This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

win32/winad.ak & Java.Shinwow removal

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey Guys,

I have two trojans on my computer and I'm pretty much a newbie to fixing these things. I have eTrust VET AnitVirus and it identifys the trojans but doesn't quarantine, remove or fix them. I have HiJackThis and have run it but I don't know what to look for and I figured just removing everything isn't the best idea. Here is the log file. If anyone could help me out it would be greatly appreciated:-)


Logfile of HijackThis v1.99.1
Scan saved at 11:46:26 AM, on 13/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\PC-TV\WinManager\WinManager.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAV.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\TagScanner\Tagscan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Q\My Documents\My Downloads\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.peopletelecom.com.au/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinManager.lnk = C:\Program Files\PC-TV\WinManager\WinManager.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
Hello Whatthe and Welcome to TomCoyote, :wavey:

I would like you to run some scans and post the results.

STEP 1.
======
Let’s check for Malware/Spyware on your computer which is best dealt with by spyware-removal programs used one after the other.
Spybot: Search and Destroy:
  • Download 'Spybot: Search And Destroy'.
  • Install it according to the instructions in 'How To Setup Spybot SD and Ad-Aware SE'.
  • Next, 'Search for Updates' as the definitions are not likely to be up-to-date.
  • Close ALL windows except Spybot SD
  • Click the "Check for Problems" button
  • Click 'Fix Selected Problems' and fix only the RED items.
  • REBOOT to finish removing what Spybot SD found and clear memory
Ad-Aware SE by Lavasoft:
  • Download 'Ad-Aware SE'.
  • Install according to the instructions in "How To Setup Spybot SD and Ad-Aware SE"
  • Next, 'Check for Updates' by clicking on the 'world globe' second from the right at the top of your Ad-Aware SE window.
  • Install the updates.
  • Close ALL windows except Ad-Aware SE
  • Click on 'Start' and choose 'full scan' for a full scan.
  • Quarantine anything that it finds and SAVE the log file.
  • REBOOT to finish removing what Ad-Aware SE found and clear memory.
Please let me know if anything can not be cleaned by these utilities.

STEP 2.
======
Ewido Trojan Scanner
Please download, install, and update the NEW free version of Ewido trojan scanner:
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. Select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
Scan again with HijackThis

Please POST
  • a New HijackThis log but DO NOT have hijackthis in a temporary folder. (C:\Documents and Settings\Q\My Documents\My Downloads\Temp\HijackThis.exe
    )
  • the results from the Ewido log
in this thread using 'Add Reply'.
Thank you Susan 528 for your help. I've done all you asked and here are the results of the Ewido Trojan Scan and Hijackthis Scan.

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 11:59:52 PM, 13/02/2006
+ Report-Checksum: 8391C14C

+ Scan result:

:mozilla.6:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\2bwqtyv2.Troy\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Xhit : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Itrack : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.230:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Q\Application Data\Mozilla\Firefox\Profiles\yb5jybvm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\webhdll.dll_tobedeleted -> Adware.WebHancer : Cleaned with backup


::Report End



Logfile of HijackThis v1.99.1
Scan saved at 12:01:09 AM, on 14/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC-TV\WinManager\WinManager.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.peopletelecom.com.au/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinManager.lnk = C:\Program Files\PC-TV\WinManager\WinManager.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe

Thanks Again your help is truly appreciated!
Hello Whatthe,

Does your antivirus still detect those trojans?

Open HijackThis. Place a check against each of the following:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

After you check these items, close all browsers and windows, except for HijackThis, then click on the Fix Checked button on HijackThis.

Reboot normally and scan with HijackThis. Post (reply) with a new hijackthis log to this thread.

If everything is fine, I will give you the final clean-up instructions in my next reply.
Hey Susan528,

I ran a scan with the Antivirus and it picked up the trjans again. So I then did as you said and ran a Hijackthis scan and the two items to be checked then fixed came up . I checked them, fixed them, them rebooted. I then did a scan again with Hijack this and here is the results.

Thank you!

Logfile of HijackThis v1.99.1
Scan saved at 9:44:05 AM, on 14/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.peopletelecom.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinManager.lnk = C:\Program Files\PC-TV\WinManager\WinManager.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
A2 Free

You will have to register name and email address but this is free too.
Download A2
and run. Post the results please.

Please let me know if your antivirus still detects the Trojans and please post the results and let me see what your antivirus is detecting.—name of Trojans and files, etc.
Hey Sandra528, I did the A2 scan and removed the issues it said I have rebooted then ran my anit virus and they came up again! Here is the A2 report. a-squared Report Scan started: 15/02/2006 12:23:25 PM Scan finished: 15/02/2006 12:38:46 PM Scan duration: 0h 15min 20sec Scanned files: 128180 Infected files: 8 Object Diagnosis Key: HKEY_CLASSES_ROOT\clsid\{147a976e-eee1-4377-8ea7-4716e4cdd239} Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\clsid\{147a976e-eee1-4377-8ea7-4716e4cdd239} Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin Trace.Registry.MyWebSearchToolbar The trojans are : Java/Shinwow.BA File C:\Documents and Settings\Q\Application Data\
Ignore Last Post Hey Sandra528, I did the A2 scan and removed the issues it said I have rebooted then ran my anit virus and they came up again! Here is the A2 report. a-squared Report Scan started: 15/02/2006 12:23:25 PM Scan finished: 15/02/2006 12:38:46 PM Scan duration: 0h 15min 20sec Scanned files: 128180 Infected files: 8 Object Diagnosis Key: HKEY_CLASSES_ROOT\clsid\{147a976e-eee1-4377-8ea7-4716e4cdd239} Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin Trace.Registry.MyWebSearchToobar Key: HKEY_CLASSES_ROOT\clsid\{147a976e-eee1-4377-8ea7-4716e4cdd239} Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.htmlpanel Trace.Registry.MyWebSearchToolbar Key: HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin Trace.Registry.MyWebSearchToolbar The trojans are : Java/Shinwow.BA File C:\Documents and Settings\Q\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-2b094b4d.zip Win32/WinAd.AK File C:\Documents and Settings\Q\Application Data\Thunderbird\Profiles\pwa4fl4z.default\Mail\Local Folders\Sent That's the lot. Thank you so much for your help Look forward to hearing from you soon! Whatthe
Hey Susan528, In case you didn't know your name isn't Sandra528 it's Susan528. Sorry about that mistake! My post before this has all the info you asked for. The one before that I somehow posted to early so ignore that one. Look forward to hearing from you. Thanks again! Whatthe
Oh yeah for your information the trojans have come up again since I posted what they were and where they where and the locations have changed. Cheeky little buggers. Whatthe
Hello Whatthe,

I am trying to find out some information about those registry entries. I have not forgotten about you.
==========================================
To delete the infected cache files
===================================
Your scan showed one of more viruses in your Sun Java Runtime Environment (JRE) cache. Delete those by clearing the JRE cache.
To clear the Java Runtime Environment (JRE) cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
    -The Java Control Panel appears.
  • Click Settings under Temporary Internet Files.
    -The Temporary Files Settings dialog box appears.
  • Click Delete Files.
    -The Delete Temporary Files dialog box appears.
    -There are three options on this window to clear the cache.
    • Delete Files
    • View Applications
    • View Applets
  • Click OK on Delete Temporary Files window.
    -Note: This deletes all the Downloaded Applications and Applets from the cache.
  • Click OK on Temporary Files Settings window.
  • Close the Java Control Panel
You can view those instructions along with graphics Here

Also when we are done Update your Java updated to the latest version. Uninstall any and all versions you have listed in add/remove programs and install the latest version from here: http://www.java.com/en/
=========================================

File C:\Documents and Settings\Q\Application Data\Thunderbird\Profiles\pwa4fl4z.default\Mail\Local Folders\Sent

I am not sure about what is infected here? Is there a file named AnyDVD 5.4.1.1 crack/crack.exe in the Local Folders\Sent ?

The file is in your Thunderbird Sent folder. Open Thunderbird. You may need to go to the File menu in the upper left-hand corner and do “Compact Folders” and then delete the file in your Sent folder.

See if this gets rid of the two infected files. I am checking on the registry entries.
Hey Susan528, I did the two things you asked me to and I then scanned my computer with the Antivirus Software. It didn't pick up the trojans this time and appeared to be clean. What do I do next? Does that mean everything is alright now? Is there anything else I should do? Thanks again Whatthe
Hey Susan528,

Here is my latest Hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 2:56:43 PM, on 20/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
C:\Program Files\Raxco\PerfectDisk\PDSched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\PC-TV\WinManager\WinManager.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\PROGRA~1\MEDIAM~1\MEDIAM~2.EXE
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.peopletelecom.com.au/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.peopletelecom.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Vet Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_5 -reboot 1
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinManager.lnk = C:\Program Files\PC-TV\WinManager\WinManager.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe

Thanks Again

Whatthe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI