH FOR NEGLIGIBLE RISK FILES
* Run the scan
* When it is done, RIGHT CLICK ON ONE OF THE ENTRIES/ SELECT ALL/ NEXT and let it remove all that if finds.



Post one last HJT log and if all is ok, I have some free programs for you to install that will help keep all the rif raf out of your system.
Awesome…. Thanks very much for all your help. You've been a lot more effective than a few of my mates that work with computers. I'll make a donation for sure mate!

Logfile of HijackThis v1.99.1
Scan saved at 10:55:19 PM, on 27/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Miranda IM\miranda32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack This\HijackThis.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\pcclient.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\System32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Miranda IM.lnk = C:\Program Files\Miranda IM\miranda32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110518650500
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
jowie53, Your log is clean :D , good job following all the instructions :thumbup: , I will be tied up for the rest of the day but later this evening, check back in and I am going to post the free programs that I urge you to install for security.
jowie53,

You have done some of these already, so just bypass those, just besure you do the System Restore tip, you don't want to get infected all over again after all your hardwork removing the infection.



Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

* Download and Install CCleaner, Click on RUN TOOL, when you run the Issues Scan and it asks you to back up the registry Say Yes.

Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.
* Clean out your TEMP FILES
* This procedure should be run from SAFEMODE for better results.

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD

* Go to My Computer/ C: Drive/ Documents and Settings/ Local Settings/ Every User on this Computer and delete all the contents of the Temp Folder

* Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder

* Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. But not the Prefetch folder itself.

NOW RE-BOOT NORMALLY


* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.

Now Empty your Recycle Bin

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

* Right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

Reboot your System

Turn ON System Restore.

* Right-click My Computer.
* ClickProperties.
* Click the System Restore tab.
* UN-Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

* Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like, something that you can remember

* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

* Here are Free Anti-Virus Programs if you need one

AVG Free Edition
AntVir Personal Edition


* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.

* Spyware Blaster It will prevent most spyware from ever being installed.

* Spyware Guard It offers realtime protection from spyware installation attempts.

* Win Patrol
This program will warn you when any changes are being made to your system and give you the option to deny the change.

* IE- Spyad IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

* Firefox Browser
It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both. When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you use this for awhile, you will want to make it your default.

* Thunderbird Mail Ther companion mail program was highly favored in PCWorld Magazine,, this has a good spam filter and is more secure than Outlook Express.

*Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.

* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER/Click on PROPERTIES/ AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.

* Go to START/ CONTROL PANEL> PERFROMANCE AND MAINTENANCE> REARRANGE ITEMS ON YOUR HARD DISK TO MAKE PROGRAMS RUN FASTER
This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.

Thanks for using Tom Coyote Mate,

Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI