This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Log-thank you in advance :)

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:10:00 PM, on 4/20/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\outlook\outlook.exe
C:\Program Files\Network\ipnetwork.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\win3206487738495.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\QWx0b24\command.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Network Monitor\netmon.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\windows\mousepad13.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\sys03495487738.exe
C:\WINDOWS\System32\SEMBLY~1\wowexec.exe
C:\Documents and Settings\Owner\My Documents\s?curity\l?ass.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\Common Files\Windows\services32.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win3206487738495] C:\WINDOWS\win3206487738495.exe
O4 - HKLM\..\Run: [w001e3e3.dll] RUNDLL32.EXE w001e3e3.dll,I2 0004fa820001e3e3
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [w06e2f08.dll] RUNDLL32.EXE w06e2f08.dll,I2 0004fa82006e2f08
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [newname] C:\windows\newname13.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad13.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard13.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ms04954877384] C:\WINDOWS\ms04954877384.exe
O4 - HKLM\..\Run: [sys03495487738] C:\WINDOWS\sys03495487738.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\System32\SEMBLY~1\wowexec.exe" -vt yazr
O4 - HKCU\..\Run: [Nxuchv] C:\Documents and Settings\Owner\My Documents\s?curity\l?ass.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: svchost.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?e4095aed42247d18d273a32562aff46
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?e4095aed42247d18d273a32562aff46
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\t8r80i9ue8.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx0b24\command.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
spongiebob,

Welcome to Tom Coyote, let me tell ya straight up, it would be easier for me to list the viruses YOU DONT HAVE then to list the ones you do have, one of the main reason being is that your Windows Operating System is out of date and letting alot of this garbage in. Besides about a half dozen viruses, you also are infected with Look2me and Purity Scan .


I would strongly urge you to stay off the internet except for posting here until we get you clean because some if the infections you have are used to download other infections.

You may want to print this all out for reference or copy and paste into Notepad and save it to your desktop because we will be off the internet for most of the fix.



DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix,
* just go to My Computer > YOUR C:\ DRIVE > Program Files and create a new folder and name it Hijackthis .
* Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
* Now open the new folder you just created and right click within that folder and select PASTE .
* Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe


Please do not proceed until you move HJT





* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean




* Go to Start> Run and type in services.msc then press Enter
* Scroll down to Network Monitor
* Double Click that service to open it.
* Click on Stop Service.
* Then change the Startup Type to Disabled.
* OK your way out of the program.

Do the same thing for Command Service or (cmdService) it could be listed either way



Download and install Ewido Anti-Malware
Ewido Anti-Malware
* When installing, under Additional Options
***uncheck
* Install background guard
* Install scan via context menu
* Launch Ewido, there should be an icon on your desktop.
o Click on update
o You should see Update Complete when done.
o Now close out the program <– Dont run it yet





Please download Look2Me-Destroyer.exe to your desktop.

Close all windows before continuing.
Double-click Look2Me-Destroyer.exe to run it.
Put a check next to Run this program as a task.

You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
Once it's done scanning, click the Remove L2M button.

You will receive a Done Scanning message, click OK.
When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
Your computer will then shutdown.

Turn your computer back on.
Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log into your next reply.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX






Now reboot into Safemode

* Go to Start> Shut off Your Computer> Restart
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to Safemode
* Then press the Enter Key on your Keyboard


Now open Ewido
o Click on scanner.
o Run a full system scan
o Let the program scan the machine.
o While the scan is in progress you will be prompted to clean files, click OK.
o Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
o Click Save report.
o Save the report to your desktop.




Open HJT Scan Only, close all open windows, the only window you should have open is HJT, check these items and click on Fix Checked


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)

O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [IpNetwork] C:\Program Files\Network\ipnetwork.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win3206487738495] C:\WINDOWS\win3206487738495.exe
O4 - HKLM\..\Run: [w001e3e3.dll] RUNDLL32.EXE w001e3e3.dll,I2 0004fa820001e3e3
O4 - HKLM\..\Run: [w06e2f08.dll] RUNDLL32.EXE w06e2f08.dll,I2 0004fa82006e2f08
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname13.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad13.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard13.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [ms04954877384] C:\WINDOWS\ms04954877384.exe
O4 - HKLM\..\Run: [sys03495487738]
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\System32\SEMBLY~1\wowexec.exe" -vt yazr
O4 - HKCU\..\Run: [Nxuchv] C:\Documents and Settings\Owner\My Documents\s?curity\l?ass.exe

O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll (file missing)

O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\t8r80i9ue8.dll

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx0b24\command.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe



Look for and delete these files

C:\Program Files\Internet Optimizer
C:\Program Files\Network
C:\Program Files\Network Monitor
C:\Program Files\outlook <– Not Outlook Express

C:\Program Files\Common Files\Windows\services32.exe


C:\windows\keyboard13.exe
C:\windows\mousepad13.exe
C:\WINDOWS\ms04954877384.exe
C:\windows\newname13.exe
C:\WINDOWS\QWx0b24
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\sys03495487738.exe
C:\WINDOWS\win3206487738495.exe


C:\WINDOWS\system32\t8r80i9ue8.dll
C:\WINDOWS\System32\SEMBLY~1\wowexec.exe



Reboot normally and lets run a system cleaner

Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


This is what I need to proceed as we still have more to do, hopefully this will take care of the majority of it, I need to see the log from Look2me Destroyer, the log from Ewido and a new HJT log

Ken :D
1)look2me destroyer log


Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 4/22/2006 6:32:06 PM

Infected! C:\WINDOWS\system32\ir44l5hq1.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll
Infected! C:\WINDOWS\system32\aza4l9fq1.dll
Infected! C:\WINDOWS\system32\diquery.dll
Infected! C:\WINDOWS\system32\fp2203foe.dll
Infected! C:\WINDOWS\system32\hr8q05l5e.dll
Infected! C:\WINDOWS\system32\ir44l5hq1.dll
Infected! C:\WINDOWS\system32\j0p0la7m1d.dll
Infected! C:\WINDOWS\system32\jt6o07j3e.dll
Infected! C:\WINDOWS\system32\jtn2075oe.dll
Infected! C:\WINDOWS\system32\k0js0a17ed.dll
Infected! C:\WINDOWS\system32\kydest.dll
Infected! C:\WINDOWS\system32\m028lafu1d28.dll
Infected! C:\WINDOWS\system32\mtyuv.dll
Infected! C:\WINDOWS\system32\mvr0l99m1.dll
Infected! C:\WINDOWS\system32\o8ro0i93e8.dll
Infected! C:\WINDOWS\system32\p48qlel51hq.dll
Infected! C:\WINDOWS\system32\r06u0aj9edo.dll
Infected! C:\WINDOWS\system32\sfrialui.dll

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\ir44l5hq1.dll
C:\WINDOWS\system32\ir44l5hq1.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\aza4l9fq1.dll
C:\WINDOWS\system32\aza4l9fq1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\diquery.dll
C:\WINDOWS\system32\diquery.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\fp2203foe.dll
C:\WINDOWS\system32\fp2203foe.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\hr8q05l5e.dll
C:\WINDOWS\system32\hr8q05l5e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\ir44l5hq1.dll
C:\WINDOWS\system32\ir44l5hq1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\j0p0la7m1d.dll
C:\WINDOWS\system32\j0p0la7m1d.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\jt6o07j3e.dll
C:\WINDOWS\system32\jt6o07j3e.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\jtn2075oe.dll
C:\WINDOWS\system32\jtn2075oe.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k0js0a17ed.dll
C:\WINDOWS\system32\k0js0a17ed.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\kydest.dll
C:\WINDOWS\system32\kydest.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m028lafu1d28.dll
C:\WINDOWS\system32\m028lafu1d28.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mtyuv.dll
C:\WINDOWS\system32\mtyuv.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mvr0l99m1.dll
C:\WINDOWS\system32\mvr0l99m1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\o8ro0i93e8.dll
C:\WINDOWS\system32\o8ro0i93e8.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\p48qlel51hq.dll
C:\WINDOWS\system32\p48qlel51hq.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\r06u0aj9edo.dll
C:\WINDOWS\system32\r06u0aj9edo.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\sfrialui.dll
C:\WINDOWS\system32\sfrialui.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{C3920E6C-CE19-4EF2-AAD3-62A5513FD10D}"
HKCR\Clsid\{C3920E6C-CE19-4EF2-AAD3-62A5513FD10D}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{045319BE-ECD4-451E-BAAD-73DA11AEE5FB}"
HKCR\Clsid\{045319BE-ECD4-451E-BAAD-73DA11AEE5FB}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AEF40B18-96C0-4150-87C3-4B91B1830D0F}"
HKCR\Clsid\{AEF40B18-96C0-4150-87C3-4B91B1830D0F}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AE0FA138-A4C2-4152-B5D0-B42E922B6034}"
HKCR\Clsid\{AE0FA138-A4C2-4152-B5D0-B42E922B6034}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded



_________________________________________________________________________________
2) ewido log

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 7:02:09 PM, 4/22/2006
+ Report-Checksum: 65460EF

+ Scan result:

HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6001CDF7-6F45-471b-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\webhancer -> Adware.WebHancer : Cleaned with backup
HKLM\SOFTWARE\webhancer\CC -> Adware.WebHancer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
[416] C:\Program Files\NewDotNet\newdotnet6_38.dll -> Adware.NewDotNet : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe -> Dropper.VB.lu : Cleaned with backup
:mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\q1caj6u5.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@epilot[1].txt -> TrackingCookie.Epilot : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\aimfix_quarantine\10960_mousepad11.exe.bak -> Hijacker.VB.mo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\i24.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr8520 -> Adware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.frE9B8 -> Adware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u18.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u1D.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u3B.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un17.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un1B.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un22.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\unC6.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\unD.tmp -> Adware.SurfSide : Cleaned with backup
C:\iexplore.exe -> Dropper.VB.mn : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000137.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000140.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000140.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
C:\Program Files\Internet Optimizer\optimize.exe -> Adware.InternetOptimizer : Cleaned with backup
C:\Program Files\Network\ipnetwork.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\newdotnet6_38.dll -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\readme.html -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\uninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\outlook\outlook.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\outlook\v.tmp -> Worm.VB.dw : Cleaned with backup
C:\Program Files\Toolbar888\tbu02640\ToolBar888.dll -> Adware.Softomate : Cleaned with backup
C:\Program Files\Toolbar888\ToolBar888.dll -> Adware.Softomate : Cleaned with backup
C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\license.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\Sporder.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\webhdll.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whAgent.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whiehlpr.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whInstaller.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whSurvey.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\Yazzle Snowball Wars\OINSetup.exe -> Dropper.PurityScan.ad : Cleaned with backup
C:\Program Files\Yazzle Sudoku\Sudoku.exe -> Dropper.VB.kk : Cleaned with backup
C:\WINDOWS\b.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\DH.dll -> Hijacker.Small.jf : Cleaned with backup
C:\WINDOWS\keyboard13.exe -> Downloader.VB.abj : Cleaned with backup
C:\WINDOWS\mousepad13.e -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\mousepad13.exe -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup
C:\WINDOWS\newname13.exe -> Downloader.VB.aaf : Cleaned with backup
C:\WINDOWS\pf79.exe -> Downloader.Dyfuca.ei : Cleaned with backup
C:\WINDOWS\QWx0b24\asappsrv.dll -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\QWx0b24\command.exe -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\SS1001.exe -> Dropper.Small.qn : Cleaned with backup
C:\WINDOWS\sys03495487738.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\SYSC00.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\system32\ad.html -> Hijacker.Agent.e : Cleaned with backup
C:\WINDOWS\system32\qzxz.dll -> Adware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\rar.exe -> Dropper.VB.mn : Cleaned with backup
C:\WINDOWS\system32\setup.exe.tmp -> Downloader.VB.abh : Cleaned with backup
C:\WINDOWS\system32\w001e3e3.dll -> Downloader.Agent.ahv : Cleaned with backup
C:\WINDOWS\system32\winlog.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\unin101.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\uni_eh.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\unwn.exe -> Trojan.Qoologic : Cleaned with backup
C:\WINDOWS\wallpap.exe -> Hijacker.Agent.gp : Cleaned with backup
C:\WINDOWS\wbyzdtv.exe -> Hijacker.VB.ij : Cleaned with backup
C:\WINDOWS\win3206487738495.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\win32097384954872006.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\wnu_238.exe -> Trojan.Qoologic : Cleaned with backup

_______________________________________________________________________________
3) new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 7:36:26 PM, on 4/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchFilter.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {C8F4C824-52BF-0631-B12A-2B17521976B7} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {A8B0BDED-64A5-495b-97DA-42C0301E229B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?e4095aed42247d18d273a32562aff46
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?e4095aed42247d18d273a32562aff46
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx0b24\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
Hey: Thank you so much for helping me. I forgot to mention my computer was not even responding to ctrl alt delete , and i had all this freeproduct.exe and adsolutions trash installing itself all the time. i also have the 888tool bar which still appears under installed programs after i did everything you told me the ctrl alt delete function is working!! wow here are the 3 logs
spongiebob, :D

Log is looking soooooooo much better but we are not 100% home yet.


* Go to Start> Run and type in services.msc then press Enter
* Scroll down to Command Service
* Double Click that service to open it.
* Click on Stop Service.
* Then change the Startup Type to Disabled.
* OK your way out of the program.

Open HJT > Misc Tools > Delete an NT Service
* Type in cmdService
* Then click on OK, it will ask you to reboot, do so.



Open HJT Scan Only, the only window you should have open is HJT, check these items and click on Fix Checked.


R3 - URLSearchHook: (no name) - {C8F4C824-52BF-0631-B12A-2B17521976B7} - (no file)

O2 - BHO: (no name) - {A8B0BDED-64A5-495b-97DA-42C0301E229B} - (no file)

O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx0b24\command.exe (file missing)



Post a new HJT log please
new log-the last object wasn't on the list. thanks. have a great day!
*******************************

Logfile of HijackThis v1.99.1
Scan saved at 10:15:53 PM, on 4/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchFilter.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?e4095aed42247d18d273a32562aff46
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?e4095aed42247d18d273a32562aff46
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
Your log looks good, just one last thing to check before I post some free tools to install to help keep your system more secure.

Go into the Add -Remove Programs in the Control Panel and see if there is a listing for NewDotNet or NewNet, if there is, uninstall it and post one last log.

Ken :D
no there is none of that. the only suspicious thing is toolbar888 Hey, the directions say that "don't forget to reverse this once your computer is clean" for 2 of the steps. do i do that now? thanks :)
spongiebob,

That toolbar888 is not showing up on your log. If its listed in the Add-Remove programs then go ahead and uninstall it.


Please download LSP-Fix from the following link and save it to a location you can find later if necessary.
LSP-Fix Download Link

We need to remove NewDotNet, here is the link from there website. Not always but sometimes the removal can interfere with your internet connection. So download LSPFix first and then if you have a problem, run it and it will restore your connection.

http://www.newdotnet.com/removal.html

First try procedure 1, if you cant then try 2, then try #4 if the other two dont work.


Post back with a new HJT log.

Ken :D
i tried procedure #4 and it removed it. i tried removing the toolbar 888 but nothing comes up when i click remove on the add/remove programs screen. here is the new log thanks :)
Logfile of HijackThis v1.99.1
Scan saved at 11:10:00 AM, on 4/23/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?e4095aed42247d18d273a32562aff46
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?e4095aed42247d18d273a32562aff46
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
spongiebob,

Good job :thumbup: Your log is clean :thumbup:

toolbar 888 Has been removed , it most likely is just a left over entry in your Add Remove Programs

You can open HJT > Misc Tools > Uninstall Manager and you can remove that entry from the list.


Open up Internet Explorer and go to Tools > Windows update and install all the critical updates which will install Service Pack 2 and beyond, its important not to install any driver files, just critical updates. Depending on your system, this could well take over an hour, but its important for the security of your system.


Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

Be sure to follow the instructions for System Restore because everything we removed is backed up in that program and if you ever use it to revert your system to an earlier date, you can reinfect your self all over again.


Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.
* Clean out your TEMP FILES
* This procedure should be run from SAFEMODE for better results.

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD

* Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer Local Settings
and delete all the contents of the Temp Folder and the Temporary Internet Files Folder <–Just the contents, not the folder itself.

* Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <– But not the temp folder itself.

* Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. <–But not the Prefetch folder itself.


NOW RE-BOOT NORMALLY


* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.

Now Empty your Recycle Bin

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your
system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

* Right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

Reboot your System

Turn ON System Restore.

* Right-click My Computer.
* ClickProperties.
* Click the System Restore tab.
* UN-Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

* Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this

* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

* Here are Free Anti-Virus Programs if you need one. Just install one because with AV software…MORE IS NOT BETTER.

AVG Free Edition
AntVir Personal Edition


* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.

* Spyware Blaster It will prevent most spyware from ever being installed.

* Spyware Guard It offers realtime protection from spyware installation attempts.

* Win Patrol This program will warn you when any changes are being made to your system and
give you the option to deny the change.

* IE- Spyad IE-Spyad places over 4000 web sites and domains
in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed,
although you will still be able to connect to the sites.

* Firefox Browser
It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use
them both. When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you use this
for awhile, you will want to make it your default.

* Thunderbird Mail There companion mail program was highly favored in PCWorld Magazine,
this has a good spam filter and is more secure than Outlook Express.

* Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't
access the internet without it.

* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER/Click on PROPERTIES/ AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.

* Go to START/ CONTROL PANEL> PERFORMANCE AND MAINTENANCE> REARRANGE ITEMS ON YOUR HARD DISK TO MAKE PROGRAMS RUN FASTER
This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.


Thanks for stopping by the Tom Coyote forum, I'm glad I was able to help you. I will keep this thead open for a few days in case you have any questions about the windows update or anything else.


Safe Surfin,

Ken :D
wow Ken thank you so much for everything. i have a question: the original instructions said "don't forget to reverse this once your computer is clean" for the HJT folder and for the "Show hidden files and hide extensions" that was unchecked. do i have to do this? Thanks )
spongiebob,

Your welcome, glad things are running better.

i have a question: the original instructions said "don't forget to reverse this once your computer is clean" for the HJT folder and for the "Show hidden files and hide extensions" that was unchecked. do i have to do this?



HJT is right where we want it to be, :thumbup: you can go here, by right clicking on the Start Button and then clicking on Explore and navigate to where you had HJT originally and delete it.
C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

Just reverse this to hide system files, it wont cause a problem if you dont, but will keep someone from deleting a critical system file by accident.

* Click on MY COMPUTER
* Then on your C: Drive
* Then to TOOLS/ FOLDER OPTIONS/ VIEW
* Choose the radio button to SHOW HIDDEN FILES AND FOLDERS
* Take the checkmark out of HIDE EXTENSIONS FOR KNOWN FILE TYPES
* Then APPLY/ OK

* Don't forget to reverse this once your computer is clean


Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI