This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyaxe and other issues

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having issues for a couple of weeks. It first started with Spy Sheriff a couple of weeks ago, and it seemed like I got rid of that one. A couple of days ago, Spyaxe was on the computer as well as 2 other icons, one Security Troubleshoot and the other Online Security Guide.

The Norton Antivirus also appears to be acting up. When starting up the computer, I get a warning box that says "Norton Anti Virus 2005 does not support the repair feature-please uninstall and reinstall".

Here is what I have done so far. I ran Spybot, AdAware and my Norton Anti Virus. Every time I deleted the Spyaxe and rebooted, it would come back. I have also followed the instructions in the forum on how to get rid of Spyaxe. I ran the smitRem. exe and also the ewido security suite in safe mode. I had quite a few problems trying to get the ewido to run. On several occasions, a box popped up with an error message, stating that ewido was having problems and would have to shut down. This happened at different times during the program (for example 3%, 40% or 77%), but mostly when clicking on the "ok buttom to remove infected object". After about the 20th time, it finally completed itself without any errors. I then rebooted into normal mode, but I still see Spyaxe listed in my "all programs" under the start button. Here are my logs, if you could please check them out and let me know what you see. Thank you very much.

——————————– Beginning of HJT log——————————-

Logfile of HijackThis v1.99.1
Scan saved at 6:41:08 PM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\w?wexec.exe
C:\Program Files\sder\dees.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - URLSearchHook: (no name) - {55E2B42F-2EE6-2F1B-9F8F-2AA748E898BA} - C:\WINNT\system32\fpda.dll (file missing)
R3 - URLSearchHook: (no name) - {26CB4390-DC55-D8FF-74CE-8ECD6EBAEFBE} - C:\WINNT\system32\kdk.dll (file missing)
R3 - URLSearchHook: (no name) - {FD039BA6-5035-539F-1043-5350A7563EBC} - C:\WINNT\system32\lvpotw.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [netrr32.exe] C:\WINNT\netrr32.exe
O4 - HKLM\..\Run: [284.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\284.tmp.exe
O4 - HKLM\..\Run: [283.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\283.tmp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunServices: [LSASS Authority] lsvhosts.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yuo] C:\WINNT\system32\w?wexec.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt tzt
O4 - HKCU\..\Run: [klop] C:\WINNT\KVG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120497753234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123449937812
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://www.wildtangent.com/install/wdriver…y/ea/wtinst.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://138.108.63.129/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a…5/Installer.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f…outLauncher.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E63543CB-2073-4AA5-874C-BC7A28248DE1} (DataManager.DataControl) - https://www.amphire.com/assets/datacontrol/Data_Manager.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup145.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

———————————End of HJT log—————————————————

———————————Beginning of Ewido Log—————————————-

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 1:29:34 PM, 12/30/2005
+ Report-Checksum: E8DB82E0

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{57E3366A-84A8-8E7A-61A4-31449D4C2413} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B81896EA-E0AA-92AA-BF67-14B1C8C5A7E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA6A8ADC-5ACF-A739-A8BF-5E4D7B5991C1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@entrepreneur.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@ford.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@journalregistercompany.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@msnservices.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@sonycorporate.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\NQGJVP4X\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\WXQRGHMJ\ErrorSafeScannerInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\ted@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Ted\Local Settings\Temporary Internet Files\Content.IE5\GXAB0TQR\gdnUS2297[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Downloads\finaldrivenitroam[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Downloads\LemonadeTycoon2Setup-dm[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\34C729A5-7C5E-4F3E-9174-B40127\87CA72D0-263D-499C-8861-A5D9A1 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\510744AE-FD5C-45C7-84AF-EC9EA6\03B2C8CC-20CC-4993-964A-1301AF -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\8D13DAEB-8734-4BD0-B5B4-471901\AD3197D7-1AD5-4D92-B7E3-DFD6EB -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\90B4441B-270E-43C3-ACF0-5A63BC\F875BEAA-6D67-45CA-BEAD-5F0B9E -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP11\A0000366.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000409.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000410.exe -> Downloader.Small.awa : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP14\A0000559.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP19\A0002608.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP20\A0002645.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002677.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002885.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002975.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0002995.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0003019.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003032.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003034.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003044.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003052.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003144.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003207.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003208.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003212.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003213.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003214.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003215.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003217.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003220.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003221.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003224.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003226.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003227.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003230.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003232.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003236.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003237.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003239.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003248.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003249.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP25\A0003333.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003368.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003369.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003629.dll -> Trojan.Small.ev : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003630.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003631.exe -> Downloader.Agent.abs : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003632.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003633.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003636.exe -> Downloader.Small.bpz : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003644.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003707.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003708.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003712.exe -> Downloader.Zlob.bu : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003714.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003734.exe -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000122.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000230.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000231.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\in9bTs.dll -> Adware.eZula : Cleaned with backup
C:\WINNT\system32\ldr100.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr111.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr120.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr121.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr129.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr130.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr133.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr160.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr172.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr182.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr185.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr193.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr204.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr208.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr210.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr212.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr218.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr221.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr222.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr226.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr235.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr237.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr241.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr243.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr248.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr253.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr260.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr265.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr282.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr294.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr30.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr312.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr320.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr326.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr331.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr333.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr337.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr344.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr348.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr356.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr358.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr374.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr382.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr383.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr396.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr407.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr41.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr424.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr436.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr439.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr459.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr468.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr475.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr479.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr484.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr485.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr49.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr497.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr50.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr509.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr513.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr517.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr519.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr528.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr533.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr538.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr539.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr552.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr553.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr556.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr557.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr558.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr564.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr566.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr567.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr569.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr577.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr58.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr580.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr584.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr59.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr590.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr591.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr592.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr597.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr601.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr617.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr62.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr640.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr654.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr656.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr66.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr668.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr672.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr682.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr687.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr691.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr702.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr711.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr738.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr75.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr750.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr777.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr784.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr80.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr802.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr804.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr81.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr854.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr86.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr864.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr880.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr884.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr886.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr890.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr891.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr894.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr904.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr905.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr945.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr963.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr99.dll -> Downloader.Small.cat : Cleaned with backup


::Report End

———————————End of Ewido Log——————————————-

———————————Beginning of Smitrem Log——————————–

smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Fri 12/30/2005
The current time is: 10:46:48.26

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url
Online Security Guide.url


~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 820 'explorer.exe'
Killing PID 820 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~

Online Security Guide.url
Online Security Guide.url


~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)



———————————————End of Smitrem Log————————————
Hi tricia, Sorry for the wait, the log just got updated to the proper forum today. I am looking it over and I can tell you we still have problems. The reason ewido had such a time was the amount of infections it was trying to deal with. I see SpySweeper in your log, do you own it? If you do, update and run a scan and remove what it finds, then post the SS log for me. If you don't and it has expired you need to think about getting it uninstalled as it is using a lot of resources and doing you no good.
I can tell you that you are still very infected. I do not see anything of Smitfraud which includes SpyAxe, so if you see it in Add Remove try to uninstall it, then search for the SpyAxe.exe and delete any instance of it you can find. If you have a problem, delete it in safe mode.

Once you run SpySweeper or not depending ownership. then I would like you to do this:

1) Review this information: http://sarc.com/avcenter/venc/data/adware.purityscan.html Once you have done that, find "removal instructions" and download this tool and run it according to instructions.
http://www.purityscan.com/uninstall.html

2) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.
If you have problems and can't run either program, pass over it and come back to it once you are clean and can.

3) I want to run ewido again, but before you run it I want you to look at the first log. You will see this: C:\Program Files\Microsoft AntiSpyware\Quarantine\ I want you to open that quarantine folder in MAS and delete everything in there. Then you will see a lot of items like this: C:\System Volume Information\_restore that is stuff in your System Restore files and we will be cleaning them out as soon as we are sure you are clean. If any more of those lines are in the next ewido scan, edit them out before you post the log.
Before you run ewido, review the configuration instructions in this link: http://rstones12.geekstogo.com/ewidosetup.htm and do your best to use them.

4) Make sure you go offline, then turn off Microsoft AntiSpyware, it will block HJT from working. Turn MAS back on after you are done before you go back online.
Open Microsoft AntiSpyware.
Click on Tools, Settings.
In the left pane, click on Real-time Protection.
Under Startup Options uncheck: Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
Under Real-time spyware threat protection uncheck: Enable real-time spyware threat protection (recommended).
After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - URLSearchHook: (no name) - {55E2B42F-2EE6-2F1B-9F8F-2AA748E898BA} - C:\WINNT\system32\fpda.dll (file missing)
R3 - URLSearchHook: (no name) - {26CB4390-DC55-D8FF-74CE-8ECD6EBAEFBE} - C:\WINNT\system32\kdk.dll (file missing)
R3 - URLSearchHook: (no name) - {FD039BA6-5035-539F-1043-5350A7563EBC} - C:\WINNT\system32\lvpotw.dll (file missing)
(the next two are not bad, but are not working right with the missing files. Once you are clean, download them again if you use them)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [netrr32.exe] C:\WINNT\netrr32.exe
O4 - HKLM\..\Run: [284.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\284.tmp.exe
O4 - HKLM\..\Run: [283.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\283.tmp.exe
O4 - HKLM\..\RunServices: [LSASS Authority] lsvhosts.EXE
O4 - HKCU\..\Run: [Yuo] C:\WINNT\system32\w?wexec.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt tzt
O4 - HKCU\..\Run: [klop] C:\WINNT\KVG.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://www.wildtangent.com/install/wdriver…y/ea/wtinst.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://138.108.63.129/ePlayer/V3_2_0_0/ACNePlayer.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file

Close all programs but HJT and all browser windows, then click on "Fix Checked"

6) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:
(some of these may be gone, just do not miss any)

lsvhosts.EXE >>> file (you will have to search for this one, just make sure the spelling is lsvhosts.

C:\Program Files\sder\ >>> folder

C:\DOCUMENTS AND SETTINGS~1\Ted\LOCALS~1\Temp\284.tmp.exe Locate the Temp file in red and delete everything in it (not the folder)

C:\WINNT\system32\w?wexec.exe >>> file

C:\WINNT\KVG.exe >>> file

C:\WINNT\netrr32.exe >>> file

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

7) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log and the Ewido scan results (include the SpySweeper log if you could run it) in this same thread along with any feedback you have.

Thanks…pskelley
TomCoyote forum
Expert Member
Hi Pskelley, :wavey:

Thank you very much for helping me. Here are my logs and what I have done. Somewhere along the way my SpySweeper and my MAS have been uninstalled from my computer. Therefore, I did not run SpySweeper or perform any of the MAS deletions in #4. Below is our feedback - the numbers correspond to the numbers in your instructions.

#1. I ran the Purity Scan Uninstall process as instructed.
#2. I uninstalled and reinstalled both Spybot and AdAware versions and configured
as instructed. I ran both of those programs and deleted what was found
#3. I could not delete the quarantined files as MAS was previously uninstalled. I ran the Ewido Scan and it found 160 items. I did not see any lines with any verbiage of system volume or restore. (I did however, delete all but the most recent system restore point prior to running Ewido).
#4. I did nothing here as previous mentioned, MAS was uninstalled.
#5. New Log posted below
#6. I have a question for you on this one. You said to deleted C:\WINNT\system32\w?wexec.exe file. I found something close to that but DID NOT delete it as I was unsure..it was wowexe.exe..so just the o and the ? were different? Should I delete that? The only other thing I found was the sder folder and deleted that. I also cleaned out the Prefetch folder. However Prefetch was in the C:\WINNT folder not C:\Windows, is that a problem?
#7. The CCleaner was completed succesfully as well.

I am still having problems with my Norton AntiVirus, but it is a different problem from the earlier posting. On the restart I get a box that says “Norton Anti Virus auto protect driver could not be loaded, must restart computer”. Restarting (after completing your instructions) we get the same error. This issue is still outstanding.

Also, after we were done with your instructions, and after restarting we attempted to run Ewido but the pgm did not start. It just showed up in the task bar and the task manager showed it as inactive – so we uninstalled & reinstalled a new Ewido download.

Below are the new HJT and Ewido logs. (No SpySweeper log – since we don’t have software installed now)

———————- start of HJT log ——————————-

Logfile of HijackThis v1.99.1
Scan saved at 6:36:38 AM, on 1/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\system32\RDSHOST.exe
C:\WINNT\system32\sessmgr.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\PCHealth\HelpCtr\Binaries\HelpCtr.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120497753234
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123449937812
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a…5/Installer.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f…outLauncher.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E63543CB-2073-4AA5-874C-BC7A28248DE1} (DataManager.DataControl) - https://www.amphire.com/assets/datacontrol/Data_Manager.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup145.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

—————– end of HJT log ———————————

——————- start of Ewido log —————————

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 7:22:23 AM, 1/9/2006
+ Report-Checksum: 8C5E4DA6

+ Scan result:

:mozilla.9:C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\vcjguykr.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\vcjguykr.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\vcjguykr.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Jennifer\Application Data\Mozilla\Firefox\Profiles\vcjguykr.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup


::Report End

———————— end of Ewido log ——————-

Thanking you again for your help. :D

Tricia (and jcarbott).
Hello Tricia (and jcarbott), and you are very welcome. I appreciate your thanks…it is what I work for. Before I look at your logs, I will look at your feedback by numbers. If I do not comment it means none is needed, that you proceeded correctly with the item/items.

#3 "I could not delete the quarantined files as MAS" Once your are happy with the computer, you may wish to reinstall that free microsoft program. I do not use it but it may give you some protection. Another tool that is handy is this free one: http://www.microsoft.com/security/malwareremove/default.mspx You may want to keep the link and run it if you suspect problems.

#6 That item appears to be gone, the uninstaller (sometimes works/sometime does not) must have removed it. You handled the situation correctly. If you are ever in doubt about a file, use these free online scans to find out:
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html

Norton: I do not run it, many people sing it's praise, alas I am not one of them. I will have to refer you to Norton Tech Support to resolve this issue. Since these nasties that you had often corrupt antivirus programs and firewalls (including spyware programs) it may be that Norton will have to be reinstalled. I would certainly suggest you discuss this with technical support at Norton.

ewido is a great program but it does use some resources.
Once the trial is over you can update and use the scanner
for as long as you wish, but unless you purchase it you should turn it of
completely so it does not run unless you start it manually.

ewido anti-malware - Scan report Created on: 7:22:23 AM, 1/9/2006

Nothing unusual here, if you want better cookie control, this information will help:
http://privacy.getnetwise.org/browsing/too…fdisablecookies
http://www.mozilla.org/projects/security/p…_priv_help.html

Logfile of HijackThis v1.99.1 Scan saved at 6:36:38 AM, on 1/9/2006

This log is clear of malware :thumbup: I will offer you this information and then give you some information about a few items: Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Look in the link following the item for the information:

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
I believe you need to update this. Start > Control Panel > Java > Updates

O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
http://castlecops.com/startuplist-1366.html

O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
http://castlecops.com/startuplist-2153.html

O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
http://castlecops.com/startuplist-2113.html

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
http://castlecops.com/startuplist-9746.html

O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
http://castlecops.com/startuplist-6801.html

O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
http://castlecops.com/startuplist-4695.html

The items above boot and use resources every time you start your computer. You may not need them everytime and can start them manually when you do. I suggest trying one or two at a time to watch for any effect you do not like. This information will help: http://netsquirrel.com/msconfig/

This line I would mention to the Norton tech:
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"

If I can do anything else, please let me know.

Thanks…Phil

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Hi Pskelley, Well, so far so good. Everything seems to be working well for the last 2 days. Thank you very much to you as well as my brother-in-law John, who as you know was helping me as well. My only problem still is we were never able to get the Norton to load correctly, so I have switched over to the Avast. I will not bother the with the Norton Tech desk. Fixing these computers sure takes alot of time, and I really appreciate all of your assitance. I now know right where to come if I have any more problems. I see so many posts with the Spyaxe problem, I am just wondering if that is something new, or has it been around a while? Tricia
Hi Tricia, You folks are very welcome. I looked back and I can't see where I gave you instructions for System Restore. See, SR does not know what is good or what is bad so it backs up everything. If you need to use SR for a valid reason, if something bad is there, it gets back on your computer. Follow the instructions in this link to get fresh SR files:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

What you are talking about is the Smitfraud trojan and the hackers keep adding junk, there is already a new variety. noahdfear has to keep updating his program to kill them. It's a real nasty, there is information about it here:
http://www.google.com/search?hl=en&q;=Smitf…G=Google+Search

If you ever need a good free antivirus program, try this one:
http://free.grisoft.com/freeweb.php Make sure you follow the "free", don't get sidetracked by trials and such.

Safe surfing…Phil :wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI