This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run ad-aware but i am still exeriencing tons of popups. Please review my log. thank you
Logfile of HijackThis v1.99.1
Scan saved at 7:17:35 PM, on 1/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\pvzymkv.exe
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\system32\PROMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\PhoneTools\CapFax.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Handspring\HOTSYNC.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINNT\enhtb.dll (file missing)
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINNT\dsr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\winnt\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\googletoolbar2.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Opware12] "C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [satmat] C:\WINNT\satmat.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINNT\enhupdt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [neficw] C:\WINNT\system32\pvzymkv.exe r
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\winnt\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\winnt\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\winnt\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\winnt\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\winnt\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\winnt\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130864383104
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINNT\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello and welcome to TomCoyote forum. Sorry for the wait, the volunteers are overwhelmed with requests for help. You have a nasty infection sometimes called Aurora/Nail. There is a class action against the folks causing this you may be able to get involved with. Here is the information: http://www.spywarewarrior.com/viewtopic.php?t=12155

It is going to take some time and work to clean your system, you can do it if you will follow the directions. This fix removes much of the infection and several trojans so that is very important. I must also say because this junk acts like a magnet to attract other junk it would be best if you stay offline as much as possible until you are clean.

Thanks to Swandog46 and any others who helped with this fix.

BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

First, download Ewido Security Suite.

Next, download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in. Install Ad-Aware using the default options, then install vx2cleaner_inst.exe, taking all the defaults there as well.

Run Ad-Aware, update to the latest definitions, then click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.

Reboot your PC and run Ad-Aware again. This time, click on the Start button in Ad-Aware, select "Perform smart system scan" and click Next. Once the scan finishes, click "Next" again. Select all objects found (right click anywhere in the list of found objects and click "Select All Objects"). Click "Next" one more time, then "OK" to confirm the removal.

You will be prompted to set Ad-Aware to run on reboot, click "OK". Exit Ad-Aware and restart your PC once again.

When Ad-Aware starts up, click on "Start", then "Next". Follow the steps above if anything is found, or click "Finish", then exit Ad-Aware.

For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.

There will be more to do

Thanks…pskelley
TomCoyote forum
Expert Member
pskelley-
Thank you so much for you help so far. Below are my logs for Hijackthis and ewido:

Logfile of HijackThis v1.99.1
Scan saved at 9:30:03 AM, on 2/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\system32\PROMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\PhoneTools\CapFax.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Handspring\HOTSYNC.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\winnt\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\googletoolbar2.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Opware12] "C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [satmat] C:\WINNT\satmat.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINNT\enhupdt.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\winnt\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\winnt\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\winnt\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\winnt\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\winnt\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\winnt\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130864383104
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

ewido anti-malware - Scan report
———————————————————

+ Created on: 9:24:07 AM, 2/5/2006
+ Report-Checksum: 9574D671

+ Scan result:

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
HKU\S-1-5-21-3064936989-4126663118-2490122174-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-3064936989-4126663118-2490122174-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000020DD-C72E-4113-AF77-DD56626C6C42} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-3064936989-4126663118-2490122174-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-3064936989-4126663118-2490122174-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-3064936989-4126663118-2490122174-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\asmfiles.cab/asm.exe -> Spyware.Altnet : Error during cleaning
C:\Documents and Settings\Owner\Local Settings\Temp\tt_reco.exe -> Dropper.Agent.ch : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\Program Files\PerfectNav -> Adware.PerfectNav : Cleaned with backup
C:\Program Files\PerfectNav\BHO -> Adware.PerfectNav : Cleaned with backup
C:\Program Files\Save -> Spyware.SaveNow : Cleaned with backup
C:\Program Files\Save\ReadMe.txt -> Spyware.SaveNow : Cleaned with backup
C:\Program Files\Save\save.db -> Spyware.SaveNow : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1130\A0091481.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1130\A0091482.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1133\A0091508.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1133\A0091509.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1133\A0091518.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1141\A0091711.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1141\A0091712.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1141\A0091714.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1141\A0091715.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1142\A0091733.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1143\A0091739.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1143\A0092739.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1143\A0092743.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1143\A0092744.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1144\A0092836.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1144\A0092837.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1152\A0092870.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1152\A0092871.exe -> Spyware.AdSquash : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1152\A0092877.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1152\A0092878.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1152\A0092883.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1154\A0093879.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1159\A0094084.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1159\A0094086.dll -> Spyware.ActivShopper : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1165\A0094143.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1165\A0094145.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1165\A0094146.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1166\A0094153.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1167\A0094197.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1168\A0094206.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1170\A0095187.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1170\A0095188.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1170\A0095189.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1173\A0095233.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1173\A0095234.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1174\A0095252.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1174\A0095253.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1174\A0095257.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1175\A0095279.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1176\A0095298.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1177\A0096252.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1177\A0097253.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1178\A0098253.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1178\A0098267.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1181\A0098288.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1182\A0098304.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1182\A0098307.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1183\A0098317.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1183\A0098318.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1185\A0098400.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1185\A0098401.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1186\A0098415.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1186\A0098426.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1188\A0099160.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1188\A0099161.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1188\A0099162.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1189\A0099196.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1189\A0099198.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1189\A0099205.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1189\A0099206.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1190\A0099237.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1191\A0099287.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1191\A0099288.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1192\A0099304.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1194\A0099342.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1194\A0099346.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1194\A0100283.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1195\A0100291.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1195\A0100292.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1198\A0100358.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1198\A0100359.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1198\A0100360.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1198\A0100361.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1200\A0100445.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1201\A0100467.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1201\A0100471.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1201\A0100478.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1201\A0100479.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1201\A0100480.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0101477.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0101478.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0101485.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0101486.dll -> Trojan.Agent.iw : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0102477.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1203\A0102478.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1204\A0102504.exe/run.exe -> Downloader.PassAlert.i : Error during cleaning
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1205\A0102507.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1205\A0102510.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1211\A0102626.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1211\A0102627.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1211\A0102628.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1212\A0102656.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1212\A0102659.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1213\A0103627.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1213\A0103628.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1213\A0103648.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP1213\A0103652.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@buycom.122.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@cornerstone.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@coxhsi.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\owner@dealnews.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\WINNT\system32\config\systemprofile\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned wit
Thanks for the new logs, I will look at the ewido log first:

ewido anti-malware - Scan report Created on: 9:24:07 AM, 2/5/2006

C:\Documents and Settings\Owner\Local Settings\Temp\asmfiles.cab/asm.exe -> Spyware.Altnet : Error during cleaning
This is the only one I see that failed, open that TEMP folder and delete everything in it (not the folder). Make sure you see this junk: asmfiles.cab/asm.exe get deleted. We may or have to run ewido again. If you should those cookies will be gone and I would appreciate it if you would edit out any System Restore items. We will clean SR before we are finished.

You are accumulating really nasty cookies, this information will help you stop that if you wish. I allow only cookies for passwords and secure sites. Takes a little work, like training a spam filter, but the requests to place cookies go away in time, your call.
http://www.mvps.org/winhelp2002/cookies.htm
http://www.microsoft.com/windows/ie/using/…acy/config.mspx

I also wish to say it looks like you cut off the ewido: 1].txt -> Spyware.Cookie.Esomniture : Cleaned wit <<< here, just make sure nothing was below that I should know about.

Logfile of HijackThis v1.99.1 Scan saved at 9:30:03 AM, on 2/5/2006

Let's clean a little more,

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll (file missing)
O4 - HKLM\..\Run: [satmat] C:\WINNT\satmat.exe
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINNT\enhupdt.exe
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\PROGRAM FILES~1\AWS\ >>> folder (if you must run AWS DL it again when we finish and make sure it is version 6.0 or above)

C:\Program Files\TBONAS\ >>> folder (if there)

C:\WINNT\enhupdt.exe >>> file

C:\WINNT\dinst.exe >>> file

C:\WINNT\satmat.exe >>> file

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

If you don't have a good cleaner, use this one with these instuctions:
Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

Restart the computer and post a new HJT log for a final check. I need feedback from you now on how it is performing. If all is well, just a few more final instructions and you will be good to go.

Thanks…Phil
Phil, I am unable to locate and delete the following files: C:\WINNT\enhupdt.exe C:\WINNT\dinst.exe C:\Windows\Prefect\ I have completed all of the steps up to this point. Thanks again!
OK, stick with me a bit longer. Make sure you have done this:

SHOW HIDDEN FILES: MANUAL INSTRUCTIONS
Double click my computers & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

This system was updated from another operating system, it is important that we find and delete this stuff, or it will cause you problems. Earlier when we checked them in HJT, the process manager stopped them from running so they could be deleted. If you have restarted your computer you will have to delete them in safe mode. Here are instructions for entering safe mode: http://www.bleepingcomputer.com/forums/tutorial61.html
It will look a little strange but what we need will work. When you know you have all files and folders enabled, then Open MyComputer > C:\ drive then locate the Windows folder. These files will be in alphabetical order:

These two may not be there but you must look carefully some times folders will be between rows of files.
It will probably be link this, and you are looking for the files in red.

C:\Windows\enhupdt.exe
C:\Windows\dinst.exe

Unless for some reason, and I doubt it, an upgrade to XP does not have a PREFETCH <<< look at the spelling, you misspelled it above, it has to be there. It will probably look like this: C:\Windows\Prefetch >> in red. I do not want the folder deleted, just the contents. Some bad stuff may be there, and delete it all. Windows will put back the good stuff it needs over a couple of reboots.

Then run a bit, tell me how it is running and post one last HJT log so I can make sure you are clean.

Thanks…Phil
phil, I am sorry but i am still stuck. I followed your new directions and i was able to delete the contents in the Prefetch file. I was NOT able to find c:\windows\enhupdt.exe or c:\windows\dinst.exe even in safe mode. You said that it looked like my system had been updated from another operating system but Windows XP was the original operation system on the computer when I bought it. Does this make a difference? Thank you so much for your help and patience.
No all is ok, usually when you see this: C:\WINNT\System32 it means windows was updated. Guess that is not true all of the time. I almost always see it in the logs like this: C:\Windows\System32\ but I don't see it as a problem. Good that you could clear Prefetch, there very likely there was junk running from there. Review the link I provided so you will know how Prefetch works. Then do this:

Then run a bit, tell me how it is running and post one last HJT log so I can make sure you are clean.

and soon I will have you on your way.

Thanks…Phil
Phil,
My system seems to be running quite well, my only concern is that it has always taken a long time to start up but I think it may be taking even longer now…I completed all of the steps and finished up by running ccleaner. Below is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 3:22:22 PM, on 2/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\system32\PROMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\PhoneTools\CapFax.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Handspring\HOTSYNC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: CCHelper Class - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Companion\CCHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\winnt\googletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\googletoolbar2.dll
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Opware12] "C:\Program Files\ScanSoft\OmniPagePro12.0\Opware12.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX6400] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE /P19 "EPSON Stylus CX6400" /O6 "USB001" /M "Stylus CX6400"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\winnt\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\winnt\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\winnt\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\winnt\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\winnt\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\winnt\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1130864383104
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Ok Ruby, remember I told you in the beginning this was going to be work and take time. Was I right :) pat yourself on the back :thumbup: The HJT log is clean of malware and you have done a grand job. Let's talk about a few things.

1) I gave you this link: http://www.windowsnetworking.com/articles_…refetch-XP.html so you can learn about it and how it works, plus bad stuff will try to run from there so it can't be seen. As I said, it will take a few reboots as windows puts back files that make the computer run quicker…hense the word…Prefetch.

2) Remember we are running a big program in the ewido "Security Suite" and it is using some resources an also slowing your down. You have the option to keep the scanner and update and use it for as long as you like, but unless you purchse the product it needs to be turned off now, or after the trial period because it is using resources and that will slow down the computer. I will post the instructions now for disabling it so it does not run and you can decide when to use them.
Disable a Service
Click Start < Run and type services.msc.
Scroll down to ewido security suite control and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled. Now it should not be running in the log and needs to be manually started if you use it.

3) Here are instructions for using MSConfig: http://netsquirrel.com/msconfig/ You are running a lot of programs at every boot that you can turn off to save resources. These links will identify those programs:
http://computercops.biz/StartupList.html
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm
http://www.pacs-portal.co.uk/startup_index.htm
http://www.sysinfo.org/startuplist.php
http://www.bleepingcomputer.com/startups/
Look at items in the log that start like this: O4 - HKLM\..\Run Turn them off one or two at a time.

4) Here are some ideas that may help with speed. Don't attempt anything that seems to difficult for you.
http://www.microsoft.com/windows/IE/commun…s/IEtopten.mspx
http://vlaurie.com/computers2/Articles/runbetter.htm
http://www.linkgrinder.com/tutorials/10_Ea…rs_article.html

5) Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

6) System Restore does not know good from bad, it backs up everything. In case some of the infection got into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, restart your computer and turn it back on.
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

7) I'll keep your topic open for a couple of days in case you have questions. Safe Surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI