This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Thank You so much

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Following is my win2000 log from hijackthis. I don't know what to delete to get rid of spyware. Ran spybot S&D and it found a trojan downloader called Zlob in my System32/stodole3.tlb Log file follows:
Logfile of HijackThis v1.99.1
Scan saved at 2:20:42 PM, on 7/5/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\IoctlSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\cidaemon.exe
C:\TATools\control\FBZip.exe
C:\My Download Files\hijackthis\HijackThis.exe
C:\WINNT\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Nothing - {5f4c3d09-b3b9-4f88-aa82-31332fee1c08} - C:\WINNT\system32\hp100.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [ADATA_PLUtil] C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
O4 - HKLM\..\Run: [LexWebUpdate] C:\Program Files\Lexmark\Install\InstallWeb\InstallWeb.exe /S /L:ENGLISH
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MTV Networks Video Optimizer.lnk.disabled
O15 - Trusted Zone: http://www.drudgereport.com
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145073813919
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} - http://www.mtv.com/overdrive/bin/setup.exe
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINNT\system32\IoctlSvc.exe

Any help to eleminate unnecessary files is appreciated.
Hello lp66, welcome to the forum


Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.



Download SmitRem.exe © noahdfear from one of these sites to your Desktop.
http://www.downloads.subratam.org/smitRem.exe
http://noahdfear.geekstogo.com/click%20cou....php?id=1"

[external image: Posted Image]


Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop. Don't Run Yet.

[external image: Posted Image]

Next:

Download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Delete".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.


Reboot to safe mode

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


logon to your user account.
Open the smitfraud folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. When the tool completes:

[external image: Posted Image]


Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
In the Control Panel click Display > Desktop > Customize desktop > Website > Uncheck "Security Info" if present.

Empty recycle bin.


Reboot

Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection


"copy/paste" the contents of the log C:\smitfiles.txt a new HijackThis log and the Ewido log.
Also please describe how your computer behaves at the moment.
:D :D Don't know what you did with ewido and smitrem but it appears to have worked. here is the ewido error log report from the scan. //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:31:44 Registers: EAX:0012E32C EBX:01290A70 ECX:0012E344 EDX:BDCD0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013588 0012E3B8 00000000 01290A70 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 00010066 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0001005E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0001005E 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013588 0012E3B8 00000000 01290A70 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 00010066 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0001005E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0001005E 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:46:34 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:117F0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0005009E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0005002E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0005002E 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0005009E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0005002E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0005002E 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:53:45 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:D7FF0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0004004E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 00060076 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 00060076 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0004004E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 00060076 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 00060076 00000005 00000000 014402C4 SendMessageW+49 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 19:01:08 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:FA490001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0007007E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 000A0034 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 000A0034 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0007007E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 000A0034 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 000A0034 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL Here is the smitfiles log: :D smitRem © log file version 3.0 by noahdfear Microsoft Windows 2000 [Version 5.00.2195] "IE"="6.0000" The current date is: Fri 07/07/2006 The current time is: 18:25:59.59 Running from C:\Documents and Settings\[removed]\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ Security Toolbar ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ regperf.exe simpole.tlb stdole3.tlb dcomcfg.exe amcompat.tlb nscompat.tlb 1024 dir ld****.tmp hp***.tmp ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 360 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) Here is my latest hijackthis scan log: :wavey: smitRem © log file version 3.0 by noahdfear Microsoft Windows 2000 [Version 5.00.2195] "IE"="6.0000" The current date is: Fri 07/07/2006 The current time is: 18:25:59.59 Running from C:\Documents and Settings\[removed]\Desktop\smitRem I will check back to see if there is anythin g more that needs to be done. Thanks again, lp66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ Security Toolbar ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ regperf.exe simpole.tlb stdole3.tlb dcomcfg.exe amcompat.tlb nscompat.tlb 1024 dir ld****.tmp hp***.tmp ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 360 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :)
:D :D Don't know what you did with ewido and smitrem but it appears to have worked. here is the ewido error log report from the scan. //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:31:44 Registers: EAX:0012E32C EBX:01290A70 ECX:0012E344 EDX:BDCD0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013588 0012E3B8 00000000 01290A70 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 00010066 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0001005E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0001005E 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013588 0012E3B8 00000000 01290A70 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 00010066 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0001005E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0001005E 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:46:34 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:117F0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0005009E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0005002E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0005002E 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0005009E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 0005002E 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 0005002E 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 18:53:45 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:D7FF0001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0004004E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 00060076 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 00060076 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0004004E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 00060076 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 00060076 00000005 00000000 014402C4 SendMessageW+49 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL //===================================== Exception code: C0000005 ACCESS_VIOLATION Fault address: 00426DD6 01:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe Module Date: 06/16/2006 09:39:05 File Version of C:\Program Files\ewido anti-spyware 4.0\ewido.exe: 4.0.0.172 Exception Date: 07/07/2006 19:01:08 Registers: EAX:0012E32C EBX:01290A98 ECX:0012E344 EDX:FA490001 ESI:77E3B7C8 EDI:01413008 CS:EIP:001B:00426DD6 SS:ESP:0023:0012E1F8 EBP:0012E38C DS:0023 ES:0023 FS:003B GS:0000 Flags:00010246 Intel specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0007007E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 000A0034 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 000A0034 00000005 00000000 014402C4 0001:0002A811 C:\WINNT\system32\USER32.dll ImageHelp specific method Call stack: Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address 00426DD6 0012E38C 00013586 0012E3B8 00000000 01290A98 0001:00025DD6 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 00427B42 0012E3D4 0012E990 00000001 0007007E 50000000 0001:00026B42 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 004280DA 0012E468 0012E5F4 77E3C159 000A0034 00000005 0001:000270DA C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77E3B811 0012E488 000A0034 00000005 00000000 014402C4 SetSystemTimer+104 Loaded Modules: Base Size Module 00400000 609000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\ewido.exe 77F80000 07C000 5.00.2195.7006 C:\WINNT\system32\ntdll.dll 690A0000 00B000 5.00.2134.0001 C:\WINNT\system32\PSAPI.DLL 7C570000 0B3000 5.00.2195.7006 C:\WINNT\system32\KERNEL32.DLL 10000000 0E3000 4.00.0000.0172 C:\Program Files\ewido anti-spyware 4.0\engine.dll 70A70000 066000 6.00.2800.1740 C:\WINNT\system32\SHLWAPI.dll 7C2D0000 065000 5.00.2195.7038 C:\WINNT\system32\ADVAPI32.dll 77D30000 06F000 5.00.2195.7085 C:\WINNT\system32\RPCRT4.dll 77F40000 03C000 5.00.2195.7073 C:\WINNT\system32\GDI32.dll 77E10000 069000 5.00.2195.7032 C:\WINNT\system32\USER32.dll 78000000 045000 6.01.9844.0000 C:\WINNT\system32\msvcrt.dll 75030000 014000 5.00.2195.6601 C:\WINNT\system32\WS2_32.dll 75020000 008000 5.00.2134.0001 C:\WINNT\system32\WS2HELP.DLL 77570000 030000 5.00.2161.0001 C:\WINNT\system32\WINMM.dll 7CF30000 246000 5.00.3900.7080 C:\WINNT\system32\SHELL32.dll 71710000 084000 5.81.4916.0400 C:\WINNT\system32\COMCTL32.dll 6B2C0000 005000 5.00.2180.0001 C:\WINNT\system32\MSIMG32.dll 76B30000 03E000 5.00.3700.6693 C:\WINNT\system32\comdlg32.dll 7CE20000 0EF000 5.00.2195.7059 C:\WINNT\system32\ole32.dll 75050000 008000 5.00.2195.6603 C:\WINNT\system32\WSOCK32.dll 77340000 013000 5.00.2195.6602 C:\WINNT\system32\iphlpapi.dll 77520000 005000 5.00.2134.0001 C:\WINNT\system32\ICMP.DLL 77320000 017000 5.00.2181.0001 C:\WINNT\system32\MPRAPI.DLL 75150000 010000 5.00.2195.6944 C:\WINNT\system32\SAMLIB.DLL 7CDC0000 053000 5.00.2195.7038 C:\WINNT\system32\NETAPI32.DLL 77980000 024000 5.00.2195.7003 C:\WINNT\system32\DNSAPI.dll 751C0000 006000 5.00.2134.0001 C:\WINNT\system32\NETRAP.dll 77BF0000 011000 5.00.2195.6666 C:\WINNT\system32\NTDSAPI.dll 77950000 02B000 5.00.2195.7017 C:\WINNT\system32\WLDAP32.DLL 7C340000 00F000 5.00.2195.6695 C:\WINNT\system32\SECUR32.DLL 779B0000 09B000 2.40.4522.0000 C:\WINNT\system32\OLEAUT32.DLL 773B0000 02F000 5.00.2195.6601 C:\WINNT\system32\ACTIVEDS.DLL 77380000 023000 5.00.2195.6993 C:\WINNT\system32\ADSLDPC.DLL 77830000 00E000 5.00.2168.0001 C:\WINNT\system32\RTUTILS.DLL 77880000 08E000 5.00.2195.6622 C:\WINNT\system32\SETUPAPI.DLL 7C0F0000 064000 5.00.2195.7002 C:\WINNT\system32\USERENV.DLL 774E0000 034000 5.00.2195.6920 C:\WINNT\system32\RASAPI32.DLL 774C0000 011000 5.00.2195.6824 C:\WINNT\system32\rasman.dll 77530000 022000 5.00.2195.6664 C:\WINNT\system32\TAPI32.dll 77360000 019000 5.00.2195.6685 C:\WINNT\system32\DHCPCSVC.DLL 77820000 007000 5.00.2195.6623 C:\WINNT\system32\VERSION.dll 759B0000 006000 5.00.2195.6611 C:\WINNT\system32\LZ32.DLL 7C950000 08F000 2000.02.3529.0000 C:\WINNT\system32\CLBCATQ.DLL 77840000 03E000 5.00.2195.6705 C:\WINNT\system32\cscui.dll 770C0000 023000 5.00.2195.6713 C:\WINNT\system32\CSCDLL.DLL 72A00000 02D000 5.00.2195.6613 C:\WINNT\system32\DBGHELP.DLL Here is the smitfiles log: :D smitRem © log file version 3.0 by noahdfear Microsoft Windows 2000 [Version 5.00.2195] "IE"="6.0000" The current date is: Fri 07/07/2006 The current time is: 18:25:59.59 Running from C:\Documents and Settings\[removed]\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ Security Toolbar ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ regperf.exe simpole.tlb stdole3.tlb dcomcfg.exe amcompat.tlb nscompat.tlb 1024 dir ld****.tmp hp***.tmp ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 360 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) Here is my latest hijackthis scan log: :wavey: smitRem © log file version 3.0 by noahdfear Microsoft Windows 2000 [Version 5.00.2195] "IE"="6.0000" The current date is: Fri 07/07/2006 The current time is: 18:25:59.59 Running from C:\Documents and Settings\[removed]\Desktop\smitRem I will check back to see if there is anythin g more that needs to be done. Thanks again, lp66 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ Security Toolbar ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ regperf.exe simpole.tlb stdole3.tlb dcomcfg.exe amcompat.tlb nscompat.tlb 1024 dir ld****.tmp hp***.tmp ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 360 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :)
Please use the [external image: Posted Image] Button below to reply. Thanks

Post a new HijackThis log here in this thread:
Please use the [external image: Posted Image] Button below to reply. Thanks
here is the latest hijackthis log for lp66. Is there anything I need to delete?
Logfile of HijackThis v1.99.1
Scan saved at 9:50:04 AM, on 7/8/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINNT\system32\IoctlSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\Explorer.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\System32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\My Download Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [ADATA_PLUtil] C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
O4 - HKLM\..\Run: [LexWebUpdate] C:\Program Files\Lexmark\Install\InstallWeb\InstallWeb.exe /S /L:ENGLISH
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MTV Networks Video Optimizer.lnk.disabled
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145073813919
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} - http://www.mtv.com/overdrive/bin/setup.exe
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINNT\system32\IoctlSvc.exe
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete this File if listed:
C:\WINNT\farmmext.exe




Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Computer appears to be running normally. No problem getting on the internet now. Here is the latest HJT log after I ran ATF Cleaner.
Logfile of HijackThis v1.99.1
Scan saved at 1:09:58 PM, on 7/8/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINNT\system32\IoctlSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\Explorer.EXE
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\System32\cidaemon.exe
C:\My Download Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
F2 - REG:system.ini: UserInit=C:\WINNT\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe -hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [ADATA_PLUtil] C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
O4 - HKLM\..\Run: [LexWebUpdate] C:\Program Files\Lexmark\Install\InstallWeb\InstallWeb.exe /S /L:ENGLISH
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: MTV Networks Video Optimizer.lnk.disabled
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145073813919
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} - http://www.mtv.com/overdrive/bin/setup.exe
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINNT\system32\IoctlSvc.exe
Good Job :thumbup:

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Thanks for the help. Does Win2000 have a system restore point. I thought only XP had that feature. I have AVG grisoft antivirus that updates daily and runs scans about 3 times per week. I use the laptop online by a netgear wireless access card to my home wireless setup. I have dsl to a Belkin wireless router. I do not broadcast a ssid and my netgear access card is MAC address only to be allowed into the router. Any other precautions I should be running. A friend told me spybot S&D is not the best to run and some antivirus pgms. call it spyware. lp66
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI