This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan? Backdoor virus? Computer is a wreck.

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and happy New Year!

I've been having several problems with my PC since Wednesday night when I noticed a weird icon of a lady (kinda looked like Ms. Krabapple from the Simpsons) in my C drive. The title was ntfull(something). It has since been deleted.

Problem #1 is when I turn on my PC. I get a message that says "backupnotify.exe" on the left of the pop-up box, "application error" to the right and the text of the box says "The application failed to intialize properly (0x0000005) Click on OK to terminate application." I click OK and it comes up again right away and I have to click OK again.

Problem #2 is when I try to access McAfee, Symantec, these forums, most any anti-virus/anti-malware webpage out there, I either get a couple different Microsoft Pages saying page could not be found or the screen just goes white with "done" in the bottom left corner.

I ordered Verizon Internet Security Suite (which I had problems installing but was fixed by the Verizon tech people) and did a scan. It found an embarassing amount of spyware and viruses which I had the program delete and yet I still get the message when I reboot my computer and I still could not access the above webpages.

I was able to go to the Ewido page and d/l that and they did a scan (which I saved the log for) and loads of spyware, some trojans and a backdoor virus were detected and deleted. The I said to hell with IE and d/l Mozilla. After that, I was able to access a few more anti-virus/anti-malware websites (this forum being one of them) but still no McAfee, Symantec and several others.

Apologies for the length. I'm hungover and feel the need to share everything. (PS: Why does it say I'm still using IE?)

Here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:57:47 AM, on 1/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Verizon\Internet Security Suite\Freedom.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….1&bm=ho_search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Verizon\Internet Security Suite\pkR.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Verizon\Internet Security Suite\FreeBHOR.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [links] links.exe
O4 - HKLM\..\Run: [Internet Security Suite] C:\Program Files\Verizon\Internet Security Suite\Freedom.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: tcpQ32 - C:\WINDOWS\SYSTEM32\tcpQ32.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
OK, I just wanted to post an update and a new HJT log. I got rid of Internet Security Suite and d/l AVG at the urging of my work's IT God. I ran a scan and it deleted three infected files, all trojans. After I re-booted my computer, the annoying backupnotify.exe error message didn't pop up and I drank a beer to celebrate. THEN I tried going to McAfee and VirusList and Symantec and I could access them again.

BUT AVG keeps popping up w/a virus detected message (trojan horse backdoor.generic2.m) and I can't do a thing to it. None of the options work and it keeps popping up. I did a search for the infected file (C:\WINDOWS\SYSTEM32\tcpQ32.dll) and came up with my HJT log and AVG history as the only results.

I will not delete it. I don't know what I'm doing. But it's there.

New HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 8:11:55 PM, on 1/3/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….1&bm=ho_search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [links] links.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: tcpQ32 - C:\WINDOWS\SYSTEM32\tcpQ32.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
Hello and welcome to TomCoyote forum. If you still need help, I would like you to follow these directions.

First: Move HJT from the Desktop for safety. I prefer C:\HJT\HijackThis.exe, if you need additional instructions use these: http://russelltexas.com/malware/createhjtfolder.htm

We will use SpySweeper and it very important that you download the FREE TRIAL VERSION from the bottom of this page:
http://www.webroot.com/consumer/products/s…er/latestv.html Then follow the rest of these instructions.
Download the free trial version of Spy Sweeper
Note: On that page, in the Spy Sweeper section, click the link for "Free Trial", NOT the link for "Free Spyware Scan".
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Restart your computer <<< very important that you reboot

Now open ewido and choose "update" allow the program to update then scan your complete system and remove anything ewido locates unless you know it is not bad. Use these instructions to configure:
http://rstones12.geekstogo.com/ewidosetup.htm they may be slightly different since you already have it downloaded.

Make sure to save the ewido scan report. Post it along with the SpySweeper log in this same thread. There will be more to do.

Thanks…pskelley
TomCoyote forum
Expert Member
Thanks. Here's the Spysweeper log: (I'm putting parental controls on my computer as soon as it's cleaned. Sheesh.) ******** 9:36 PM: | Start of Session, Tuesday, January 03, 2006 | 9:36 PM: Spy Sweeper started 9:36 PM: Sweep initiated using definitions version 595 9:36 PM: Starting Memory Sweep 9:39 PM: Memory Sweep Complete, Elapsed Time: 00:03:30 9:39 PM: Starting Registry Sweep 9:40 PM: Found Adware: iwon 9:40 PM: HKLM\software\microsoft\windows\currentversion\uninstall\iwoncopilot\ (5 subtraces) (ID = 129307) 9:40 PM: HKLM\software\microsoft\windows\currentversion\uninstall\iwonslots\ (2 subtraces) (ID = 129309) 9:40 PM: Found Adware: trojan-downloader-linkschain 9:40 PM: HKLM\software\microsoft\windows\currentversion\run\ || links (ID = 1015825) 9:40 PM: HKU\S-1-5-21-4121975358-3303806650-3302315319-1003\software\netscape\netscape navigator\automation shutdown\ || iwontoolbar.iwonnetscapeshutdown.1 (ID = 129310) 9:40 PM: Registry Sweep Complete, Elapsed Time:00:00:45 9:40 PM: Starting Cookie Sweep 9:40 PM: Found Spy Cookie: sandboxer cookie 9:40 PM: owner@0[1].txt (ID = 3282) 9:40 PM: owner@0[2].txt (ID = 3282) 9:40 PM: Found Spy Cookie: primaryads cookie 9:40 PM: [removed][1].txt (ID = 3190) 9:40 PM: Found Spy Cookie: 3 cookie 9:40 PM: owner@3[2].txt (ID = 1959) 9:40 PM: Found Spy Cookie: 64.62.232 cookie 9:40 PM: owner@64.62.232[2].txt (ID = 1987) 9:40 PM: Found Spy Cookie: websponsors cookie 9:40 PM: [removed][1].txt (ID = 3665) 9:40 PM: Found Spy Cookie: go.com cookie 9:40 PM: [removed][1].txt (ID = 2729) 9:40 PM: Found Spy Cookie: adrevolver cookie 9:40 PM: owner@adrevolver[2].txt (ID = 2088) 9:40 PM: owner@adrevolver[3].txt (ID = 2088) 9:40 PM: Found Spy Cookie: cc214142 cookie 9:40 PM: owner@ads.cc214142[1].txt (ID = 2367) 9:40 PM: Found Spy Cookie: ads.stileproject cookie 9:40 PM: [removed][1].txt (ID = 2127) 9:40 PM: Found Spy Cookie: adultfriendfinder cookie 9:40 PM: owner@adultfriendfinder[1].txt (ID = 2165) 9:40 PM: Found Spy Cookie: adultrevenueservice cookie 9:40 PM: owner@adultrevenueservice[1].txt (ID = 2167) 9:40 PM: Found Spy Cookie: alt cookie 9:40 PM: owner@alt[1].txt (ID = 2217) 9:40 PM: Found Spy Cookie: apmebf cookie 9:40 PM: owner@apmebf[1].txt (ID = 2229) 9:40 PM: Found Spy Cookie: ask cookie 9:40 PM: owner@ask[1].txt (ID = 2245) 9:40 PM: Found Spy Cookie: belnk cookie 9:40 PM: [removed][2].txt (ID = 2293) 9:40 PM: Found Spy Cookie: atwola cookie 9:40 PM: owner@atwola[1].txt (ID = 2255) 9:40 PM: Found Spy Cookie: azjmp cookie 9:40 PM: owner@azjmp[2].txt (ID = 2270) 9:40 PM: Found Spy Cookie: banner cookie 9:40 PM: owner@banner[1].txt (ID = 2276) 9:40 PM: owner@belnk[1].txt (ID = 2292) 9:40 PM: Found Spy Cookie: enhance cookie 9:40 PM: [removed][1].txt (ID = 2614) 9:40 PM: Found Spy Cookie: barelylegal cookie 9:40 PM: [removed][2].txt (ID = 2286) 9:40 PM: Found Spy Cookie: goclick cookie 9:40 PM: [removed][2].txt (ID = 2733) 9:40 PM: Found Spy Cookie: zedo cookie 9:40 PM: [removed][1].txt (ID = 3763) 9:40 PM: Found Spy Cookie: gostats cookie 9:40 PM: [removed][1].txt (ID = 2748) 9:40 PM: Found Spy Cookie: ccbill cookie 9:40 PM: owner@ccbill[1].txt (ID = 2369) 9:40 PM: Found Spy Cookie: cnt cookie 9:40 PM: owner@cnt[1].txt (ID = 2422) 9:40 PM: Found Spy Cookie: did-it cookie 9:40 PM: owner@did-it[2].txt (ID = 2523) 9:40 PM: [removed][1].txt (ID = 2729) 9:40 PM: [removed][2].txt (ID = 2293) 9:40 PM: Found Spy Cookie: freshauditionsdating cookie 9:40 PM: owner@freshauditionsdating[1].txt (ID = 2710) 9:40 PM: owner@gostats[2].txt (ID = 2747) 9:40 PM: owner@go[1].txt (ID = 2728) 9:40 PM: Found Spy Cookie: herfirstanalsex cookie 9:40 PM: owner@herfirstanalsex[2].txt (ID = 2769) 9:40 PM: Found Spy Cookie: clickandtrack cookie 9:40 PM: [removed][2].txt (ID = 2397) 9:40 PM: Found Spy Cookie: hotmatch cookie 9:40 PM: owner@hotmatch[1].txt (ID = 3854) 9:40 PM: Found Spy Cookie: ic-live cookie 9:40 PM: owner@ic-live[1].txt (ID = 2821) 9:40 PM: Found Spy Cookie: iwon cookie 9:40 PM: [removed][1].txt (ID = 2884) 9:40 PM: Found Spy Cookie: imlive.com cookie 9:40 PM: owner@imlive[2].txt (ID = 2843) 9:40 PM: Found Spy Cookie: netster cookie 9:40 PM: [removed][1].txt (ID = 3072) 9:41 PM: Found Spy Cookie: infospace cookie 9:41 PM: owner@infospace[1].txt (ID = 2865) 9:41 PM: Found Spy Cookie: seeq cookie 9:41 PM: [removed][1].txt (ID = 3332) 9:41 PM: Found Spy Cookie: kount cookie 9:41 PM: owner@kount[2].txt (ID = 2911) 9:41 PM: Found Spy Cookie: ugo cookie 9:41 PM: [removed][2].txt (ID = 3609) 9:41 PM: [removed][1].txt (ID = 2884) 9:41 PM: Found Spy Cookie: metareward.com cookie 9:41 PM: owner@metareward[2].txt (ID = 2990) 9:41 PM: Found Spy Cookie: military cookie 9:41 PM: owner@military[1].txt (ID = 2996) 9:41 PM: [removed][1].txt (ID = 2748) 9:41 PM: [removed][1].txt (ID = 2729) 9:41 PM: Found Spy Cookie: nextag cookie 9:41 PM: owner@nextag[1].txt (ID = 5014) 9:41 PM: Found Spy Cookie: netratingsselect cookie 9:41 PM: owner@nnselect[2].txt (ID = 3065) 9:41 PM: Found Spy Cookie: outster cookie 9:41 PM: owner@outster[2].txt (ID = 3103) 9:41 PM: Found Spy Cookie: partypoker cookie 9:41 PM: owner@partypoker[2].txt (ID = 3111) 9:41 PM: Found Spy Cookie: passion cookie 9:41 PM: owner@passion[2].txt (ID = 3113) 9:41 PM: Found Spy Cookie: moviemonster cookie 9:41 PM: [removed][2].txt (ID = 3011) 9:41 PM: Found Spy Cookie: rightmedia cookie 9:41 PM: owner@rightmedia[2].txt (ID = 3259) 9:41 PM: Found Spy Cookie: rn11 cookie 9:41 PM: owner@rn11[2].txt (ID = 3261) 9:41 PM: Found Spy Cookie: tvguide cookie 9:41 PM: [removed][1].txt (ID = 3600) 9:41 PM: Found Spy Cookie: starware.com cookie 9:41 PM: [removed][2].txt (ID = 3442) 9:41 PM: owner@seeq[1].txt (ID = 3331) 9:41 PM: Found Spy Cookie: about cookie 9:41 PM: [removed][2].txt (ID = 2038) 9:41 PM: Found Spy Cookie: tickle cookie 9:41 PM: owner@tickle[2].txt (ID = 3529) 9:41 PM: Found Spy Cookie: toplist cookie 9:41 PM: owner@toplist[1].txt (ID = 3557) 9:41 PM: owner@toplist[2].txt (ID = 3557) 9:41 PM: Found Spy Cookie: sexsearch cookie 9:41 PM: [removed][2].txt (ID = 3358) 9:41 PM: Found Spy Cookie: tracking cookie 9:41 PM: owner@tracking[1].txt (ID = 3571) 9:41 PM: owner@tracking[2].txt (ID = 3571) 9:41 PM: owner@tvguide[1].txt (ID = 3599) 9:41 PM: [removed][1].txt (ID = 2038) 9:41 PM: Found Spy Cookie: videodome cookie 9:41 PM: owner@videodome[1].txt (ID = 3638) 9:41 PM: Found Spy Cookie: web-stat cookie 9:41 PM: owner@web-stat[2].txt (ID = 3648) 9:41 PM: [removed][1].txt (ID = 2246) 9:41 PM: Found Spy Cookie: webpower cookie 9:41 PM: owner@webpower[2].txt (ID = 3660) 9:41 PM: [removed][1].txt (ID = 2991) 9:41 PM: Found Spy Cookie: mytemplatestorage cookie 9:41 PM: [removed][1].txt (ID = 3050) 9:41 PM: Found Spy Cookie: redzip cookie 9:41 PM: [removed][1].txt (ID = 3250) 9:41 PM: Found Spy Cookie: starpulse cookie 9:41 PM: [removed][2].txt (ID = 3440) 9:41 PM: Found Spy Cookie: stlyrics cookie 9:41 PM: [removed][1].txt (ID = 3462) 9:41 PM: [removed][2].txt (ID = 3600) 9:41 PM: Found Spy Cookie: upspiral cookie 9:41 PM: [removed][2].txt (ID = 3615) 9:41 PM: Found Spy Cookie: xzoomy cookie 9:41 PM: [removed][2].txt (ID = 3742) 9:41 PM: Found Spy Cookie: franklinsurveys cookie 9:41 PM: [removed][2].txt (ID = 2689) 9:41 PM: [removed][1].txt (ID = 3332) 9:41 PM: Found Spy Cookie: xiti cookie 9:41 PM: owner@xiti[1].txt (ID = 3717) 9:41 PM: Found Spy Cookie: xmatch cookie 9:41 PM: owner@xmatch[1].txt (ID = 3719) 9:41 PM: Cookie Sweep Complete, Elapsed Time: 00:00:22 9:41 PM: Starting File Sweep 10:08 PM: iwonslot1,0,2,5.inf (ID = 64809) 10:08 PM: Found System Monitor: potentially rootkit-masked files 10:08 PM: tcpq64.sys (ID = 0) 10:08 PM: tcpq32.dll (ID = 0) 10:08 PM: qz.dll (ID = 0) 10:08 PM: qz.sys (ID = 0) 10:08 PM: klgcptini.dat (ID = 0) 10:08 PM: stt82.ini (ID = 0) 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:08 PM: Warning: Invalid file - not a PKZip file 10:09 PM: File Sweep Complete, Elapsed Time: 00:27:56 10:09 PM: Full Sweep has completed. Elapsed time 00:32:39 10:09 PM: Traces Found: 104 10:10 PM: Removal process initiated 10:10 PM: Quarantining All Traces: potentially rootkit-masked files 10:10 PM: Quarantining All Traces: iwon 10:10 PM: Quarantining All Traces: trojan-downloader-linkschain 10:10 PM: Quarantining All Traces: 3 cookie 10:10 PM: Quarantining All Traces: 64.62.232 cookie 10:10 PM: Quarantining All Traces: about cookie 10:10 PM: Quarantining All Traces: adrevolver cookie 10:10 PM: Quarantining All Traces: ads.stileproject cookie 10:10 PM: Quarantining All Traces: adultfriendfinder cookie 10:10 PM: Quarantining All Traces: adultrevenueservice cookie 10:10 PM: Quarantining All Traces: alt cookie 10:10 PM: Quarantining All Traces: apmebf cookie 10:10 PM: Quarantining All Traces: ask cookie 10:10 PM: Quarantining All Traces: atwola cookie 10:10 PM: Quarantining All Traces: azjmp cookie 10:10 PM: Quarantining All Traces: banner cookie 10:10 PM: Quarantining All Traces: barelylegal cookie 10:10 PM: Quarantining All Traces: belnk cookie 10:10 PM: Quarantining All Traces: cc214142 cookie 10:10 PM: Quarantining All Traces: ccbill cookie 10:10 PM: Quarantining All Traces: clickandtrack cookie 10:10 PM: Quarantining All Traces: cnt cookie 10:10 PM: Quarantining All Traces: did-it cookie 10:10 PM: Quarantining All Traces: enhance cookie 10:10 PM: Quarantining All Traces: franklinsurveys cookie 10:10 PM: Quarantining All Traces: freshauditionsdating cookie 10:10 PM: Quarantining All Traces: go.com cookie 10:10 PM: Quarantining All Traces: goclick cookie 10:10 PM: Quarantining All Traces: gostats cookie 10:10 PM: Quarantining All Traces: herfirstanalsex cookie 10:10 PM: Quarantining All Traces: hotmatch cookie 10:10 PM: Quarantining All Traces: ic-live cookie 10:10 PM: Quarantining All Traces: imlive.com cookie 10:10 PM: Quarantining All Traces: infospace cookie 10:10 PM: Quarantining All Traces: iwon cookie 10:10 PM: Quarantining All Traces: kount cookie 10:10 PM: Quarantining All Traces: metareward.com cookie 10:10 PM: Quarantining All Traces: military cookie 10:10 PM: Quarantining All Traces: moviemonster cookie 10:10 PM: Quarantining All Traces: mytemplatestorage cookie 10:10 PM: Quarantining All Traces: netratingsselect cookie 10:10 PM: Quarantining All Traces: netster cookie 10:10 PM: Quarantining All Traces: nextag cookie 10:10 PM: Quarantining All Traces: outster cookie 10:10 PM: Quarantining All Traces: partypoker cookie 10:10 PM: Quarantining All Traces: passion cookie 10:10 PM: Quarantining All Traces: primaryads cookie 10:10 PM: Quarantining All Traces: redzip cookie 10:10 PM: Quarantining All Traces: rightmedia cookie 10:10 PM: Quarantining All Traces: rn11 cookie 10:10 PM: Quarantining All Traces: sandboxer cookie 10:10 PM: Quarantining All Traces: seeq cookie 10:10 PM: Quarantining All Traces: sexsearch cookie 10:10 PM: Quarantining All Traces: starpulse cookie 10:10 PM: Quarantining All Traces: starware.com cookie 10:10 PM: Quarantining All Traces: stlyrics cookie 10:10 PM: Quarantining All Traces: tickle cookie 10:10 PM: Quarantining All Traces: toplist cookie 10:10 PM: Quarantining All Traces: tracking cookie 10:10 PM: Quarantining All Traces: tvguide cookie 10:10 PM: Quarantining All Traces: ugo cookie 10:10 PM: Quarantining All Traces: upspiral cookie 10:10 PM: Quarantining All Traces: videodome cookie 10:10 PM: Quarantining All Traces: webpower cookie 10:10 PM: Quarantining All Traces: websponsors cookie 10:10 PM: Quarantining All Traces: web-stat cookie 10:10 PM: Quarantining All Traces: xiti cookie 10:10 PM: Quarantining All Traces: xmatch cookie 10:10 PM: Quarantining All Traces: xzoomy cookie 10:10 PM: Quarantining All Traces: zedo cookie 10:10 PM: Removal process completed. Elapsed time 00:00:34 ******** 9:34 PM: | Start of Session, Tuesday, January 03, 2006 | 9:34 PM: Spy Sweeper started 9:35 PM: Your spyware definitions have been updated. 9:36 PM: | End of Session, Tuesday, January 03, 2006 | And here's the Ewido report: ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 7:54:41 AM, 1/4/2006 + Report-Checksum: 24B88F38 + Scan result: :mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup :mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.83:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup :mozilla.93:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\h02n4a47.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup ::Report End I have to go to work now, but will be home at 5. Thank you, thank you thank, for helping me.
The new HJT Scan-

Logfile of HijackThis v1.99.1
Scan saved at 5:23:47 PM, on 1/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hjt\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….1&bm=ho_search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: tcpQ32 - tcpQ32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Thanks for the HJT log and for moving HJT to a safe place. I want to look at HJT first.

First, the R1/R0 lines dealing with HP search junk, I would like to remove them. It is just clutter and is not making your browser run faster. You can click any of them to see where they send you and you can still set any homepage you wish.

Second, I want to mention the both SpySweeper and ewido are resource users (as you would expect) ewido, you can keep the scaner with updates for as long as you like, but I suggest unless you purchase that you turn them off or uninstall SS once the trials are over.

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE is considered "Spyware" see this: http://castlecops.com/startuplist-180.html Personally I am surprised a valid company like Realtek does this, this is optional, if you want it removed make sure you remove only the file I have highlited in red.

This item: O2/03 - BHO: Verizon Broadband Toolbar is missing a file and not working correctly if at all. If you wish to use it, download it again once you are clean.

Having said that, let's finish up like this:

1) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

2) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….1&bm=ho_search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us9.hpwis.com/
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O20 - Winlogon Notify: tcpQ32 - tcpQ32.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

3) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

ALCXMNTR.EXE >>> file only, you will have to search for this, probably C:\Windows\

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

4) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log in this same thread along with any feedback you have. Please tell me how you are running now.

5) When you are completely finished with the removal procedure and are satisfied that the threat has been removed follow these instructions:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

Thanks…Phil
Ad-Aware is not letting me update. It just freezes at 5%. Is it dire that I use this program or may I move on to the next step? I've re-booted twice and I still can't get an update. Thanks again for all your help.
OK, I went ahead and scanned using the un-updated Ad-Adware since out-of-date is better than nothing at all and I deleted the files it suggested. No problems with SpyBot and ditto on the deleting.

I looked for ALCXMNTR.EXE and found five items, but was not sure what to delete since you said "file only" and 4 of them were not files, I think. There was one by that exact name in the prefetch folder which was deleted when I got rid off all the files in that folder. Since you said that getting rid of the item was optional and CastleCops said it wasn't a malicious program, just crappy spyware, I left the rest alone. I will delete them all upon your approval. They all had a crab icon, if that means anything.

My computer seems fine and AVG has not popped up with the backdoor virus warning, but all symptoms that made me come here in the first place were fixed when I ran the AVG scan yesterday afternoon, before I kept getting the backdoor message.

Now, though, I keep gettin a pop-up about updates from SonicNet (I think that's the name) I'll Google it later.

Right now, my main concern is being able to check my bank account online again and using my credit card online. I'll run one more AVG scan before I go to bed tonight.

Also, Ewido will be deleted, along with a few other programs.

Here's the new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:41:28 PM, on 1/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Verizon Online\bin\mpbtn.exe
C:\hjt\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

Thanks again for you help and I'm sorry if I'm rambling.
Hello molly, Let's look at Ad-aware first. No it is not dire, Spybot will get most of the same adware as Ad-aware. These two programs use little space and set dormant until you need them. (unless TeaTimer is activated in Spybot). It would be good if you can install and use Ad-adware though as it is a very important tool on some infections. We can do without it to finish this cleanup. I suggest you try uninstalling it and downloading it again later, make sure you are downloading the FREE version. Here is a good forum where you may get help: http://castlecops.com/f142-Lavasoft_Ad_Aware.html Once we are done and you have a little time, see if you can troubleshoot that installation with CastleCops help.

As far as this goes: ALCXMNTR.EXE I would rather you left it than delete the wrong file. It is your audio. It is also not malicious. You may want to address the issue with the company later: http://www.realtek.com.tw/contact/contactX…name=contact1-4 that is your option.

My computer seems fine and AVG has not popped up with the backdoor virus warning

This is good, I was going to request that you update and run a complete system scan anyway, since it is coming up clean, make sure AVG is set for automatic updates and schedule a time for it to scan your computer when it will not interfere with your work.

Now, though, I keep gettin a pop-up about updates from SonicNet

O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r You have it set to run each time you boot. Here is what it is: http://castlecops.com/startuplist-3546.html You should be able to turn it off in MSConfig: http://netsquirrel.com/msconfig/ or from within the program.

Also, Ewido will be deleted, along with a few other programs.

I will say again that the ewido scanner and free updates will NOT use any resources if you turn it off so it can not run (disable in services) you should not see it in the log. I use mine about once a month to keep an eye on stuff Spybot/Ad-aware miss. Now unless you own SpySweeper I do not believe it will do anything once the trial is over. Your call.
You do have a few programs running at startup you may be able to turn off to save resources. Google the executable on any line that starts like this: O4 - HKLM\..\Run. You HJT log is showing no malware, and if all is coming up clean you are good to go. Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Safe Surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Thank you SO FREAKIN' MUCH. You just successfully helped me end a 5 day freakout about the state of my computer. Your final advice has been more than helpful and I will tend to your suggestions once I can stand sitting in front of a computer screen for longer than ten minutes again. You're a saint. Thank you.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI