This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

How to remove spyfalcon messages

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

In my task bar I have a green icon that flashes Red and from time to time it produces a pop windoe indicating thte my system is infected with spyware click here it get the latest removal software. Clicking ont the link brings me to www.spyfalcon.com.

I have tried various methods on the web to remove the spyfalcon but they all failed. I've also done scans with spybot, ADware, and spy doctor and they detect nothing.

This message is getting anoyning so hopefull someone here and steer me in the direction.

here is my log and thanks in advance!!

Logfile of HijackThis v1.99.1
Scan saved at 12:36:53 AM, on 01/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\TEMP\ZD27BF.EXE
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijack this\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qca7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qca7.hpwis.com/
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1146102288156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1146193203546
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
Hello P_Dude, welcome to the forum


Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.



Download SmitRem.exe © noahdfear from one of these sites to your Desktop.
http://www.downloads.subratam.org/smitRem.exe
http://noahdfear.geekstogo.com/click%20cou....php?id=1"

Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop. Don't Run Yet.



Please download the trial version of ewido anti-malware 3.5. Install ewido anti-malware 3.5 and start the program from the icon on your desktop, then check for and download updates. Don't Run Yet.


Reboot to safe mode

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


logon to your user account.
Open the smitfraud folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. When the tool completes:



Open Ewido Security Suite
  • Then please run Ewido, click on the Scanner run a full scan and let
  • it clean everything it finds.
  • Once the scan has completed, there will be a button located on the bottom
  • of the screen named
  • Click Save report
  • Save the report to your desktop

In the Control Panel click Display > Desktop > Customize desktop > Website > Uncheck "Security Info" if present.

Empty recycle bin.


Reboot



"copy/paste" the contents of the log C:\smitfiles.txt a new HijackThis log and the Ewido log.
Also please describe how your computer behaves at the moment.
HI LDTate

Thanks so much for taking the time to respond, your suggestion worked like a charm. I am no longer seeing the spyfalcon false mesages. Its amazing how the other spyware scanners did not pick it up. Welll here are my log files as requested…….

Thanks once again!!!

Logfile of HijackThis v1.99.1
Scan saved at 12:41:23 AM, on 02/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\RV74CF.EXE
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qca7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qca7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qca7.hpwis.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1146102288156
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1146193203546
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe





smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: 01/06/2006
The current time is: 22:06:34.29

Running from
C:\Documents and Settings\Owner\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{a566f298-05a6-4b3d-b672-da7c27316430}"="AutoDisc Ware"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
@="C:\WINDOWS\system32\htey.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 844 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{a566f298-05a6-4b3d-b672-da7c27316430}"="AutoDisc Ware"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430}\InProcServer32]
@="C:\WINDOWS\system32\htey.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)
Here is the last log. I took out a lot of the bad cookie stuff…. ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 11:23:06 PM, 01/06/2006 + Report-Checksum: 5BEE483B + Scan result: HKU\S-1-5-21-716129303-1088688356-2523437037-1003\Software\Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430} -> Trojan.Small : Cleaned with backup HKU\S-1-5-21-716129303-1088688356-2523437037-1003_Classes\CLSID\{a566f298-05a6-4b3d-b672-da7c27316430} -> Trojan.Small : Cleaned with backup [740] C:\WINDOWS\system32\htey.dll -> Trojan.Fakealert : Cleaned with backup :mozilla.6:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.7:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.8:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.9:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.11:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.12:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.13:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.14:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.15:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.16:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.17:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.18:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.19:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.20:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.21:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.22:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.23:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.24:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.35:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.36:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.37:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.38:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.48:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.49:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.50:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.51:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.55:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.64:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.65:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.66:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.70:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup :mozilla.71:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.72:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.73:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.74:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.75:C:\Documents and Settings\lambro\Application Data\Mozilla\Profiles\default\sh834zms.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@com[1].txt -> TrackingCookie.Com : Cleaned with backup C:\Program Files\Media-Codec -> Trojan.Small : Cleaned with backup ************************ :mozilla.110:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.111:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.112:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Revenue : Cleaned with backup :mozilla.113:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Revenue : Cleaned with backup :mozilla.114:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Revenue : Cleaned with backup :mozilla.122:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.123:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.124:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.125:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Advertising : Cleaned with backup :mozilla.126:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Advertising : Cleaned with backup :mozilla.127:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Advertising : Cleaned with backup :mozilla.131:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.132:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.134:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.135:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.136:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.137:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.139:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.146:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.2o7 : Cleaned with backup :mozilla.147:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.2o7 : Cleaned with backup :mozilla.148:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.2o7 : Cleaned with backup :mozilla.184:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Com : Cleaned with backup :mozilla.186:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.187:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.197:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.198:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.199:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.206:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.2o7 : Cleaned with backup :mozilla.208:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.209:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.210:C:\RECYCLER\NPROTECT\00000121.MOZ -> TrackingCookie.Hitbox : Cleaned with backup C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup C:\WINDOWS\system32\htey.dll -> Trojan.Fakealert : Cleaned with backup C:\WINDOWS\system32\simpole.tlb -> Downloader.Zlob.ow : Cleaned with backup
Looking good :thumbup:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI