This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

A new flavour of VX2 ?

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:scratch:
Please refer to the attached log.
I have had a dump of what the cexx.org website so aptly calls "foistware" onto my computer.
Spybot S&D removed most of it.
Windows Defender/Security Centre removed look2me but inform me that I have the "Blackstone worm" which they cannot remove and try to sell me a sponsored product (WinAntivirus Pro 2006) which does not even detect Blackstone or VX2 (two names for the same thing I believe) let alone remove it.
Ad-Aware SE plus the VX2 add-on detect VX2 but cannot remove it, suggesting that it is a new variant.
I have tried breaking the chain by substituting a write protected dummy "guard.tmp" file which usually spoils the seeding process for generating new dll's but I think the VX2 corporation must be onto this and have introduced a hidden file somewhere, certainly I am seeing more than the usual two dlls created/renamed as part of the start up process.
Can anyone advise how to proceed since adverts every 15 to 20 seconds means I can't connect to the net without becoming very irate. - Will booting from a DOS start up disc and removing the offending dll's that way work? I guess I really need to find the hidden file first though.

TIA and best regards :(

Logfile of HijackThis v1.99.1
Scan saved at 10:19:25, on 24/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Documents and Settings\martinp\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fttech.co.uk/
O3 - Toolbar: (no name) - -{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O17 - HKLM\Software\..\Telephony: DomainName = FTTechnologies.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\gpjql3151.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

————————————————–
Hello and welcome to TomCoyote forum. Right your are, it is a Variant of Adware.Look2Me, we have a fix that works when the directions are followed:

1) Move HJT from the Desktop for safety. I prefer C:\HJT\HijackThis.exe, if you need additional instructions use these: http://russelltexas.com/malware/createhjtfolder.htm

Thanks to Atribune and any others who helped with this fix

2) Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If Look2Me-Destroyer does not reopen automatically, reboot and try again.

If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX

More info:

If for some reason Look2Me-Destroyer doesn't reopen check that task scheduler is running.
If it isnt you can use sc.exe to start it

start>run sc start schedule press enter.

Post the two logs bolded above and we'll see how the fix worked and what is left to be done, please include your comments.

Thanks…pskelley
TomCoyote forum
Expert Member
:D
Well, that seems to have worked OK, thanks very much; it is a bit alarming to say the least when you see the extent of what is being affected by this pest, but at least I have connected to this forum without getting bombarded with adverts!

I am interested to see what you think of my set up and if anything remains to be done.
Thank you very much for your help.
All the best
Perry

Please see the attached logs as requested:

Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 27/03/2006 08:12:07

Infected! C:\WINDOWS\system32\n84s0ih7e84.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019813.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019830.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019839.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019854.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020040.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020048.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020056.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020061.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020076.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020083.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020106.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020111.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020115.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020120.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020139.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020146.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020156.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020166.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020171.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020432.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020528.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020595.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020790.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021795.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021799.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022802.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022806.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022820.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022821.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022829.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022830.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022845.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022923.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022924.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022929.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022930.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022931.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022933.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022934.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022935.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022936.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022937.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022938.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022939.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022940.dll
Infected! C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022942.dll
Infected! C:\WINDOWS\system32\h80qlid5180.dll
Infected! C:\WINDOWS\system32\n84s0ih7e84.dll
Infected! C:\WINDOWS\system32\nxcfg.dll
Infected! C:\WINDOWS\system32\__delete_on_reboot__wkhcon.dll
Infected! C:\WINDOWS\system32\guard.tmp

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\n84s0ih7e84.dll
C:\WINDOWS\system32\n84s0ih7e84.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019813.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019813.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019830.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019830.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019839.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019839.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019854.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0019854.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020040.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020040.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020048.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020048.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020056.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020056.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020061.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020061.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020076.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020076.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020083.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP210\A0020083.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020106.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020106.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020111.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020111.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020115.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020115.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020120.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP211\A0020120.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020139.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020139.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020146.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020146.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020156.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020156.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020166.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020166.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020171.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020171.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020432.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020432.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020528.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP212\A0020528.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020595.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020595.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020790.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0020790.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021795.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021795.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021799.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0021799.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022802.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022802.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022806.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022806.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022820.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022820.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022821.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022821.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022829.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022829.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022830.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022830.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022845.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP213\A0022845.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022923.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022923.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022924.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022924.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022929.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022929.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022930.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022930.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022931.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022931.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022933.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022933.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022934.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022934.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022935.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022935.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022936.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022936.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022937.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022937.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022938.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022938.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022939.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022939.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022940.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022940.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022942.dll
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP217\A0022942.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\h80qlid5180.dll
C:\WINDOWS\system32\h80qlid5180.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\n84s0ih7e84.dll
C:\WINDOWS\system32\n84s0ih7e84.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\nxcfg.dll
C:\WINDOWS\system32\nxcfg.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\__delete_on_reboot__wkhcon.dll
C:\WINDOWS\system32\__delete_on_reboot__wkhcon.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Applets

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{BB6AA09E-BE60-4838-8F1F-89AEAC7CE880}"
HKCR\Clsid\{BB6AA09E-BE60-4838-8F1F-89AEAC7CE880}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5525D11A-2C6B-4E91-89EB-AB17EB0C0FBA}"
HKCR\Clsid\{5525D11A-2C6B-4E91-89EB-AB17EB0C0FBA}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{36865116-9604-4E24-B853-70826B835E2B}"
HKCR\Clsid\{36865116-9604-4E24-B853-70826B835E2B}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E01F022C-44C4-4EB5-BB00-D839A65F014E}"
HKCR\Clsid\{E01F022C-44C4-4EB5-BB00-D839A65F014E}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{8980882C-0AB1-4EC2-A26A-422DE2E85D47}"
HKCR\Clsid\{8980882C-0AB1-4EC2-A26A-422DE2E85D47}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F5819F2B-5C5B-4560-AC34-ADD0841DB0FE}"
HKCR\Clsid\{F5819F2B-5C5B-4560-AC34-ADD0841DB0FE}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1A17A92D-66F0-4866-BF22-C5CBE9CBEC1B}"
HKCR\Clsid\{1A17A92D-66F0-4866-BF22-C5CBE9CBEC1B}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4905A960-25DD-4DC1-8DFF-08DD3D423CB8}"
HKCR\Clsid\{4905A960-25DD-4DC1-8DFF-08DD3D423CB8}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded


Logfile of HijackThis v1.99.1
Scan saved at 08:24:46, on 27/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\martinp\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fttech.co.uk/
O3 - Toolbar: (no name) - -{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O17 - HKLM\Software\..\Telephony: DomainName = FTTechnologies.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
:blink:
Sorry, I got so exited I forgot.

Logfile of HijackThis v1.99.1
Scan saved at 15:03:31, on 27/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\TrackPro\TrackPro.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fttech.co.uk/
O3 - Toolbar: (no name) - -{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O17 - HKLM\Software\..\Telephony: DomainName = FTTechnologies.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = FTTechnologies.local
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
No problem Perry, I feel safer when it is tucked away out of site in case others use the computer. It can be a dangerous tool in untrained hands. Good job with the Destroyer :thumbup: appears it did the job well. I see a little junk to clean and you should be good to go.

1) Windows Defender is still new to us and we are not yet sure if it blocks fixes like some spyware/malware tools. You can try this first if you wish, if it does not work, then:
We need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
Open Windows Defender, Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

2) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(these are just clutter)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
O3 - Toolbar: (no name) - -{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

** step three, if you clean your Prefetch as needed, you can skip this step. If you are unsure, review the information in the link.

3) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\Windows\Prefetch\ >>> delete the contents (NOT THE FOLDER)
Prefetch info: http://www.windowsnetworking.com/articles_…refetch-XP.html

4) If you don't have a good cleaner, use this free one with these instructions:
Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp
Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do.

Perry, since you have nothing left but a little clutter, I will go ahead with closing information now:
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.org/viewtopic.php?t=957
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam

There is no need to post again unless you feel it is necessary.

Safe surfing…Phil :wavey:

Thanks…pskelley
TomCoyote forum
Expert Member
If you are reading this information…thank a teacher,
If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI