This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

take some minutes to help this poor soul

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

could someone help me with this?
Thanks! :)

Logfile of HijackThis v1.99.1
Scan saved at 16:51:39, on 03/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
G:\softs\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WDpqclq] C:\WINDOWS\rliqrvb.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=051406 serial=DR12WUJ-5877021-YTR lang=EN
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - Startup: GlobespanVirata Dial-Up PPP Connection.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128539483764
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{286589F2-9036-46A1-A050-F2F3BF4A80A0}: NameServer = 192.115.106.35 62.219.186.7
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Hello and welcome to TomCoyote forum. Is this your location: http://www.whois.sc/62.219.186.7

You do have some issues, including a trojan I can not identify: C:\WINDOWS\rliqrvb.exe Please use one or more of these free online scanners and post the informaiton for me:
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html

Please follow these instruction in the posted order.

1) HJT must run from a drive to store backups for safety. You are running from G:\softs\HijackThis.exe and I do not know G:\ is a drive. Move HJT to here: C:\HJT\HijackThis.exe.


2) ewido scan:
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - HKLM\..\Run: [WDpqclq] C:\WINDOWS\rliqrvb.exe
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} -

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\rliqrvb.exe >>> file (be sure it is bad with the scanners first)

C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe >>> file

C:\Windows\Prefetch\ >>> delete the contents (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

If you don't have a good cleaner, use this one with these instuctions:
Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

Restart the computer and post the ewido scan report, a new HJT log and any feedback you think will help.

Thanks…pskelley
TomCoyote forum
Expert Member
first of all, I thank pskelley for his/her help. Thank you! this is my second post (the first is to be found: http://forums.tomcoyote.org/index.php?show…0&#entry264184)
I did everything according to pskelley, by I should note that I never found the ibm00005.exe anywhere. I guess that if I had to delete it and it wasn't there, it's all right.

HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 16:19:03, on 06/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=051406 serial=DR12WUJ-5877021-YTR lang=EN
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - Startup: GlobespanVirata Dial-Up PPP Connection.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128539483764
O17 - HKLM\System\CCS\Services\Tcpip\..\{286589F2-9036-46A1-A050-F2F3BF4A80A0}: NameServer = 192.115.106.35 62.219.186.7
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

———-X———-

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 15:43:05, 06/03/2006
+ Report-Checksum: 565A418F

+ Scan result:

C:\WINDOWS\osaupd.exe -> Not-A-Virus.Hoax.Win32.Renos.bq : Ignored
C:\WINDOWS\system32\shell386.exe -> Downloader.Small.cjy : Ignored
C:\WINDOWS\wupdmgr.exe -> Not-A-Virus.Hoax.Win32.Renos.bq : Ignored
HKU\S-1-5-21-448539723-920026266-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A19EF336-01D4-48E6-926A-FE7E1C747AED} -> Adware.MWSearch : Cleaned with backup
HKU\S-1-5-21-448539723-920026266-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4} -> Adware.MWSearch : Cleaned with backup
HKU\S-1-5-21-448539723-920026266-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F65B197F-8260-4D52-909A-F70118E646EB} -> Adware.MWSearch : Cleaned with backup
[1400] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Cleaned with backup
[1408] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[1828] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[1864] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[1944] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[1960] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[1980] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[168] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[188] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[216] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[240] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[2568] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[2628] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[2780] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[3456] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[4064] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
[3452] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Error during cleaning
:mozilla.9:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.38:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.40:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.53:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.54:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.55:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.56:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.62:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.63:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.68:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.75:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.82:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.88:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.92:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.93:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.106:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.112:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup
:mozilla.133:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.134:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.163:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned with backup
:mozilla.170:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Komtrack : Cleaned with backup
:mozilla.193:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.224:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.225:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.226:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.227:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.242:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.243:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.244:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.245:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.246:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.254:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.256:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.257:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.258:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.259:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.260:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.261:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.262:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.263:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.272:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.273:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.283:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.284:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.285:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.287:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.292:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.307:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup
:mozilla.364:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.399:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.400:C:\Documents and Settings\CasaComp\Application Data\Mozilla\Firefox\Profiles\v1bir9s5.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\CasaComp\Local Settings\Temp\Cookies\casacomp@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\CasaComp\Local Settings\Temp\Cookies\casacomp@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\CasaComp\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\CasaComp\Local Settings\Temp\uninstall.exe -> Adware.SurfAccuracy : Cleaned with backup
C:\Documents and Settings\CasaComp\Local Settings\Temp\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.dll -> Logger.Small.dg : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.dll -> Logger.Small.dg : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe -> Logger.Small.dg : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00006.dll -> Logger.Small.dg : Cleaned with backup
C:\Program Files\SideFind -> Adware.SideFind : Cleaned with backup
C:\Program Files\SideFind\update -> Adware.SideFind : Cleaned with backup
C:\WINDOWS\system32\azesearch4.ocx -> Adware.AzSearch : Cleaned with backup
C:\WINDOWS\system32\iasada.dll_tobedeleted -> Adware.AzSearch : Cleaned with backup


::Report End
It look like your post got closed because of the length of time with no response? You must have posted again in a New Topic and little eagle spotted it and merged it with the original post. We need to stay in this same topic using the Add Reply button and never the NewTopic one. If you wish to continue, I can say the HJT log looks good, but ewido did has some trouble cleaning everything. To make sure nothing bad is left, please do this:

Open ewido and undate the scanner, allow time for it to finish. Now use these instructions to start your computer in safe mode: http://www.bleepingcomputer.com/tutorials/tutorial61.html Once in safe mode open ewido and choose scanner then complete system scan. Allow ewido to remove everything it locates unless you are sure it is not bad. Save that scan report, I must see it. Once the scan report is saved, then reboot to normal mode and post the scan report and a new HJT log in this same thread.

If I do not hear from you with 48 hours, I will assume you no longer need this thread and close it.

Thanks…Phil
thank you pskelley onde again! :)

Logfile of HijackThis v1.99.1
Scan saved at 19:47:37, on 18/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\WINDOWS\system32\gsicon.exe
C:\WINDOWS\system32\dslagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=051406 serial=DR12WUJ-5877021-YTR lang=EN
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: GlobespanVirata Dial-Up PPP Connection.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128539483764
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 19:45:00, 18/04/2006
+ Report-Checksum: C110F943

+ Scan result:

C:\Documents and Settings\CasaComp\Cookies\casacomp@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup


::Report End
Thanks for returning with that information. ewido is showing one cookie and your HJT log is clean, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

ewido is a great program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

You are good to go, safe surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI