This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

spyware, malware ect.

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am a novice so any help would be greatly appreciated…….THANKS……..


Logfile of HijackThis v1.99.1
Scan saved at 7:23:38 PM, on 7/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$COSSNET8082\Binn\sqlservr.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\WINDOWS\system32\98740089.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\winstall.exe
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jason\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [98740089.exe] C:\WINDOWS\system32\98740089.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [98740089.exe] C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.foremoststar.com
O15 - Trusted IP range: http://195.95.*.*
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: fairydom - {5839511e-ec1b-4f91-ace3-fb88e52f5239} - C:\WINDOWS\system32\jevtxpg.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2 - Unknown owner - C:\COSS\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hey guys my computer is driving me nuts.. My homepage has been set to sysnetsecurity.com,,, I also get a security wizard that pops up every 5 min. My task bar is also full of spyware type applications….. Will Someone please look at my Hijackthis LOG……………
Hello and welcome to the forum


Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.



Download SmitRem.exe © noahdfear from one of these sites to your Desktop.
http://www.downloads.subratam.org/smitRem.exe
http://noahdfear.geekstogo.com/click%20cou....php?id=1"

[external image: Posted Image]


Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop. Don't Run Yet.

[external image: Posted Image]

Next:

Download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Delete".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.


Reboot to safe mode

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


logon to your user account.
Open the smitfraud folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. When the tool completes:

[external image: Posted Image]


Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
In the Control Panel click Display > Desktop > Customize desktop > Website > Uncheck "Security Info" if present.

Empty recycle bin.


Reboot

Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection


"copy/paste" the contents of the log C:\smitfiles.txt a new HijackThis log and the Ewido log.
Also please describe how your computer behaves at the moment.
So I did everthing but I dont think that I did the smitrem right ……there was no (runthis.bat) only a (runthis) which i did not do ……computer is much better but there are still a couple of pop ups telling me to download ultimate defender and other such…… here is the Ewido log and the new Hijack this logs….. Do I need to repeat the whole thing because of the (smitrem)?


Logfile of HijackThis v1.99.1
Scan saved at 5:06:42 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$COSSNET8082\Binn\sqlservr.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jason\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINDOWS\system32\hp100.tmp (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [98740089.exe] C:\WINDOWS\system32\98740089.exe
O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [98740089.exe] C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: fairydom - {5839511e-ec1b-4f91-ace3-fb88e52f5239} - C:\WINDOWS\system32\jevtxpg.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2 - Unknown owner - C:\COSS\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe










ewido anti-spyware - Scan Report
———————————————————

+ Created at: 4:50:49 PM 7/8/2006

+ Scan result:



HKLM\SOFTWARE\Classes\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB} -> Adware.Generic : Cleaned.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{736b5468-bdad-41be-92d0-22ae2ddf7bcb} -> Adware.Generic : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-12-05-40\10000.qit -> Adware.WeirWeb : Cleaned.
C:\nj.exe -> Downloader.Small.cpg : Cleaned.
C:\winstall.exe -> Downloader.Small.cpg : Cleaned.
C:\WINDOWS\system32\dcomcfg.exe -> Downloader.Zlob.xo : Cleaned.
C:\WINDOWS\system32\hp100.tmp -> Downloader.Zlob.xo : Cleaned.
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned.
C:\WINDOWS\system32\jevtxpg.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10003.qit -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@ford.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10008.qit -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10009.qit -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10019.qit -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10020.qit -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10000.qit -> TrackingCookie.7search : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10004.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10024.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10036.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\28-06-2006-10-13-48\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10000.qit -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10014.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10000.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10005.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10025.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10037.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10046.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-06-2006-23-06-46\10000.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10001.qit -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10001.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10002.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10000.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10002.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10002.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10001.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10002.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10019.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10038.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10001.qit -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10003.qit -> TrackingCookie.Adviva : Cleaned.
C:\Documents and Settings\Crystal\Cookies\crystal@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Jason\Local Settings\Temp\Cookies\jason@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10002.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10003.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-14-58-40\10000.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10001.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10004.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10015.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10002.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10001.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10004.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10003.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10002.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10000.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10006.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10003.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10020.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10026.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10034.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10039.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10047.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-06-2006-23-06-46\10001.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\28-06-2006-10-13-48\10001.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10002.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10002.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\31-05-2006-16-13-31\10000.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10004.qit -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10005.qit -> TrackingCookie.Bridgetrack : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10007.qit -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10008.qit -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Crystal\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10004.qit -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10006.qit -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10003.qit -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Crystal\Cookies\crystal@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jason\Local Settings\Temp\Cookies\jason@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10004.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10005.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-14-58-40\10001.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10002.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10005.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10017.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10003.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10003.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10005.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10005.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10003.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10001.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10010.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10007.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10021.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10027.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10040.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-06-2006-23-06-46\10002.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\28-06-2006-10-13-48\10002.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10004.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10004.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\31-05-2006-16-13-31\10001.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10003.qit -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10007.qit -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10008.qit -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10009.qit -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10022.qit -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10006.qit -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10006.qit -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10012.qit -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10013.qit -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10010.qit -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10006.qit -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10005.qit -> TrackingCookie.Internetfuel : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10014.qit -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10005.qit -> TrackingCookie.Liveperson : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10017.qit -> TrackingCookie.Liveperson : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10035.qit -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Crystal\Cookies\crystal@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Jason\Local Settings\Temp\Cookies\jason@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10006.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10004.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10007.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10018.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10005.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10007.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10008.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10006.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10011.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10041.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\28-06-2006-10-13-48\10003.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10006.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10049.qit -> TrackingCookie.Onestat : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10005.qit -> TrackingCookie.Overture : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10006.qit -> TrackingCookie.Overture : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10007.qit -> TrackingCookie.Overture : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10018.qit -> TrackingCookie.Overture : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10007.qit -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10028.qit -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10050.qit -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10006.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-14-58-40\10002.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10006.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10021.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10008.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10004.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10008.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10009.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10002.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10015.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10012.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-06-2006-23-06-46\10003.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\28-06-2006-10-13-48\10004.qit -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10013.qit -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\01-07-2006-11-19-49\10007.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10007.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-06-2006-10-52-36\10007.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10010.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10022.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10011.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10005.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10009.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10009.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10016.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10014.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10023.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10042.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-06-2006-23-06-46\10004.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\29-06-2006-10-19-25\10005.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\31-05-2006-16-13-31\10003.qit -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10015.qit -> TrackingCookie.Revenue : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10004.qit -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10011.qit -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10005.qit -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\31-05-2006-16-13-31\10002.qit -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10012.qit -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][2].txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\13-06-2006-10-11-52\10006.qit -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10029.qit -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10051.qit -> TrackingCookie.Sexcounter : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Jason\Cookies\jason@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10023.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\06-07-2006-09-50-38\10024.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10017.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\22-06-2006-09-36-50\10018.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10030.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10031.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10032.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10033.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10043.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10044.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10052.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10053.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10054.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10055.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10056.qit -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Jason\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10009.qit -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10012.qit -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10045.qit -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10009.qit -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Jason\Local Settings\Temp\Cookies\jason@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10010.qit -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10010.qit -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10011.qit -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\SpywareBot\Quarantine\14-06-2006-20-02-05\10011.qit -> TrackingCookie.Webtrendslive : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10010.qit -> TrackingCookie.Webtrendslive : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10012.qit -> TrackingCookie.Wegcash : Cleaned.
C:\Program Files\SpywareBot\Quarantine\02-06-2006-11-06-19\10013.qit -> TrackingCookie.Wegcash : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10013.qit -> TrackingCookie.Wegcash : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10057.qit -> TrackingCookie.Xxxcounter : Cleaned.
C:\Documents and Settings\Crystal\Cookies\crystal@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\SpywareBot\Quarantine\09-06-2006-12-58-54\10014.qit -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\SpywareBot\Quarantine\16-06-2006-08-42-53\10010.qit -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\SpywareBot\Quarantine\21-06-2006-09-20-32\10014.qit -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\SpywareBot\Quarantine\26-05-2006-16-55-36\10016.qit -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\SpywareBot\Quarantine\30-05-2006-18-00-50\10011.qit -> TrackingCookie.Zedo : Cleaned.
C:\WINDOWS\system32\entry.dll -> Trojan.Agent.qg : Cleaned.
C:\Program Files\Media-Codec -> Trojan.Small : Cleaned.
C:\Program Files\Media-Codec\uninst.exe -> Trojan.Small : Cleaned.
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned.
C:\WINDOWS\system32\atmclk.exe -> Trojan.Small : Cleaned.

……there was no (runthis.bat) only a (runthis) which i did not do

You're still infected: Run the fix again and use runthis
Will do…..also when I went to empty recycle bin there was nothing in it….. My screen was also very enlarged in safe mode is that just how it is?

Will do…..also when I went to empty recycle bin there was nothing in it….. My screen was also very enlarged in safe mode is that just how it is?

Yes, that's how it looks in Safe Mode.
Here are my logs…. I still get a system integrity scan wizard that pops up.. other than that all is well….




smitRem © log file
version 3.0

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
"IE"="6.0000"
The current date is: Sat 07/08/2006
The current time is: 17:36:44.89

Running from
C:\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"fairydom"="{5839511e-ec1b-4f91-ace3-fb88e52f5239}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~

Security Toolbar


~~~ Shortcuts ~~~

Online Security Guide.url
Security Troubleshooting.url


~~~ Favorites ~~~



~~~ system32 folder ~~~

regperf.exe
simpole.tlb
stdole3.tlb
amcompat.tlb
nscompat.tlb
ld****.tmp


~~~ Icons in System32 ~~~

ts.ico
ot.ico


~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 824 'explorer.exe'
Killing PID 824 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)




Logfile of HijackThis v1.99.1
Scan saved at 6:25:35 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$COSSNET8082\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\WINDOWS\system32\98740089.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jason\My Documents\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [98740089.exe] C:\WINDOWS\system32\98740089.exe
O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [98740089.exe] C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2 - Unknown owner - C:\COSS\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [98740089.exe] C:\WINDOWS\system32\98740089.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [98740089.exe] C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
C:\WINDOWS\system32\98740089.exe
C:\winstall.exe
C:\Documents and Settings\Jason\Local Settings\Application Data\98740089.exe


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.



Be sure to keep SunJava, updated

In Add/Remove programs click on these and press *remove* if listed:
J2SE Runtime Environment 5.0 - 97.99Mb
J2SE Runtime Environment 5.0 Update 2 - 143.00Mb
J2SE Runtime Environment 5.0 Update 4 - 144.00Mb
J2SE Runtime Environment 5.0 Update 5- 151.00Mb
Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb
Or any other outdated J2SE


It is important to remove older versions as these are the ones with the holes in them. You will be surprised when you go to add/remove to see all of the versions sitting there.

Download Newest >>>> http://www.java.com/en/download/index.jsp

Once installed you can test to see that it is in fact installed >>>>

Sun Java Test


Sun Microsystems has fixed five security bugs in Java that expose computers running Linux, Solaris and Windows to hacker attack.
Everything seems good….. Do I need to delete the backups in the HJT folder? Here is my new HJT log..

Thank you very much for the help!!!!!!!!!!!!!!!!!!!!!!!




Logfile of HijackThis v1.99.1
Scan saved at 7:18:30 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL$COSSNET8082\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\COSS\Apache Group\Apache2\bin\Apache.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Documents and Settings\Jason\My Documents\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Monitor Apache Servers.lnk = C:\COSS\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://eagent.farmersinsurance.com/PLA/eAg…ctiveX/smsx.cab
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/PLA/eAg…ImgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/PLA/eAg…mgXDialog61.cab
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/PLA/eAg…iveX/ImgX61.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apache2 - Unknown owner - C:\COSS\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Jason\Desktop\ewido anti-spyware 4.0\guard.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Do I need to delete the backups in the HJT folder?

Yes,

Good Job :thumbup:

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI