spyware
11 min read
There's a new version of HijackThis.
Please delete any HijackThis Folders and Files you have now.
Please download this self extracting file to your My Downloads folder or My Received Files (dependent on your Operating System):
Click the "Save" button.
Navigate to My Documents>Chose My Downloads or My Received Files folder once inside that folder click "Save".
Now go to the folder you saved HijackThis_sfx.exe in.
Double click HijackThis_sfx.exe and select Unzip. When done click "OK".
Close the WinZip self Extractor window.
Open HijackThis and select: Do a system scan and save a log file.
When the scan is finished, Click Edit> Select All> Edit> Copy> and paste its contents here [Add Reply].
Hello suhail, Welcome to the Forum.
There's a new version of HijackThis.
Please delete any HijackThis Folders and Files you have now.
Please download this self extracting file to your My Downloads folder or My Received Files (dependent on your Operating System):
Click the "Save" button.
Navigate to My Documents>Chose My Downloads or My Received Files folder once inside that folder click "Save".
Now go to the folder you saved HijackThis_sfx.exe in.
Double click HijackThis_sfx.exe and select Unzip. When done click "OK".
Close the WinZip self Extractor window.
Open HijackThis and select: Do a system scan and save a log file.
When the scan is finished, Click Edit> Select All> Edit> Copy> and paste its contents here [Add Reply].
Here it is dude. I'll keep my fingers crossed
Logfile of HijackThis v1.99.1
Scan saved at 12:52:58 AM, on 1/17/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\addkv32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
C:\Program Files\Smart-Speed\SmartSpeed2.0.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\WINDOWS\system32\msbi32.exe
C:\winstall.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\shell386.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultp
osition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\xmkpf.dll/sp.html#88449%resultposition.net
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {0713F490-5897-74D3-8736-456602C0D47B} - C:\WINDOWS\system32\ntty.dll
O2 - BHO: Class - {08758A23-686A-D1F3-ED90-69CB61C8741D} - C:\WINDOWS\addqd.dll
O2 - BHO: Class - {10AA115E-9874-17AF-147C-C424D9FA21F0} - C:\WINDOWS\ipjv32.dll
O2 - BHO: Class - {1B056603-6606-516A-4D3F-B2CDA5116B5B} - C:\WINDOWS\mfcpb.dll
O2 - BHO: Class - {34266EAB-10FC-675A-938B-149B57C0B571} - C:\WINDOWS\iemh.dll
O2 - BHO: Class - {486C8EBC-94F7-84B6-486B-926EB7B5C768} - C:\WINDOWS\ieol.dll
O2 - BHO: Class - {4B3E5A14-3E7C-118C-24D5-F3F49D8E89A8} - C:\WINDOWS\system32\ierc.dll
O2 - BHO: Class - {4E09FF81-80A8-DBD8-3E83-3C177063F6ED} - C:\WINDOWS\sysov.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll
O2 - BHO: Class - {58424828-3F1E-F0E7-AA14-833DD569B7CD} - C:\WINDOWS\system32\d3tt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Class - {8EF1A0D7-1F28-169C-CDC6-204EFF24D24A} - C:\WINDOWS\neteq32.dll
O2 - BHO: Class - {A18BBD1A-155E-061F-CEC3-1D1D0FD001AD} - C:\WINDOWS\sysyd32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O2 - BHO: Class - {A5152B07-E5DB-91EF-DE2E-52F765593512} - C:\WINDOWS\sdkco.dll
O2 - BHO: Class - {B0375CCF-9532-2B4F-8D3C-3766EF4FFA65} - C:\WINDOWS\system32\mfcug.dll
O2 - BHO: Class - {C10E70B6-0A9C-EFB9-C902-4055C2D7F322} - C:\WINDOWS\addqd.dll
O2 - BHO: Class - {C4846C68-7320-CD9D-77E4-288DF6A3C3A2} - C:\WINDOWS\ntuf32.dll
O2 - BHO: Class - {CE6391C4-346E-13E9-03A2-E8708CCA3B6A} - C:\WINDOWS\system32\ntqp.dll
O2 - BHO: Class - {D7C43CFF-343D-063E-1C14-C8A0FEB6F6A4} - C:\WINDOWS\system32\d3fu32.dll
O2 - BHO: Class - {F97B935C-4820-CB6C-D4EF-A3AF4B649DB3} - C:\WINDOWS\ipnt.dll
O2 - BHO: Class - {F9F0D49F-C740-D5E3-0FCC-BE0B70DE122C} - C:\WINDOWS\ntvp32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [links] links.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [5.tmp] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [ntya.exe] C:\WINDOWS\ntya.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SmartSpeed] C:\Program Files\Smart-Speed\SmartSpeed2.0.exe
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [GameDrive] "C:\Program Files\FarStone\GameDrive\GDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [atltm.exe] C:\WINDOWS\atltm.exe
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [apipc.exe] C:\WINDOWS\apipc.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [apiux.exe] C:\WINDOWS\apiux.exe
O4 - HKLM\..\Run: [msbi32.exe] C:\WINDOWS\system32\msbi32.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKLM\..\Run: [apilf32.exe] C:\WINDOWS\system32\apilf32.exe
O4 - HKLM\..\Run: [d3mx.exe] C:\WINDOWS\system32\d3mx.exe
O4 - HKLM\..\Run: [apior32.exe] C:\WINDOWS\apior32.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addkv32.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
Please do not delete anything unless instructed to.
Download CWShredder from my signature below. Unzip it on the desktop.
Open CWShredder and with ALL other windows closed, click fix.
Even if you've already run these, make SURE they're up-to-date and run per instructions.
Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.
Download Spybot, install and update. Then download Ad-aware, install, and update.
Spybot:
Install the program and launch it.
Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D
Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.
Ad-Aware FULL SCAN:
Install the program and launch it.
1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.
Next:
Please download the trial version of ewido anti-malware 3.5 here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.
Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Scan saved at 1:23:08 AM, on 1/18/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 1:20:40 AM, 1/18/2006
+ Report-Checksum: E4704D33
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{029DB004-6BCD-0E73-3AEA-F205B565F0F8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{04256906-BECE-83AC-2058-27ABA38B11A3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{07F0CAA0-8206-9DCC-5402-D4CC24EC1764} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{09248DC7-285D-A208-7675-8D1BAC7208C9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0B4F9B2C-F81D-7C42-AE33-07F0FCB846EC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{109FCEAD-8C5C-5B76-3BB3-A646D2B52C93} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{10D837D7-D6EA-8BCE-37FB-E58A2E09397B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{12130DCB-3DF4-96EC-27B9-61E0D766F680} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1228458E-6B19-48F4-5449-A00AEE93F0FC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1323178D-09E3-B628-CC3A-95630B64B7DA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1486290A-90C1-388F-ADC8-6BFAA6B057E8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1674BCBE-46DE-7BAB-FBFA-CA15D9FEB632} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{16C710FD-4C93-9C02-15FC-681DF7937350} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1714A690-3BE3-3C63-D05D-B9E2E19A88A3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{18EAFE7B-570B-346C-ADEF-9CDDA8A1986F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1D232F9D-941D-5CD9-732F-8F6EC1977CF2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1D3E7FA6-E393-C514-F461-E0B59435D825} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1DE20533-9118-BF9A-A6C6-F8E881A5FD4B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1F6A3B74-3D40-4D48-4D55-E3A0A8029CC2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1FE935FF-DB66-AC76-99D8-18EC1F0F013C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{211D33BE-B506-603A-E0C1-E50E4D62779F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{22E7067A-283F-CF1C-4373-210A97C38BDB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{25742C0F-DC0D-F5DC-55DE-C66285AA22AB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{286ECE71-3F17-089B-F6BD-0E16D255AE8A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{29B25401-5964-022D-3AC2-C7207FEFF994} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B284248-D0FE-C340-0D87-ABD55DD24BFA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B5A2313-AE67-454E-9A8B-F74070E57F1B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2BFAB072-A3F3-0A97-6990-3673392B7DFC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2D99FD34-F395-DFB0-0852-36D4976F6E3D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3684B1D1-C737-AA3A-00B8-83FE7FF3C058} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38A09FC8-FCAF-3D1E-A6D6-FB0A0E2E2D98} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38C14AA2-0708-7DAD-F01C-6C0208A38BE2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38EA95B6-06DF-844E-6763-813A152D6F74} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3BAA3AE9-9C0B-E08A-A982-9818F457337E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3D1F3C37-49CA-66D3-9877-04375ADE521D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3E8AEA49-2882-96D1-D4B0-D1EA3E4EEFD2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3EA8A165-1EE8-2BEF-A8D1-9CDBD760FC43} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3F15B481-32E2-FE85-96FA-A8976289B4FD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4095AAF5-BAD2-A97D-D64C-566A52E35C2E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{44CE9131-E13C-D36A-083A-FAFF61E866CA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{452C15DF-936D-C8CB-B825-97DD4A210ABD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{46C8C875-7053-566F-B7DF-A8735884B10E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4822A81B-A35C-81CA-4B1E-595C44DF3F5E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4904C579-9366-3B77-3148-9401DBD4A5AA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{491288EB-D314-5571-9C18-B1EAC89ADE09} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4B3176F0-E32F-B010-C0D8-65FC118C3716} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4C1CBC17-3C15-343F-1E7C-D8F447935C05} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4C96C433-2EDC-3926-B873-410DB1199685} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4E11A0FD-72A3-AEF3-D4E4-E168F75A238E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4FCD2C21-6232-FD0F-36AA-4EFFC9284B2A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{50B9D537-5DB0-52B1-FF6F-ED6C70DA477E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{529D86BB-85DC-FC40-1699-BECC09038E95} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{52CA0FCE-F9E0-2125-6CA6-2627141A47E9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{53741D3E-19CE-5959-0908-3BB13C3C3990} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5735BB6F-7A93-49E1-B628-ABB60DAA5F0B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5932F9CB-E60E-11C7-5BA5-2CD8198CBDB4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5B9A8BE3-69A5-661B-3BB5-FA99E29D5453} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5DA6CA48-7D98-BC0B-40EF-22AC6558668A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{677E5988-9E47-B4BE-8002-B86CEAD32154} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{68005AEB-2632-F033-B29F-EA21C446CA22} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{69A88C5E-04E5-741D-6CA2-9CB5374EB263} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6A389597-708B-6F9D-B6EC-8D1A3EC9DFAF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6A493714-8012-621E-A09E-CD80FF52FB1F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6D3DF846-86BE-A81E-C69E-5A1818F8E929} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{714C2287-DB2D-3514-4785-8EC21BA5C5F1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{742CF04D-EE46-1423-E899-B91C547ABC20} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{76321C6A-B800-93A4-24BB-B1F318D2A8E0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{795714A8-C9C0-E8BD-30DB-A0DA3B603993} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7A8EC00B-7964-C396-E2F8-621F6C9029FA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7DA446BF-5485-78F9-CC9A-2A02C93519E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7E2B347A-52AA-597F-9371-80822A8D1263} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8007F30A-ADD5-7E61-D29C-8F166BC8A3DD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8169E4D3-2914-C956-AAFE-F49D78C929A8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{821C8BB3-C516-BEE5-C6A4-ECF0D92BF426} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{826D0369-102B-4A44-F27B-D9DCC50A8EE6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{85F1C7FC-7359-D6D5-C42B-F3E410DB4CAD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{88261A8F-96F3-66D7-0279-B1C677B30B41} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8BBD3FEB-8F56-FA45-F83E-0589E7E09434} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8E22B410-9A68-7588-EDE1-05BA98980E7E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8E883EC3-ABB5-0CD9-EC0A-78CB81A818D1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{952B27F0-D129-A966-5DF7-9E2D52C7E338} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{98832348-0E38-D102-51A5-517934760119} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9913F006-5621-D9B4-E3CB-064477E8D278} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{99B1E639-DCA2-2C21-013F-DEF4B5729CA9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9C149FC6-86A5-C649-4760-9E20AC138BED} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9D7705A4-9543-9869-8249-F62AC961BDA5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E2092B1-77DB-2A6A-A476-8BAA6CC65237} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E960055-CBAB-522C-F6D0-3C06FAA39285} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A0B249A8-05AF-32B0-992B-DB1CAFDEB3E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A3B9B534-33C7-F4A9-994E-4A8BFD538322} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A507C113-55E6-12CB-8EC0-BA8BE1F569B2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A5B3B4A7-6BD2-E7CE-E654-7A1D658D1BB3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A72CAEB7-7E44-7941-564B-A741D28B01DB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A7737E2C-9C15-D4BE-4A5B-C15B7E8C41E9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AAC06F6E-F261-4E44-CF1D-B1EA9712EF4B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AEDEFEF1-3732-630E-951F-1CBF02877CF3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AF197E67-53B8-6C01-4733-3E7C25BA3A3B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B36D5282-D413-F545-CF79-A6CE970CFEBB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B38F516E-48F2-CDBB-7D76-E0CFBCDBEE45} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B4F697AE-7E58-DC0D-D012-24F83EAB9F25} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B595A235-53A2-27D5-EFF6-D0208801D071} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BCA234F8-DBE0-1CBE-CE94-63240442E405} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BD757058-7180-2CE5-E5B6-8C70AEF236CC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BE5DCDBC-54D3-95EA-B258-2D53BD817431} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C092CEA0-FB34-5E12-83ED-47942941DECC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C432F8C9-5E41-F564-674E-C21B8257061B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C54510FE-72AA-27FF-1198-0CC47906F451} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C6984483-D454-B316-4040-575B9FB13D11} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C74DF792-DD4B-4B33-4D25-BB3E8A211BB3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CAEA3DE4-DAC7-8DF9-1A53-651E63E86CDF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D063E7A9-F6B2-80F8-44B2-F8210FDEDF67} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D0EFC5AD-B041-13C1-482F-CF46EFEFF6C3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D1F6B196-AB9F-2B48-C708-0B7CEC5DA4F9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D377FF80-B093-7377-D7F1-2D8792CCF322} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D75897AF-4779-FE93-0121-038FA5AA18C4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D7B5394E-D013-3545-35D0-45376236A8DC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D847DBFE-4EE2-AF6C-D202-0D9795B9D820} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D85FBAA5-5F33-6173-D800-EFD4E38AE63E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DBE13E5D-7E11-2943-722B-C75B9A94EFED} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DD25AEF3-3DC7-625D-F3C6-DE10B7C6BF82} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DE064CF5-809E-A243-CC14-F5427E5967A1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DF7346F5-4EB1-7F19-9320-5E86CBCBDA80} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E404F826-ABE4-D856-61BA-BCBD539933F8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E8A06DEA-6626-407D-5720-FE211C989AC1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E8C74323-6EAC-41DF-4232-E6575DCCE375} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EBB942DD-6CAD-83C9-BB7A-1A229122535B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EDB7FF48-2CC7-7131-A993-53C8F83DD550} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EDE4719B-AC04-9EE1-7AEA-7712560B2832} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EFC71F6E-8006-6787-AAD0-B50964B31181} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{EFF18EAC-64BF-91FF-8F1B-42B57350D99F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1E91259-92C0-8767-A2E0-85139867622A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F22C21C3-2FA8-F0A7-72B3-7927ADEFC66E} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F317424C-8ECC-86C7-5E5B-7AA1BD81D1C4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F80F0D50-2D6C-75C3-606A-3DFE0F4FC5D0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F99D5FC9-1F47-B6F5-F1D5-55AFEAD2853A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FA986CDE-0FA2-33A9-ECFD-8291DFA81985} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB277F1B-89B6-A114-DD01-EC507A933F39} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FC92C3DE-F786-C2A4-4565-359ECF140E14} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C285D18D-43A2-4AEF-83FB-BF280E660A97} -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
:mozilla.9:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.14:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.29:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.31:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.33:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.49:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.50:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.52:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.53:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.54:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.55:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.57:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.58:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.59:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.82:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.83:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.84:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.94:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.95:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.96:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.97:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.105:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.106:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.107:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.108:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.110:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.111:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.112:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.113:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.114:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.115:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.116:C:\Documents and Settings\suhail\Application Data\Mozilla\Firefox\Profiles\dz08onxk.Suhail\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\10.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\12.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\13.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\14.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\15.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\16.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\17.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\18.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\19.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1A.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1B.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1C.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1D.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1E.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\1F.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\20.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\21.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\22.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\3.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\4.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\5.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\6.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\7.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\8.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\9.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\A.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\B.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\C.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\D.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\E.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\F.tmp -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\temp.fr5F81 -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\temp.fr8C6E -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\temp.frBC02 -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temp\temp.frD081 -> Trojan.Small.ga : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\052ZSDU7\psg[1].anr -> Downloader.Ani.c : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\ALONI921\runapl[1].exe -> Downloader.VB.vc : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\CBDR6YRP\pic[1].wmf -> Exploit.MS05-053-WMF : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\CL2B4PAR\runapl[1].exe -> Trojan.Small.ev : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\CL2B4PAR\start[1].exe -> Downloader.WinShow.bi : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\IPXUJAL0\pic[1].wmf -> Exploit.MS05-053-WMF : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\OFUH2ZQV\pic[1].wmf -> Not-A-Virus.Exploit.Win32.IMG-WMF : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\OXO5MJWH\runapl[1].exe -> Not-A-Virus.Hoax.Win32.Renos.al : Cleaned with backup
C:\Documents and Settings\suhail\Local Settings\Temporary Internet Files\Content.IE5\XZVZT5WU\start[1].exe -> Downloader.WinShow.bi : Cleaned with backup
C:\Games\Act of War\ACTOFWAR.EXE -> Heuristic.Win32.Backdoor.IrcBot : Cleaned with backup
C:\My Downloads\Half-Life 2 Keygen (Steam)(1).rar/keygen.exe -> Trojan.Pakes : Cleaned with backup
C:\ntnc.exe -> Not-A-Virus.Hoax.Win32.Renos.al : Cleaned with backup
C:\ntpnt.exe -> Downloader.VB.vc : Cleaned with backup
C:\WINDOWS\addcc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addlx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apinp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apioq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appae.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appak.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appaq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appls.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\applz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appon32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apppk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appps32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apprx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appsz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appte32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvz.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\appzk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlak32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlaq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlii32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlkf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlli32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlnr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlrw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlte.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\craf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crau32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crbk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crfl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crhy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\criw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crsx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crwf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crwt.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\d3bu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3mw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3tt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3xa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieaa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieie.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ielm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ienz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieor32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipab32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipil.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipou.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\ipow.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iprj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipys.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaan32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javana32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javanu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javasj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javavn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcit.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcnv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcoo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcyc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mscu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msyp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszp.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\neten.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netis.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netrz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netud.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netvk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntak.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntih.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntin.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\ntkl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntza32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\quabf.dat:mwwku -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\sdkae.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkcj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysar32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysbk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysed.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syshn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysky.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysrl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addah32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addbf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apify.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apigq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiox32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apivg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apivm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apixq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appii.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\system32\applm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apprs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appui32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlfh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlgj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atllc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlnl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlno.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlog.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpn.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\system32\atlqq.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\system32\atlws.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crcm.exe -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\system32\crde.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cres.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crlk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crpk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crqr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cruw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3as.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ev32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3kv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3nf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3og.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3oj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3qv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3sn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3wx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iecf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iecu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieks32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ielg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iemd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ienj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieoz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iexf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieyu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\intxt.exe -> Adware.CashD
First of all, I want you to download and install another browser, because for the moment I strongly suggest NOT to use Internet Explorer, because everytime you open it, new malware is getting downloaded.
So, I want you to use Firefox instead to browse the web.
When your system is clean again, you can use your IE again.
Here you can find firefox to download: http://www.mozilla.org/products/firefox/
°Download AboutBuster.
http://www.malwarebytes.org/AboutBuster.zip
Unzip AboutBuster in an own folder such as C:\AboutBuster.
Start AboutBuster.exe. Click OK, Update, Check For Update and download the updates if present.
Close aboutbuster now, because you may not run it yet, that's for later.
If You are getting an error when updating, please let me know first before you proceed with the next steps.
* Download and install CCleaner
http://www.ccleaner.com/
Do not use it yet.
* Download CWShredder. Don't let it run yet!
http://cwshredder.net/bin/CWShredder.exe
* Download this regfix: HSfix
http://users.pandora.be/marcvn/tools/HSfix.zip
Unzip it and place it on your desktop, don't use it yet!
* We will also be running another Ewido Scan. Do NOT run a scan yet.
°First, we will make your hidden files and folders visible.
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Uncheck the Hide file extensions for known file types.
* Click Yes to confirm.
* Click OK.
open notepad and copy and paste next bold in it:
(do not forget to copy and paste REGEDIT4 in it!)
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
Save this as fix.reg , choose to save as *all files and place it on your desktop.
*Please reboot your system into SAFE MODE.
°To get into the Windows XP Safe mode as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.
Doubleclick on fix.reg you made before and when it asks you if you want to add the contents to the registry, click yes/ok
*Start hijackthis and click scan and put a checkmark next to the following items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R3 - Default URLSearchHook is missing
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
*Close all open windows except hijackthis and click 'Fix Checked'.
*Start Aboutbuster and let it scan. When the scan is done and you choose exit, it will automatically create a log in the same folder where aboutbuster is in.
*Start Cwshredder and click FIX
* Doubleclick on HSfix you downloaded earlier before which is present on your desktop and when it asks you if you want to add the contents to the registry, click yes/ok
* Still in safe mode Run Ccleaner and click Run Cleaner (bottom right)
* Now open ewido anti-malware 3.5
* click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.
Close Ewido
*Go to start>Control Panel>Internet Options>tab programs> and click restore websettings.
* Reboot your PC back to normal.
*Post a new hijackthis-log + log from ewido and log from aboutbuster which you'll find in the aboutbuster-folder
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\yifec.dll/sp.html#88449%
R3 - Default URLSearchHook is missing
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
THIS IS WHAT I GOT WHEN I RAN HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 5:46:44 PM, on 1/19/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {263D8EC6-3994-13AE-F18C-F072FE879294} - C:\WINDOWS\system32\ntdw32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
I want you to unplug your internet connection, then run another Ewido scan.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.
Plug connection back in.
Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
ewido anti-malware - Scan report
———————————————————
+ Created on: 11:33:33 PM, 1/19/2006
+ Report-Checksum: 5FC30B10
+ Scan result:
No infected objects found.
::Report End
HIJACKTHIS REPORT:
Logfile of HijackThis v1.99.1
Scan saved at 11:37:02 PM, on 1/19/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\WINDOWS\System32\shell386.exe
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {263D8EC6-3994-13AE-F18C-F072FE879294} - C:\WINDOWS\system32\ntdw32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
By the way I did Ewido scan twice. Once before I went to safe mode and once after. That is why it shows nothing.
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !. Don't Run it yet.
I suggest you do this:
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {263D8EC6-3994-13AE-F18C-F072FE879294} - C:\WINDOWS\system32\ntdw32.dll (file missing)
O2 - BHO: winapi32.MyBHO - {7A533235-A128-434B-9F8A-9300A544D191} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Class - {DCA3E944-414A-C209-B901-462873898794} - C:\WINDOWS\system32\sysjp.dll (file missing)
O4 - HKLM\..\Run: [5.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\5.tmp.exe
O4 - HKLM\..\Run: [19.tmp.exe] C:\DOCUME~1\suhail\LOCALS~1\Temp\19.tmp.exe
O4 - HKLM\..\Run: [sdket.exe] C:\WINDOWS\sdket.exe
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\crfq32.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKLM\..\Run: [apint.exe] C:\WINDOWS\system32\apint.exe
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\System32\sfg.dll"
Close ALL windows and browsers except HijackThis and click "Fix checked"
Now double-click on the killbox.exe program.
Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.
Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.
When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.
C:\WINDOWS\sdket.exe
C:\WINDOWS\system32\d3bc.exe
C:\WINDOWS\System32\xxxdialer.exe
C:\WINDOWS\crfq32.exe
C:\WINDOWS\System32\sfg.dll
C:\WINDOWS\System32\popups.exe
C:\WINDOWS\System32\keylogger32.exe
C:\WINDOWS\System32\porntrojan.exe
C:\WINDOWS\system32\apint.exe
C:\Program Files\RazeSpyware\RazeSpyware.exe
C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
Return to Killbox, go to the File menu and select Paste from Clipboard.
Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually
After Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Scan saved at 12:18:33 AM, on 1/21/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\notepad.exe
C:\WINDOWS\System32\shell386.exe
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {A313F723-15E1-42D7-9E62-A40F345CD1C6} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
My pc behaves better now i guess. However i keep on getting these pop-ups from EWIDO, finding malware all the time.I am running EWIDO as realtime protection.I am also getting this pop-up:
Warning!Virus Infection(porntrojan.exe)
C:\windows\system32\porntrojan.exe
hkey_local_machine\software\microsoft\windows\currentversion\run\w.porntrojan
when I close it, razespyware appears again.
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL
Click "Start"> "Run"> type in Regedit tap Enter Key
Make sure "My Computer" is highlighted
Click "Edit"> "Find"
Type in w.porntrojan tap Enter Key.
Right Click on the file and select "Delete"
Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.
Close Regedit.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
O4 - HKLM\..\Run: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
Close ALL windows and browsers except HijackThis and click "Fix checked"
Then double-click on the killbox.exe program.
Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.
Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.
When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.
C:\WINDOWS\system32\d3bc.exe
C:\WINDOWS\System32\popups.exe
C:\windows\system32\porntrojan.exe
Return to Killbox, go to the File menu and select Paste from Clipboard.
Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually
"copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Scan saved at 3:46:00 PM, on 1/21/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\shell386.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {A313F723-15E1-42D7-9E62-A40F345CD1C6} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
I am still getting:
1. Warning!Virus infection (xxxdialer.exe)
2. http://www.razespyware.net/?aff=160
And lots of "Infected object found!" in Ewido.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
O2 - BHO: winapi32.MyBHO - {A313F723-15E1-42D7-9E62-A40F345CD1C6} - C:\WINDOWS\System32\winapi32.dll
O4 - HKLM\..\Run: [X.32 Keylogger] C:\WINDOWS\System32\keylogger32.exe
O4 - HKLM\..\Run: [W.PornTrojan] C:\WINDOWS\System32\porntrojan.exe
Close ALL windows and browsers except HijackThis and click "Fix checked"
Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.
Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.
When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.
C:\WINDOWS\System32\shell386.exe
C:\WINDOWS\System32\keylogger32.exe
C:\WINDOWS\System32\porntrojan.exe
Return to Killbox, go to the File menu and select Paste from Clipboard.
Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually
Restart your computer.
"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Scan saved at 12:41:33 AM, on 1/23/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe
C:\Program Files\RazeSpyware\RazeSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\shell386.exe
C:\Documents and Settings\suhail\Desktop\hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {A313F723-15E1-42D7-9E62-A40F345CD1C6} - C:\WINDOWS\System32\winapi32.dll
O2 - BHO: Popup Blocker Pro - {A44B961C-8C36-470f-8555-EDA0EFC1E710} - C:\Program Files\SafeGuard Pop-up Blocker Pro FREE Edition\popupblocker.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RAMDrive] "C:\Program Files\FarStone\GameDrive\VHD\RDTask.exe"
O4 - HKLM\..\Run: [Universal Porn Dialer] C:\WINDOWS\System32\xxxdialer.exe
O4 - HKLM\..\Run: [Popup Maker] C:\WINDOWS\System32\popups.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [RazeSpyware] C:\Program Files\RazeSpyware\RazeSpyware.exe
O4 - HKCU\..\Run: [RazeSpyware Monitor] C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe" service (file missing)
Ok now it is even worse. Not only Razespyware pop-ups, but it intalls itself to my pc and runs a scan no matter how many times I un-install it.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI