This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT logfile

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running windows xp and has a host of problems , such as pop ups , winfixer , sloooow , frezzes up , kicks me off internet , it is especially bad at startup , or first getting on the net , and gets better after i've been on a while . I have Adaware , AVG , HJT and I have updated and ran them today as well as windows update . I also rebooted before I ran HJT . Any help would be greatly appriciated . The folling is my HJT logfile Thanks again , Terry ( slowly backing away from computer with bfh ) Logfile of HijackThis v1.99.1
Scan saved at 3:02:28 PM, on 6/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\iissrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
C:\SLIDESHW\Snsicon.exe
C:\Documents and Settings\Liz Taylor\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\WgaTray.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - URLSearchHook: UB Class - {00000000-15D9-4736-AB29-131578A45F2B} - C:\WINDOWS\System32\wsrchc3.dll (file missing)
O2 - BHO: DPCUpdater Object - {E291663A-2D6F-4B56-B9DF-AE239AEF6A5B} - C:\WINDOWS\System32\awvvv.dll
O4 - HKLM\..\Run: [dsbkqbbta] C:\WINDOWS\System32\ovopfxlx.exe
O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe
O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKLM\..\Run: [wxdxoda] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [iissrv] C:\WINDOWS\iissrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ywp7RXN4T] loasp.exe
O4 - Startup: Snsicon.lnk = C:\SLIDESHW\Snsicon.exe
O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145685213596
O20 - Winlogon Notify: awvvv - C:\WINDOWS\System32\awvvv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Welcome to the forum :wavey:

There's quite a bit of "unwanteds" running amok on your machine. :(

Let's see if we can corral them nasty critters…. :thumbup:

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan yet.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only

Don't run it yet.

Download VundoFix.exe to your desktop from here:

VundoFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. You will receive a prompt asking if you want to remove the files, click YES.
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will shutdown your computer, click OK.
7. Turn your computer back on.

Boot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All. Click the Empty Selected button. Close the program.

Then run Ewido, click on the Scanner, run a Full scan and let it clean everything it finds. Save the logfile from the scan.

Boot in normal mode.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


And the report from Ewido, into this thread.
:)
Ok , I have done everything you said and here are the results Logfile of HijackThis v1.99.1
Scan saved at 12:32:17 AM, on 6/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
C:\SLIDESHW\Snsicon.exe
C:\Documents and Settings\Liz Taylor\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - URLSearchHook: (no name) - {00000000-15D9-4736-AB29-131578A45F2B} - (no file)
O4 - HKLM\..\Run: [dsbkqbbta] C:\WINDOWS\System32\ovopfxlx.exe
O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe
O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKLM\..\Run: [wxdxoda] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ywp7RXN4T] loasp.exe
O4 - Startup: Snsicon.lnk = C:\SLIDESHW\Snsicon.exe
O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145685213596
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


VundoFix V4.2.84

Checking Java version…

Sun Java not detected
Scan started at 11:01:51 PM 6/25/2006

Listing files found while scanning….

C:\WINDOWS\System32\awvvv.dll
C:\WINDOWS\System32\vvvwa.ini
C:\WINDOWS\System32\vvvwa.bak1
C:\WINDOWS\System32\vvvwa.bak2
C:\WINDOWS\System32\vvvwa.ini2
C:\WINDOWS\System32\vvvwa.tmp

C:\WINDOWS\system32\vvvwa.bak1
C:\WINDOWS\system32\vvvwa.bak2
C:\WINDOWS\system32\vvvwa.tmp
C:\WINDOWS\system32\vvvwa.ini
C:\WINDOWS\system32\vvvwa.ini2
C:\WINDOWS\system32\awvvv.dll
C:\WINDOWS\system32\vvvwa.ini2
C:\WINDOWS\system32\vvvwa.bak2
C:\WINDOWS\system32\vvvwa.tmp
C:\WINDOWS\system32\vvvwa.ini
C:\WINDOWS\system32\vvvwa.ini2
C:\WINDOWS\system32\awvvv.dll
Attempting to delete C:\WINDOWS\System32\awvvv.dll
C:\WINDOWS\System32\awvvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\vvvwa.ini
C:\WINDOWS\System32\vvvwa.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\vvvwa.bak1
C:\WINDOWS\System32\vvvwa.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\vvvwa.bak2
C:\WINDOWS\System32\vvvwa.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\vvvwa.ini2
C:\WINDOWS\System32\vvvwa.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\vvvwa.tmp
C:\WINDOWS\System32\vvvwa.tmp Has been deleted!

Performing Repairs to the registry.
Done!
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:56:36 PM 6/25/2006

+ Scan result:



C:\WINDOWS\system32\Cache\cxtpls_loader.exe -> Adware.Apropos : No action taken.
C:\WINDOWS\system32\BO2801040128.dll -> Adware.BargainBuddy : No action taken.
C:\WINDOWS\system32\msbb321.dll -> Adware.BargainBuddy : No action taken.
C:\WINDOWS\Downloaded Program Files\flash.inf -> Adware.BetterInternet : No action taken.
C:\Program Files\Common Files\CMEII\CMEIIAPI.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GController.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GDwldEng.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GIocl.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GIoclClient.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GStore.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\CMEII\GStoreServer.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\GMT\EGGCEngine.dll -> Adware.Gator : No action taken.
C:\Program Files\Common Files\GMT\egIEEngine.dll -> Adware.Gator : No action taken.
C:\WINDOWS\system32\ilmdat.exe -> Adware.MDH : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Adware.WebSearch : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~16360.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~236929.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~243570.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~253489.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~261520.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~266908.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~280174.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~291989.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~292473.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~296835.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~304115.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~317652.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~327890.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~32878.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~336135.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~342120.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~354650.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~372250.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~378478.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~384598.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~396012.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~398705.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~405780.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~442505.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~447126.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~452161.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~453713.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~459057.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~465366.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~473166.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~484237.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~491340.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~502246.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~514969.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~518608.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~519733.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~539221.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~549812.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~558225.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~562447.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~565935.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~570886.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~584427.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~585180.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~593945.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~599588.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~600880.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~607913.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~627534.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~627650.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~637308.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~644635.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~649021.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~649953.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~650274.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~650951.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~661845.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~663351.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~664174.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~666315.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~671954.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~676515.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~684442.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~686526.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~687005.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~701142.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~703192.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~705416.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~705615.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~706703.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~707234.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~709185.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~710494.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~712917.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~714473.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~722696.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~723091.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~724087.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~735453.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~740774.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~741101.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~742289.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~742925.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~752469.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~753779.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~757440.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~757637.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~757801.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~759780.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~763846.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~769090.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~769155.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~772558.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~776479.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~777477.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~781978.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~782529.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~794301.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~797139.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~799158.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~800825.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~801036.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~805619.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~808080.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~811180.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~814317.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~817919.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~820739.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~821638.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~832906.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~834970.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~838273.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~843721.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~845824.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~848475.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~850202.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~852320.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~852647.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~854544.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~855010.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~860250.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~867626.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~868781.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~877491.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~877824.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~880669.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~883819.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~884266.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~890988.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~891011.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~900256.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~900849.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~905697.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~906223.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~909170.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~910888.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~919114.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~926680.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~928794.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~931232.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~934196.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~938098.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~941242.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~943063.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~946314.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~949279.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~954883.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~955154.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~958307.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~958845.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~962061.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~969834.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~972423.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~973258.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~976274.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~984403.tmp -> Adware.Wintol : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~996788.tmp -> Adware.Wintol : No action taken.
HKLM\SOFTWARE\Classes\CLSID\{00000000-15D9-4736-AB29-131578A45F2B} -> Adware.Wordsonweb : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~136730.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~143547.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~14394.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~199187.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~23674.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~253756.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~270070.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~286066.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~306066.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~315681.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~320386.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~345606.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~394862.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~416432.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~449817.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~460707.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~484205.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~528001.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~552262.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~556333.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~580508.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~600634.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~609321.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~640028.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~643013.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~651771.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~654158.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~671226.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~686732.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~703535.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~705852.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~731217.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~733588.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~734646.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~759308.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~809510.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~839951.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~842538.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~8615.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~864751.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~874371.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~893574.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~894443.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~920444.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~920863.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~931798.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~943822.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~956722.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~961666.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~979837.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~986717.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~992500.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~994891.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~994906.tmp -> Downloader.Wintool.a : No action taken.
C:\Documents and Settings\Liz Taylor\Local Settings\Temp\~997182.tmp -> Downloader.Wintool.a : No action taken.
C:\WINDOWS\Temp\~322845.tmp -> Downloader.Wintool.a : No action taken.
C:\WINDOWS\Temp\~514902.tmp -> Downloader.Wintool.a : No action taken.
C:\WINDOWS\system32\drivers\df_kmd.sys -> Rootkit.Agent.af : No action taken.
C:\WINDOWS\iissrv.exe -> Trojan.Small : No action taken.


::Report end
:scratch:

I'm not "hip" on Ewido controls, but why does it say "No action taken." after all the "baddies" it found?
:unsure:

"Fix" these items with HijackThis!:

R3 - URLSearchHook: (no name) - {00000000-15D9-4736-AB29-131578A45F2B} - (no file)

O4 - HKLM\..\Run: [dsbkqbbta] C:\WINDOWS\System32\ovopfxlx.exe

O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe

O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe

O4 - HKLM\..\Run: [wxdxoda] C:\WINDOWS\svchost.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [Ywp7RXN4T] loasp.exe

Boot in "safe" mode, and run Ewido once more.

This time, have it quarantine (look at direction no. 5 in my first post) the bad items it finds.

Then boot in normal mode, and post a new HijackThis! log, and a new Ewido report.

On a positive note, "Vundo" (A.K.A. "Winfixer") is gone now.
:) :thumbup:
On the ewido report , I think I copied the report before I took action on them , I ran another scan , then took action , and then copied this time ! I fixed the items in HJT , and yes Winfixer is gone ! The computer is still running kind of funky but is much , much better ! What can I do , or download to minimize this in the future ? You guys are a godsend thank you so much !Logfile of HijackThis v1.99.1
Scan saved at 11:47:23 AM, on 6/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
C:\SLIDESHW\Snsicon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Liz Taylor\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
R3 - URLSearchHook: (no name) - {00000000-15D9-4736-AB29-131578A45F2B} - (no file)
O4 - HKLM\..\Run: [dsbkqbbta] C:\WINDOWS\System32\ovopfxlx.exe
O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe
O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe
O4 - HKLM\..\Run: [wxdxoda] C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ywp7RXN4T] loasp.exe
O4 - Startup: Snsicon.lnk = C:\SLIDESHW\Snsicon.exe
O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145685213596
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 12:40:28 PM 6/26/2006

+ Scan result:



C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081246.exe -> Adware.Apropos : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081244.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081245.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081248.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081249.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081250.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081251.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081252.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081253.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081254.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081255.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081256.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081247.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081242.sys -> Rootkit.Agent.af : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz [removed][1].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz [removed][1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Liz Taylor\Cookies\liz taylor@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{09CEBF32-B68D-4AD7-8E1C-45C7740F6F2E}\RP260\A0081243.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end
Download Killbox from here:

Killbox.zip © Option^Explicit

Unzip it, but don't run it yet.

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

C:\WINDOWS\System32\ovopfxlx.exe
C:\WINDOWS\Meruoq.exe
C:\WINDOWS\pgtaff.exe
C:\WINDOWS\svchost.exe


CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R3 - URLSearchHook: (no name) - {00000000-15D9-4736-AB29-131578A45F2B} - (no file)

O4 - HKLM\..\Run: [dsbkqbbta] C:\WINDOWS\System32\ovopfxlx.exe

O4 - HKLM\..\Run: [Rxagik] C:\WINDOWS\Meruoq.exe

O4 - HKLM\..\Run: [pgtaff] C:\WINDOWS\pgtaff.exe

O4 - HKLM\..\Run: [wxdxoda] C:\WINDOWS\svchost.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [Ywp7RXN4T] loasp.exe

Then click "Fix checked", and close Hijack This!

Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new HijackThiS! log file into this thread. :)
I couldn't copy the things in the quote box, but I put them in manually , one at a time ad all of them came up file does not exist . Logfile of HijackThis v1.99.1
Scan saved at 10:30:04 PM, on 6/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
C:\WINDOWS\System32\svchost.exe
C:\SLIDESHW\Snsicon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Liz Taylor\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Snsicon.lnk = C:\SLIDESHW\Snsicon.exe
O4 - Global Startup: Watch.lnk = C:\Program Files\4.0M MPEG4 DV\Console\Watch.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145685213596
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI