This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Redirect problems, [removed], ad-w-a-r-e.com

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Well, I have kept my system pretty clean until now. I thought I was pretty good at getting rid of this stuff, but this one has me whipped. I've scanned with every spyware/adware/virus program I normally use, but it's not doing any good. They're turning up clean, but I still have the problems. New browser popups every minute or so. Usually start out with 64.192.130.141 and then redirect to another page. I've also seen www.ad-w-a-r-e.com in the title bar on some of these. I'm posting my current HJT log below. Thanks in advance for the help!!

Logfile of HijackThis v1.99.1
Scan saved at 3:42:55 PM, on 10/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTSvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Phillip Spires\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = HiWAAY Internet Services
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9954A3B-F2C6-4266-98AB-E65741C69601}: NameServer = 216.180.99.2 216.180.122.2
O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\mlapsspc.dll
O20 - Winlogon Notify: RunServicesOnce - C:\WINDOWS\system32\en0ml1d11.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Hello Phillip and welcome to TomCoyote forum. If you still need help, Spysweeper has recently updated their software to kill this infection. They are also nice enough to offer a trial version to do it for you. Let's test it out, follow these directions.

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Restart your computer <<< very important.

After the restart, Open HijackThis and choose "Do a system scan only" then check the box in front of these line items, if there are still there.

O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\mlapsspc.dll
O20 - Winlogon Notify: RunServicesOnce - C:\WINDOWS\system32\en0ml1d11.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

then please copy and paste the SpySweeper log and a new HJT log into this thread.

Thanks…pskelley
TomCoyote forum
Expert Member
Ok. That may have done the trick! Below are the logs you requested…

(SpySweeper)

********
3:02 PM: | Start of Session, Tuesday, November 01, 2005 |
3:02 PM: Spy Sweeper started
3:02 PM: Sweep initiated using definitions version 564
3:02 PM: Starting Memory Sweep
3:02 PM: Found Adware: icannnews
3:02 PM: Detected running threat: C:\WINDOWS\system32\n82u0if9e82.dll (ID = 83)
3:03 PM: Detected running threat: C:\WINDOWS\system32\mfltus35.dll (ID = 83)
3:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:03 PM: Memory Sweep Complete, Elapsed Time: 00:01:24
3:03 PM: Starting Registry Sweep
3:03 PM: Found Adware: quicklink search toolbar
3:03 PM: HKCR\qlink.qlfilter\ (3 subtraces) (ID = 890588)
3:03 PM: HKCR\qlink.qlfilter.1\ (3 subtraces) (ID = 890592)
3:03 PM: HKCR\qlink.qlhelper\ (3 subtraces) (ID = 890596)
3:03 PM: HKCR\qlink.qlhelper.1\ (3 subtraces) (ID = 890600)
3:03 PM: HKCR\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (8 subtraces) (ID = 890604)
3:03 PM: HKCR\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (10 subtraces) (ID = 890613)
3:03 PM: HKCR\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (9 subtraces) (ID = 890624)
3:03 PM: HKLM\software\classes\qlink.qlfilter\ (3 subtraces) (ID = 890661)
3:03 PM: HKLM\software\classes\qlink.qlfilter.1\ (3 subtraces) (ID = 890665)
3:03 PM: HKLM\software\classes\qlink.qlhelper\ (3 subtraces) (ID = 890669)
3:03 PM: HKLM\software\classes\qlink.qlhelper.1\ (3 subtraces) (ID = 890673)
3:03 PM: HKLM\software\classes\clsid\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (8 subtraces) (ID = 890677)
3:03 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\ (10 subtraces) (ID = 890686)
3:03 PM: Found Adware: instant access
3:03 PM: HKLM\software\classes\clsid\{e225ab73-4d7e-45f7-9425-47d2f7c7a8ab}\progid\ (1 subtraces) (ID = 890691)
3:03 PM: HKLM\software\classes\typelib\{090712ed-1622-4227-94d3-f573a9c2577f}\ (9 subtraces) (ID = 890697)
3:03 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser qlhelper objects\{aa3c0ffe-758e-4c41-b1b9-2d711915a938}\ (ID = 909564)
3:04 PM: Found Adware: targetsaver
3:04 PM: HKU\S-1-5-21-1220945662-1326574676-682003330-1003\software\tsl2\ (1 subtraces) (ID = 143616)
3:04 PM: Registry Sweep Complete, Elapsed Time:00:00:12
3:04 PM: Starting Cookie Sweep
3:04 PM: Found Spy Cookie: yieldmanager cookie
3:04 PM: phillip [removed][1].txt (ID = 3751)
3:04 PM: Found Spy Cookie: hbmediapro cookie
3:04 PM: phillip [removed][2].txt (ID = 2768)
3:04 PM: Found Spy Cookie: hotbar cookie
3:04 PM: phillip [removed][2].txt (ID = 4207)
3:04 PM: Found Spy Cookie: clickandtrack cookie
3:04 PM: phillip [removed][2].txt (ID = 2397)
3:04 PM: Found Spy Cookie: rn11 cookie
3:04 PM: phillip spires@rn11[2].txt (ID = 3261)
3:04 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:04 PM: Starting File Sweep
3:04 PM: c:\program files\quicklinks (1 subtraces) (ID = -2147468660)
3:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:05 PM: Found Adware: look2me
3:05 PM: appwrap[1].exe (ID = 65722)
3:06 PM: appwrap[1].exe (ID = 65739)
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:07 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: qlutility.exe (ID = 168232)
3:08 PM: uninst.exe (ID = 73428)
3:08 PM: Found System Monitor: potentially rootkit-masked files
3:08 PM: 00006651. (ID = 0)
3:08 PM: 00006650. (ID = 0)
3:08 PM: 00006649. (ID = 0)
3:08 PM: rmc8023x.sys (ID = 0)
3:08 PM: shfedeng.exe (ID = 0)
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:19 PM: File Sweep Complete, Elapsed Time: 00:15:10
3:19 PM: Full Sweep has completed. Elapsed time 00:16:50
3:19 PM: Traces Found: 115
3:19 PM: Removal process initiated
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:20 PM: Quarantining All Traces: potentially rootkit-masked files
3:20 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
3:20 PM: 00006651. is in use. It will be removed on reboot.
3:20 PM: 00006650. is in use. It will be removed on reboot.
3:20 PM: 00006649. is in use. It will be removed on reboot.
3:20 PM: rmc8023x.sys is in use. It will be removed on reboot.
3:20 PM: shfedeng.exe is in use. It will be removed on reboot.
3:20 PM: Quarantining All Traces: look2me
3:20 PM: Quarantining All Traces: icannnews
3:20 PM: icannnews is in use. It will be removed on reboot.
3:20 PM: C:\WINDOWS\system32\n82u0if9e82.dll is in use. It will be removed on reboot.
3:20 PM: C:\WINDOWS\system32\mfltus35.dll is in use. It will be removed on reboot.
3:20 PM: Quarantining All Traces: instant access
3:20 PM: Quarantining All Traces: quicklink search toolbar
3:20 PM: Quarantining All Traces: targetsaver
3:20 PM: Quarantining All Traces: clickandtrack cookie
3:20 PM: Quarantining All Traces: hbmediapro cookie
3:20 PM: Quarantining All Traces: hotbar cookie
3:20 PM: Quarantining All Traces: rn11 cookie
3:20 PM: Quarantining All Traces: yieldmanager cookie
3:20 PM: Warning: Launched explorer.exe
3:20 PM: Warning: Quarantine process could not restart Explorer.
3:20 PM: Preparing to restart your computer. Please wait…
3:20 PM: Removal process completed. Elapsed time 00:00:42
********
2:58 PM: | Start of Session, Tuesday, November 01, 2005 |
2:58 PM: Spy Sweeper started
2:59 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:01 PM: Your spyware definitions have been updated.
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
3:02 PM: | End of Session, Tuesday, November 01, 2005 |



(Hijack This)

Logfile of HijackThis v1.99.1
Scan saved at 3:24:34 PM, on 11/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTSvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\devldr32.exe
C:\Documents and Settings\Phillip Spires\Desktop\hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = HiWAAY Internet Services
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe



I really appreciate your help. If you see anything else that needs to be addressed, please let me know. Thanks again!!
Hey Phil, The HJT log is clean and the markers for the trojan which may have been Look2me are gone. The SS log looks a little funny to me. I'll keep the topic open for a couple of days, keep an eye on how things are running. I suggest you do this:

Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp Run CCleaner, when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

PURGE SYSTEM RESTORE to make sure nothing is hiding in those files
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe surfing…Phil

Thanks…pskelley
TomCoyote forum
Expert Member
Thanks alot. The SS log may have looked funny because it made me restart before I could save the log. Some of the processes must have still been in memory. Well, I'll be sure and get the updated versions of the other software you recommended. I'll let you know how things go over the next few days. Thanks again for all your help! This sure beats reloading Windows!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI