This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

results from - please help me get rid of these virus's

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 12:17:41 AM, on 2/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rcbl\elthk.exe
C:\WINDOWS\system32\eioj\cgfajyg.exe
C:\WINDOWS\system32\rcbl\elthk.exe
C:\WINDOWS\system32\xrarkf\glnbghvf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rwbvkxyl\hpuvcv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\system32\jbabs\fxnxh.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Trend Micro\Antivirus\PCCGUIDE.EXE
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [swbrwc] C:\WINDOWS\system32\rotys\swbrwc.exe
O4 - HKLM\..\Run: [qmvmgh] C:\WINDOWS\system32\bvpsoth\qmvmgh.exe
O4 - HKLM\..\Run: [snrhewhu] C:\WINDOWS\system32\wmrfn\snrhewhu.exe
O4 - HKLM\..\Run: [quqqa] C:\WINDOWS\system32\isshyfxg\quqqa.exe
O4 - HKLM\..\Run: [bhod] C:\WINDOWS\system32\fgrv\bhod.exe
O4 - HKLM\..\Run: [vyqpbdmi] C:\WINDOWS\system32\gyuxclfm\vyqpbdmi.exe
O4 - HKLM\..\Run: [tvrbpvd] C:\WINDOWS\system32\qwasf\tvrbpvd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [cgfajyg] C:\WINDOWS\system32\eioj\cgfajyg.exe
O4 - HKLM\..\Run: [elthk] C:\WINDOWS\system32\rcbl\elthk.exe
O4 - HKLM\..\Run: [srwnsucs] C:\WINDOWS\system32\etudypfm\srwnsucs.exe
O4 - HKLM\..\Run: [hpuvcv] C:\WINDOWS\system32\rwbvkxyl\hpuvcv.exe
O4 - HKLM\..\Run: [glnbghvf] C:\WINDOWS\system32\xrarkf\glnbghvf.exe
O4 - HKLM\..\Run: [fxnxh] C:\WINDOWS\system32\jbabs\fxnxh.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by4fd.bay4.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: bhodfgrv - Unknown owner - C:\WINDOWS\system32\fgrv\bhod.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: fxnxhjbabs - Unknown owner - C:\WINDOWS\system32\jbabs\fxnxh.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello TomDiF, Welcome to the forum.

This is what I suggest you do.


Please do not delete anything unless instructed to.


Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.

Next:

Please download the trial version of ewido anti-malware 3.5 here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Logfile of HijackThis v1.99.1
Scan saved at 1:28:10 PM, on 2/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\gcqc\xaoyu.exe
C:\WINDOWS\system32\namkeqv\oedjac.exe
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\main\APPLIC~1\RACLE~1\dexplore.exe
C:\Program Files\??pPatch\s?ool32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\evpw\rwsnw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: (no name) - {B4AC2F63-B5D6-C359-F7DD-E0CB59EB5C96} - C:\WINDOWS\system32\vsqk.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {B4AC2F63-B5D6-C359-F7DD-E0CB59EB5C96} - C:\WINDOWS\system32\vsqk.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [swbrwc] C:\WINDOWS\system32\rotys\swbrwc.exe
O4 - HKLM\..\Run: [qmvmgh] C:\WINDOWS\system32\bvpsoth\qmvmgh.exe
O4 - HKLM\..\Run: [snrhewhu] C:\WINDOWS\system32\wmrfn\snrhewhu.exe
O4 - HKLM\..\Run: [bhod] C:\WINDOWS\system32\fgrv\bhod.exe
O4 - HKLM\..\Run: [vyqpbdmi] C:\WINDOWS\system32\gyuxclfm\vyqpbdmi.exe
O4 - HKLM\..\Run: [tvrbpvd] C:\WINDOWS\system32\qwasf\tvrbpvd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [cgfajyg] C:\WINDOWS\system32\eioj\cgfajyg.exe
O4 - HKLM\..\Run: [elthk] C:\WINDOWS\system32\rcbl\elthk.exe
O4 - HKLM\..\Run: [srwnsucs] C:\WINDOWS\system32\etudypfm\srwnsucs.exe
O4 - HKLM\..\Run: [hpuvcv] C:\WINDOWS\system32\rwbvkxyl\hpuvcv.exe
O4 - HKLM\..\Run: [fxnxh] C:\WINDOWS\system32\jbabs\fxnxh.exe
O4 - HKLM\..\Run: [oedjac] C:\WINDOWS\system32\namkeqv\oedjac.exe
O4 - HKLM\..\Run: [cryyey] C:\WINDOWS\system32\gmcqaww\cryyey.exe
O4 - HKLM\..\Run: [cmvcej] C:\WINDOWS\system32\blcfj\cmvcej.exe
O4 - HKLM\..\Run: [rwsnw] C:\WINDOWS\system32\evpw\rwsnw.exe
O4 - HKLM\..\Run: [wcxtxlre] C:\WINDOWS\system32\yowapa\wcxtxlre.exe
O4 - HKLM\..\Run: [ufkpdrv] C:\WINDOWS\system32\atymda\ufkpdrv.exe
O4 - HKLM\..\Run: [xaoyu] C:\WINDOWS\system32\gcqc\xaoyu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [Amot] "C:\DOCUME~1\main\APPLIC~1\RACLE~1\dexplore.exe" -vt yazr
O4 - HKCU\..\Run: [Xuixsb] C:\Program Files\??pPatch\s?ool32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by4fd.bay4.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: bhodfgrv - Unknown owner - C:\WINDOWS\system32\fgrv\bhod.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: fxnxhjbabs - Unknown owner - C:\WINDOWS\system32\jbabs\fxnxh.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: rwsnwevpw - Unknown owner - C:\WINDOWS\system32\evpw\rwsnw.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 1:23:33 PM, 2/20/2006
+ Report-Checksum: 9FE8D8CA

+ Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Adware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetOffers -> Adware.LZIO : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0AD937E7-2F37-4873-A05E-548A67EF1D0E} -> Adware.FlashEnhancer : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11A4CA8C-A8B9-49C2-A6D3-3F64C9EEBAE6} -> Adware.Shorty : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E588AB-A5D9-4422-B313-22A3470F9700} -> Adware.FlashEnhancer : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFF4E223-7019-4CE7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-1574323382-1815002781-3652652152-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup
HKU\S-1-5-21-1574323382-1815002781-3652652152-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0AD937E7-2F37-4873-A05E-548A67EF1D0E} -> Adware.FlashEnhancer : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11A4CA8C-A8B9-49C2-A6D3-3F64C9EEBAE6} -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7E588AB-A5D9-4422-B313-22A3470F9700} -> Adware.FlashEnhancer : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFF4E223-7019-4CE7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\main\a.exe/mc-58-12-0000137.exe -> Adware.Maxifiles : Cleaned with backup
:mozilla.8:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.35:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.36:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.37:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.38:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.39:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.55:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.57:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.58:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.59:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.60:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.64:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.72:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.80:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.127:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.129:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.147:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.155:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.156:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.157:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.158:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.163:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.164:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.166:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.167:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.168:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.187:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.188:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.189:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.190:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.191:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.192:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.193:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.194:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.195:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.196:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.197:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.198:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.208:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.209:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.210:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.212:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.220:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.221:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.222:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.223:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.224:C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.32:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.34:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.41:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.43:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.51:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.53:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.54:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.55:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.56:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.64:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.65:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.66:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.73:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.76:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.78:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.86:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.88:C:\Documents and Settings\main\Application Data\Netscape\NSB\Profiles\gitb56jg.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\main\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup
C:\Documents and Settings\main\Local Settings\TEMP\13.tmp -> Downloader.Agent.lg : Cleaned with backup
C:\Documents and Settings\main\Local Settings\TEMP\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Program Files\BearShare\Installer\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\BearShare\Installer\saveinstwm.exe/VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Ftk\ftk.dll -> Adware.FlashEnhancer : Cleaned with backup
C:\Program Files\Yazzle Sudoku\Sudoku.exe -> Dropper.VB.kk : Cleaned with backup
C:\System Volume Information\_restore{10079EF7-9BEA-4908-92B4-0EDBB2391CF2}\RP114\A0016078.exe -> Dropper.VB.kk : Cleaned with backup
C:\System Volume Information\_restore{10079EF7-9BEA-4908-92B4-0EDBB2391CF2}\RP116\A0016357.exe -> Adware.BrilliantDigital : Cleaned with backup
C:\WINDOWS\system32\ariqaro\xdwnmgrn.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\auaonf\aynaxgoo.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\bngkfyhd.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\bnugl.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\BO2809040510.exe -> Adware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\system32\bsdg.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\cegh\exmwmd.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\cinmnpl.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\danfxsdr\xtbodhu.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\ddichos\1E.tmp -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\dun.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\etcgwr.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\fluc\thbjqjuh.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\hfnjjl\qglmtx.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\hliknm\qtwfq.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\ioave.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\isshyfxg\quqqa.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\jbfp\aadjo.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\jenjm.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\jfgign\klyt.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\jocyjsw\ywvr.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\kastqwem\fxyylro.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\lgaqhy\ontwsx.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\mema.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\oeeg.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\oklamto\trwyapn.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\pdbfjlo.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\prmw.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\qyieu\xdrf.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\sasrowc.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\seoht.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\smoypsn\xnqdi.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\spfs.exe -> Adware.EZula : Cleaned with backup
C:\WINDOWS\system32\SplWbr.dll -> Adware.VirtualBouncer : Cleaned with backup
C:\WINDOWS\system32\ubgqhf.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\xrarkf\glnbghvf.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\xxpxfk.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\xyev\grobkk.exe -> Downloader.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\yrvn.exe -> Adware.DealHelper : Cleaned with backup


::Report End
When replying: Please use the [external image: Posted Image] Button to reply. Thanks


You need To disable TeaTimer, until clean.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts

I suggest you do this:




Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: (no name) - {B4AC2F63-B5D6-C359-F7DD-E0CB59EB5C96} - C:\WINDOWS\system32\vsqk.dll

O2 - BHO: (no name) - {B4AC2F63-B5D6-C359-F7DD-E0CB59EB5C96} - C:\WINDOWS\system32\vsqk.dll

O4 - HKLM\..\Run: [swbrwc] C:\WINDOWS\system32\rotys\swbrwc.exe
O4 - HKLM\..\Run: [qmvmgh] C:\WINDOWS\system32\bvpsoth\qmvmgh.exe
O4 - HKLM\..\Run: [snrhewhu] C:\WINDOWS\system32\wmrfn\snrhewhu.exe
O4 - HKLM\..\Run: [bhod] C:\WINDOWS\system32\fgrv\bhod.exe
O4 - HKLM\..\Run: [vyqpbdmi] C:\WINDOWS\system32\gyuxclfm\vyqpbdmi.exe
O4 - HKLM\..\Run: [tvrbpvd] C:\WINDOWS\system32\qwasf\tvrbpvd.exe
O4 - HKLM\..\Run: [cgfajyg] C:\WINDOWS\system32\eioj\cgfajyg.exe
O4 - HKLM\..\Run: [elthk] C:\WINDOWS\system32\rcbl\elthk.exe
O4 - HKLM\..\Run: [srwnsucs] C:\WINDOWS\system32\etudypfm\srwnsucs.exe
O4 - HKLM\..\Run: [hpuvcv] C:\WINDOWS\system32\rwbvkxyl\hpuvcv.exe
O4 - HKLM\..\Run: [fxnxh] C:\WINDOWS\system32\jbabs\fxnxh.exe
O4 - HKLM\..\Run: [oedjac] C:\WINDOWS\system32\namkeqv\oedjac.exe
O4 - HKLM\..\Run: [cryyey] C:\WINDOWS\system32\gmcqaww\cryyey.exe
O4 - HKLM\..\Run: [cmvcej] C:\WINDOWS\system32\blcfj\cmvcej.exe
O4 - HKLM\..\Run: [rwsnw] C:\WINDOWS\system32\evpw\rwsnw.exe
O4 - HKLM\..\Run: [wcxtxlre] C:\WINDOWS\system32\yowapa\wcxtxlre.exe
O4 - HKLM\..\Run: [ufkpdrv] C:\WINDOWS\system32\atymda\ufkpdrv.exe
O4 - HKLM\..\Run: [xaoyu] C:\WINDOWS\system32\gcqc\xaoyu.exe
O4 - HKCU\..\Run: [Amot] "C:\DOCUME~1\main\APPLIC~1\RACLE~1\dexplore.exe" -vt yazr
O4 - HKCU\..\Run: [Xuixsb] C:\Program Files\??pPatch\s?ool32.exe

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll

O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200203…meInstaller.exe

O23 - Service: fxnxhjbabs - Unknown owner - C:\WINDOWS\system32\jbabs\fxnxh.exe
O23 - Service: rwsnwevpw - Unknown owner - C:\WINDOWS\system32\evpw\rwsnw.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"




Download Pocket Killbox version 2.0.0.175
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Then double-click on the killbox.exe program.


Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.

Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.


When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.

C:\WINDOWS\system32\vsqk.dll
C:\WINDOWS\system32\rotys\swbrwc.exe
C:\WINDOWS\system32\bvpsoth\qmvmgh.exe
C:\WINDOWS\system32\wmrfn\snrhewhu.exe
C:\WINDOWS\system32\fgrv\bhod.exe
C:\WINDOWS\system32\gyuxclfm\vyqpbdmi.exe
C:\WINDOWS\system32\qwasf\tvrbpvd.exe
C:\WINDOWS\system32\eioj\cgfajyg.exe
C:\WINDOWS\system32\rcbl\elthk.exe
C:\WINDOWS\system32\etudypfm\srwnsucs.exe
C:\WINDOWS\system32\rwbvkxyl\hpuvcv.exe
C:\WINDOWS\system32\jbabs\fxnxh.exe
C:\WINDOWS\system32\namkeqv\oedjac.exe
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\blcfj\cmvcej.exe
C:\WINDOWS\system32\evpw\rwsnw.exe
C:\WINDOWS\system32\yowapa\wcxtxlre.exe
C:\WINDOWS\system32\atymda\ufkpdrv.exe
C:\WINDOWS\system32\gcqc\xaoyu.exe
C:\DOCUME~1\main\APPLIC~1\RACLE~1\dexplore.exe" -vt yazr
C:\Program Files\??pPatch\s?ool32.exe
C:\WINDOWS\system32\jbabs\fxnxh.exe
C:\WINDOWS\system32\evpw\rwsnw.exe


Return to Killbox, go to the File menu and select Paste from Clipboard.


Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 3:32:46 PM, on 2/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\1117033789\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\1117033789\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0b\waol.exe
c:\program files\common files\aol\1117033789\ee\aolssc.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\evpw\rwsnw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {0
6849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1117033789\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1117033789\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [cryyey] C:\WINDOWS\system32\gmcqaww\cryyey.exe
O4 - HKLM\..\Run: [rwsnw] C:\WINDOWS\system32\evpw\rwsnw.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by4fd.bay4.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: bhodfgrv - Unknown owner - C:\WINDOWS\system32\fgrv\bhod.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: rwsnwevpw - Unknown owner - C:\WINDOWS\system32\evpw\rwsnw.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Go to Start > Run and type in Services.msc then click OK

Click the Extended tab.

Scroll down until you find bhodfgrv

Click once on the service to highlight it.

Click Stop

Right-Click on the service.

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The service is now stopped and disabled.

Repeat the above for this one also:
rwsnwevpw




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [cryyey] C:\WINDOWS\system32\gmcqaww\cryyey.exe
O4 - HKLM\..\Run: [rwsnw] C:\WINDOWS\system32\evpw\rwsnw.exe
O23 - Service: bhodfgrv - Unknown owner - C:\WINDOWS\system32\fgrv\bhod.exe
O23 - Service: rwsnwevpw - Unknown owner - C:\WINDOWS\system32\evpw\rwsnw.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"

Click Start-> Run and type cmd in the Open: line. Click OK.
* Type or paste in the following in bold: sc delete bhodfgrv
* Hit Enter
* Type: Exit
* Hit Enter


Click Start-> Run and type cmd in the Open: line. Click OK.
* Type or paste in the following in bold: sc delete rwsnwevpw
* Hit Enter
* Type: Exit
* Hit Enter



Delete these Files if listed:
C:\WINDOWS\system32\gmcqaww\cryyey.exe
C:\WINDOWS\system32\evpw\rwsnw.exe
C:\WINDOWS\system32\fgrv\bhod.exe


Delete these folders if listed:
C:\WINDOWS\system32\gmcqaww
C:\WINDOWS\system32\evpw
C:\WINDOWS\system32\fgrv



Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 10:56:41 PM, on 2/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\1117033789\ee\AOLSoftware.exe
C:\Program Files\Common Files\AOL\1117033789\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\HJT\HijackThis.exe
c:\program files\common files\aol\1117033789\ee\aolssc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\main\Application Data\Mozilla\Profiles\default\y6fnwbn6.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1117033789\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1117033789\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .xml: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by4fd.bay4.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - http://updates.lifescapeinc.com/installers…ll/pinstall.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1117033789\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Antivirus\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

computer was very slow when booting back up… seemed to take a really long time
i forgot to mention, i could not perform this: Click Start-> Run and type cmd in the Open: line. Click OK. * Type or paste in the following in bold: sc delete bhodfgrv * Hit Enter * Type: Exit * Hit Enter Click Start-> Run and type cmd in the Open: line. Click OK. * Type or paste in the following in bold: sc delete rwsnwevpw * Hit Enter * Type: Exit * Hit Enter when i tried to run cmd, a black screen would flash on the screen and then disappear
You can use Add/Remove Programs and remove: ewido security suite, it's only a 14 day trial version.

After that reboot and tell me how it's running.
ok, removed Ewido Security Suite but i still can't remove those files by running CMD when i try to run CMD, it just flashes on the screen still and then disappears and the computer still boots up slow this is what u wanted me to do but still can't try because CMD won't work: Click Start-> Run and type cmd in the Open: line. Click OK. * Type or paste in the following in bold: sc delete bhodfgrv * Hit Enter * Type: Exit * Hit Enter Click Start-> Run and type cmd in the Open: line. Click OK. * Type or paste in the following in bold: sc delete rwsnwevpw * Hit Enter * Type: Exit * Hit Enter
Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
thanks for all the help… do you know of any reason my computer won't let me use the CMD? it still just flashes on the screen and then is gone when i type CMD in the run box

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI