tricia
Topic Starter
I have been having issues for a couple of weeks. It first started with Spy Sheriff a couple of weeks ago, and it seemed like I got rid of that one. A couple of days ago, Spyaxe was on the computer as well as 2 other icons, one Security Troubleshoot and the other Online Security Guide.
The Norton Antivirus also appears to be acting up. When starting up the computer, I get a warning box that says "Norton Anti Virus 2005 does not support the repair feature-please uninstall and reinstall".
Here is what I have done so far. I ran Spybot, AdAware and my Norton Anti Virus. Every time I deleted the Spyaxe and rebooted, it would come back. I have also followed the instructions in the forum on how to get rid of Spyaxe. I ran the smitRem. exe and also the ewido security suite in safe mode. I had quite a few problems trying to get the ewido to run. On several occasions, a box popped up with an error message, stating that ewido was having problems and would have to shut down. This happened at different times during the program (for example 3%, 40% or 77%), but mostly when clicking on the "ok buttom to remove infected object". After about the 20th time, it finally completed itself without any errors. I then rebooted into normal mode, but I still see Spyaxe listed in my "all programs" under the start button. Here are my logs, if you could please check them out and let me know what you see. Thank you very much.
——————————– Beginning of HJT log——————————-
Logfile of HijackThis v1.99.1
Scan saved at 6:41:08 PM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\w?wexec.exe
C:\Program Files\sder\dees.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - URLSearchHook: (no name) - {55E2B42F-2EE6-2F1B-9F8F-2AA748E898BA} - C:\WINNT\system32\fpda.dll (file missing)
R3 - URLSearchHook: (no name) - {26CB4390-DC55-D8FF-74CE-8ECD6EBAEFBE} - C:\WINNT\system32\kdk.dll (file missing)
R3 - URLSearchHook: (no name) - {FD039BA6-5035-539F-1043-5350A7563EBC} - C:\WINNT\system32\lvpotw.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [netrr32.exe] C:\WINNT\netrr32.exe
O4 - HKLM\..\Run: [284.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\284.tmp.exe
O4 - HKLM\..\Run: [283.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\283.tmp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunServices: [LSASS Authority] lsvhosts.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yuo] C:\WINNT\system32\w?wexec.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt tzt
O4 - HKCU\..\Run: [klop] C:\WINNT\KVG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120497753234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123449937812
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://www.wildtangent.com/install/wdriver…y/ea/wtinst.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://138.108.63.129/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a…5/Installer.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f…outLauncher.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E63543CB-2073-4AA5-874C-BC7A28248DE1} (DataManager.DataControl) - https://www.amphire.com/assets/datacontrol/Data_Manager.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup145.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
———————————End of HJT log—————————————————
———————————Beginning of Ewido Log—————————————-
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 1:29:34 PM, 12/30/2005
+ Report-Checksum: E8DB82E0
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{57E3366A-84A8-8E7A-61A4-31449D4C2413} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B81896EA-E0AA-92AA-BF67-14B1C8C5A7E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA6A8ADC-5ACF-A739-A8BF-5E4D7B5991C1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@entrepreneur.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@ford.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@journalregistercompany.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@msnservices.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@sonycorporate.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\NQGJVP4X\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\WXQRGHMJ\ErrorSafeScannerInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\ted@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Ted\Local Settings\Temporary Internet Files\Content.IE5\GXAB0TQR\gdnUS2297[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Downloads\finaldrivenitroam[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Downloads\LemonadeTycoon2Setup-dm[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\34C729A5-7C5E-4F3E-9174-B40127\87CA72D0-263D-499C-8861-A5D9A1 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\510744AE-FD5C-45C7-84AF-EC9EA6\03B2C8CC-20CC-4993-964A-1301AF -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\8D13DAEB-8734-4BD0-B5B4-471901\AD3197D7-1AD5-4D92-B7E3-DFD6EB -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\90B4441B-270E-43C3-ACF0-5A63BC\F875BEAA-6D67-45CA-BEAD-5F0B9E -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP11\A0000366.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000409.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000410.exe -> Downloader.Small.awa : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP14\A0000559.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP19\A0002608.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP20\A0002645.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002677.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002885.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002975.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0002995.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0003019.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003032.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003034.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003044.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003052.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003144.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003207.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003208.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003212.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003213.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003214.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003215.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003217.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003220.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003221.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003224.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003226.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003227.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003230.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003232.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003236.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003237.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003239.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003248.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003249.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP25\A0003333.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003368.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003369.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003629.dll -> Trojan.Small.ev : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003630.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003631.exe -> Downloader.Agent.abs : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003632.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003633.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003636.exe -> Downloader.Small.bpz : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003644.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003707.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003708.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003712.exe -> Downloader.Zlob.bu : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003714.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003734.exe -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000122.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000230.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000231.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\in9bTs.dll -> Adware.eZula : Cleaned with backup
C:\WINNT\system32\ldr100.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr111.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr120.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr121.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr129.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr130.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr133.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr160.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr172.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr182.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr185.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr193.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr204.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr208.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr210.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr212.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr218.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr221.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr222.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr226.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr235.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr237.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr241.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr243.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr248.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr253.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr260.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr265.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr282.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr294.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr30.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr312.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr320.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr326.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr331.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr333.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr337.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr344.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr348.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr356.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr358.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr374.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr382.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr383.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr396.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr407.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr41.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr424.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr436.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr439.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr459.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr468.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr475.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr479.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr484.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr485.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr49.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr497.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr50.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr509.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr513.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr517.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr519.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr528.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr533.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr538.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr539.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr552.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr553.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr556.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr557.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr558.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr564.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr566.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr567.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr569.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr577.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr58.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr580.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr584.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr59.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr590.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr591.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr592.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr597.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr601.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr617.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr62.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr640.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr654.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr656.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr66.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr668.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr672.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr682.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr687.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr691.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr702.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr711.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr738.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr75.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr750.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr777.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr784.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr80.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr802.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr804.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr81.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr854.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr86.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr864.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr880.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr884.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr886.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr890.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr891.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr894.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr904.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr905.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr945.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr963.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr99.dll -> Downloader.Small.cat : Cleaned with backup
::Report End
———————————End of Ewido Log——————————————-
———————————Beginning of Smitrem Log——————————–
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Fri 12/30/2005
The current time is: 10:46:48.26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
checking for WinHound.com key
WinHound.com key not present!
spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 820 'explorer.exe'
Killing PID 820 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
———————————————End of Smitrem Log————————————
The Norton Antivirus also appears to be acting up. When starting up the computer, I get a warning box that says "Norton Anti Virus 2005 does not support the repair feature-please uninstall and reinstall".
Here is what I have done so far. I ran Spybot, AdAware and my Norton Anti Virus. Every time I deleted the Spyaxe and rebooted, it would come back. I have also followed the instructions in the forum on how to get rid of Spyaxe. I ran the smitRem. exe and also the ewido security suite in safe mode. I had quite a few problems trying to get the ewido to run. On several occasions, a box popped up with an error message, stating that ewido was having problems and would have to shut down. This happened at different times during the program (for example 3%, 40% or 77%), but mostly when clicking on the "ok buttom to remove infected object". After about the 20th time, it finally completed itself without any errors. I then rebooted into normal mode, but I still see Spyaxe listed in my "all programs" under the start button. Here are my logs, if you could please check them out and let me know what you see. Thank you very much.
——————————– Beginning of HJT log——————————-
Logfile of HijackThis v1.99.1
Scan saved at 6:41:08 PM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\System32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\WINNT\system32\CTHELPER.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\w?wexec.exe
C:\Program Files\sder\dees.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - URLSearchHook: (no name) - {55E2B42F-2EE6-2F1B-9F8F-2AA748E898BA} - C:\WINNT\system32\fpda.dll (file missing)
R3 - URLSearchHook: (no name) - {26CB4390-DC55-D8FF-74CE-8ECD6EBAEFBE} - C:\WINNT\system32\kdk.dll (file missing)
R3 - URLSearchHook: (no name) - {FD039BA6-5035-539F-1043-5350A7563EBC} - C:\WINNT\system32\lvpotw.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [netrr32.exe] C:\WINNT\netrr32.exe
O4 - HKLM\..\Run: [284.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\284.tmp.exe
O4 - HKLM\..\Run: [283.tmp] C:\DOCUME~1\Ted\LOCALS~1\Temp\283.tmp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunServices: [LSASS Authority] lsvhosts.EXE
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yuo] C:\WINNT\system32\w?wexec.exe
O4 - HKCU\..\Run: [Ltho] "C:\Program Files\sder\dees.exe" -vt tzt
O4 - HKCU\..\Run: [klop] C:\WINNT\KVG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120497753234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123449937812
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/u…AIM.9.5.1.8.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://www.wildtangent.com/install/wdriver…y/ea/wtinst.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://138.108.63.129/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/6c5b0a…5/Installer.exe
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f…outLauncher.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {E63543CB-2073-4AA5-874C-BC7A28248DE1} (DataManager.DataControl) - https://www.amphire.com/assets/datacontrol/Data_Manager.CAB
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup145.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
———————————End of HJT log—————————————————
———————————Beginning of Ewido Log—————————————-
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 1:29:34 PM, 12/30/2005
+ Report-Checksum: E8DB82E0
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{57E3366A-84A8-8E7A-61A4-31449D4C2413} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B81896EA-E0AA-92AA-BF67-14B1C8C5A7E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA6A8ADC-5ACF-A739-A8BF-5E4D7B5991C1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6685509E-B47B-4F47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-2557603035-146357336-2046000653-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@entrepreneur.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@ford.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@journalregistercompany.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@msnservices.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@paypopup[2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\jennifer@sonycorporate.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jennifer\Cookies\[removed][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temp\Cookies\[removed][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\NQGJVP4X\mm[1].js -> Spyware.Chitika : Cleaned with backup
C:\Documents and Settings\Jennifer\Local Settings\Temporary Internet Files\Content.IE5\WXQRGHMJ\ErrorSafeScannerInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Ted\Cookies\ted@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Ted\Local Settings\Temporary Internet Files\Content.IE5\GXAB0TQR\gdnUS2297[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Downloads\finaldrivenitroam[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Downloads\LemonadeTycoon2Setup-dm[1].exe -> Spyware.Trymedia : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\34C729A5-7C5E-4F3E-9174-B40127\87CA72D0-263D-499C-8861-A5D9A1 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\510744AE-FD5C-45C7-84AF-EC9EA6\03B2C8CC-20CC-4993-964A-1301AF -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\8D13DAEB-8734-4BD0-B5B4-471901\AD3197D7-1AD5-4D92-B7E3-DFD6EB -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\90B4441B-270E-43C3-ACF0-5A63BC\F875BEAA-6D67-45CA-BEAD-5F0B9E -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP11\A0000366.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000409.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP12\A0000410.exe -> Downloader.Small.awa : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP14\A0000559.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP19\A0002608.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP20\A0002645.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002677.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002885.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP22\A0002975.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0002995.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP23\A0003019.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003032.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003034.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003044.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003052.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003144.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003207.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003208.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003212.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003213.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003214.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003215.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003217.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003220.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003221.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003224.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003226.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003227.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003230.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003232.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003236.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003237.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003239.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003248.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP24\A0003249.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP25\A0003333.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003368.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003369.exe -> Downloader.Zlob.bn : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003629.dll -> Trojan.Small.ev : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003630.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003631.exe -> Downloader.Agent.abs : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003632.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003633.exe -> Downloader.Agent.zx : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003636.exe -> Downloader.Small.bpz : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP26\A0003644.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003707.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003708.dll -> Downloader.SpyAxe : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003712.exe -> Downloader.Zlob.bu : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003714.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP28\A0003734.exe -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP4\A0000122.dll -> Downloader.Small.cat : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000230.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7DCA1BE4-D752-48D6-A25E-C722C8FD1BC4}\RP7\A0000231.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\in9bTs.dll -> Adware.eZula : Cleaned with backup
C:\WINNT\system32\ldr100.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr111.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr120.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr121.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr129.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr130.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr133.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr160.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr172.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr182.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr185.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr193.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr204.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr208.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr210.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr212.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr218.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr221.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr222.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr226.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr235.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr237.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr241.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr243.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr248.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr253.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr260.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr265.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr282.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr294.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr30.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr312.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr320.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr326.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr331.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr333.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr337.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr344.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr348.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr356.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr358.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr374.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr382.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr383.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr396.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr407.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr41.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr424.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr436.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr439.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr459.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr468.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr475.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr479.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr484.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr485.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr49.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr497.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr50.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr509.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr513.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr517.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr519.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr528.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr533.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr538.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr539.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr552.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr553.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr556.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr557.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr558.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr564.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr566.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr567.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr569.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr577.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr58.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr580.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr584.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr59.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr590.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr591.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr592.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr597.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr601.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr617.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr62.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr640.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr654.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr656.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr66.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr668.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr672.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr682.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr687.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr691.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr702.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr711.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr738.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr75.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr750.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr777.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr784.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr80.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr802.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr804.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr81.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr854.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr86.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr864.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr880.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr884.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr886.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr890.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr891.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr894.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr904.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr905.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr945.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr963.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINNT\system32\ldr99.dll -> Downloader.Small.cat : Cleaned with backup
::Report End
———————————End of Ewido Log——————————————-
———————————Beginning of Smitrem Log——————————–
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Fri 12/30/2005
The current time is: 10:46:48.26
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
checking for WinHound.com key
WinHound.com key not present!
spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 820 'explorer.exe'
Killing PID 820 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Online Security Guide.url
Online Security Guide.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
———————————————End of Smitrem Log————————————