This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can you please help me with my HJT log. My log is:

Logfile of HijackThis v1.99.1
Scan saved at 16:03:02, on 21.07.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Priit\Desktop\siim\kaitse\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neti.ee/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"
O4 - HKCU\..\Run: [a81c1d03.exe] C:\Documents and Settings\Priit\Local Settings\Application Data\a81c1d03.exe
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://amsterdam.rawflow.com/clients/3.1.1.2/Rawflow.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteA…/bridge-c18.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112617393817
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://axis.ivmv.ee/activex/AxisCamControl.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.msngamecentre.co.uk/online2/MSN…aploader_v6.cab
O20 - Winlogon Notify: winyqq32 - winyqq32.dll (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi maizipulgad

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below.

Please download Look2Me-Destroyer.exe to your desktop.

Please use this link:
http://www.atribune.org/content/view/28/

* Close all windows and browsers, before continuing.
* Double-click Look2Me-Destroyer.exe to run it.
* Put a check next to Run this program as a task.
* You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
* When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
* Once it's done scanning, click the Remove L2M button.
* You will receive a Done Scanning message, click OK.
* When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
* Your computer will then shutdown.
* Turn your computer back on.

If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
http://www.ascentive.com/support/new/suppo…me=MSWINSCK.OCX

Next:

Please boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.

To stop a service and set to 'disabled'
WXP ONLY

Go to Start > Run and type in Services.msc then click OK

Click the Extended tab.

Scroll down until you find the service. Boonty Games - BOONTY

Click once on the service to highlight it.

Click Stop

Right-Click on the service. Boonty Games - BOONTY

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'


Then, please reboot into Normal Mode.

Then, go into Control Panel>Add/Remove Programs and Uninstall/Remove…

BOONTY Shared/Boonty

Next:
Please set your system to show all files; please see here if you're unsure how to do this.

Close all windows and browsers, leaving only HijackThis running.

Place a check beside each of these entries listed below, if still present.

O4 - HKCU\..\Run: [a81c1d03.exe] C:\Documents and Settings\Priit\Local Settings\Application Data\a81c1d03.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/WebsiteA…/bridge-c18.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O20 - Winlogon Notify: winyqq32 - winyqq32.dll (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe

Click on Fix Checked when finished and exit HijackThis.


Reboot into Safe Mode: see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders shown DARK and delete them, if still present:

C:\Documents and Settings\Priit\Local Settings\Application Data\a81c1d03.exe

C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe

Please perform a search for the following files shown DARK and delete all instances. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

winyqq32 - winyqq32.dll

Exit Explorer, enable hidden files and reboot.

If you were unable to delete any of the files, then please follow these additional instructions:
Download Pocket Killbox and unzip it; save it to your Desktop.
Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
Let the system reboot.

Please run Hijack This again. Scan and copy the log, then post it into this topic, along with the contents of C:\Look2Me-Destroyer.txt .


Please advise if any problems remain.

Please use the [external image: Posted Image] button to reply.
Thank you for your time and help!
My new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:20:38, on 28.07.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Priit\Desktop\siim\kaitse\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neti.ee/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://amsterdam.rawflow.com/clients/3.1.1.2/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112617393817
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://axis.ivmv.ee/activex/AxisCamControl.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.msngamecentre.co.uk/online2/MSN…aploader_v6.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

And Look2Me text:

Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 28.07.2006 11:13:55

Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0079863.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081867.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081873.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081874.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081880.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081881.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081887.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081888.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081896.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081897.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081903.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081904.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081909.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081910.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081916.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081917.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082147.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082148.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082176.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082177.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083199.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083200.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083221.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083393.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083394.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083415.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083417.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083591.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083592.dll
Infected! C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP429\A0085814.dll

Attempting to delete infected files…

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0079863.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0079863.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081867.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081867.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081873.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081873.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081874.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081874.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081880.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081880.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081881.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081881.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081887.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081887.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081888.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081888.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081896.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081896.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081897.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081897.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081903.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081903.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081904.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081904.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081909.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081909.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081910.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081910.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081916.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081916.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081917.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP411\A0081917.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082147.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082147.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082148.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082148.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082176.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082176.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082177.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0082177.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083199.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083199.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083200.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083200.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083221.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP412\A0083221.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083393.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083393.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083394.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083394.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083415.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083415.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083417.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083417.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083591.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083591.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083592.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP415\A0083592.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP429\A0085814.dll
C:\System Volume Information\_restore{6AF3B6C9-D322-4580-9DCD-3770BB49A992}\RP429\A0085814.dll Deleted successfully!

Making registry repairs.


Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{585EC23F-A08D-43E4-98D2-1553A9895275}"
HKCR\Clsid\{585EC23F-A08D-43E4-98D2-1553A9895275}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{FBDA3477-5F9A-4EC2-964B-CBEB4FF06E2F}"
HKCR\Clsid\{FBDA3477-5F9A-4EC2-964B-CBEB4FF06E2F}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded
Hi maizipulgad. You're welcome.

Are you using the Norton/Symantec firewall, or another ? Please respond to this question, in your followup post.

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below.

Close all windows and browsers, leaving only HijackThis running.

Place a check beside each of these entries listed below, if still present.

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.msngamecentre.co.uk/online2/MSN…aploader_v6.cab

Click on Fix Checked when finished and exit HijackThis.


Please run Hijack This again. Scan and copy the log, then post it into this topic.

Please advise if any problems remain.

Please use the [external image: Posted Image] button to reply.
I think I'm using regular windows firewall.

My latest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 20:31:12, on 28.07.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\BitLord\BitLord.exe
C:\Program Files\Morpheus\Morpheus.exe
C:\Documents and Settings\Priit\Desktop\siim\kaitse\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neti.ee/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitLord\BitLord.exe"
O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://amsterdam.rawflow.com/clients/3.1.1.2/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1112617393817
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://axis.ivmv.ee/activex/AxisCamControl.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi maizipulgad, you're welcome.

If you are not using Norton/Symantec firewall and are using the native MS XP firewall, I suggest you move to a better firewall. Below are a couple of free firewalls, unless you have another in mind. Please download one of these below, or another of your choice, before disabling the MS XP firewall.

Below you will find a link to Zone Alarm, which has a good free firewall for personal use, another for kerio (free for personal use) and a link to sygate. Note that it is not recommended to run two firewalls simultaneously, not even along with the new Microsoft firewall.
http://www.zonelabs.com/store/content/cata…sku_list_za.jsp
http://www.kerio.com/us/kpf_home.html
http://smb.sygate.com/products/spf_pro.htm

Then:
To disable the XP firewall: Control Panel > Internet Options > Connections > Settings > Properties > Advanced…. Remove the check mark from the "Internet Connection Firewall" box and click "OK." Now, install your new firewall, without any further delay and certainly before going onto the internet.


Your Hijack This logfile looks to be clean. However, Hijack This does not see everything and problems can still be present that may not seem to be causing you any difficulties. That is why it is always recommended to on a regular basis run some online Virus scanners and a Trojan scanner, as well as Ad-Aware SE and Spybot S&D. None of these will normally give you any false positives and are safe to run. Other programs of this type are sometimes sold by using scare tactics and giving false positives, to coerce you into purchasing their worthless, sometimes harmful, products.

Please use the following links to run two, or more of these online Virus Scanners on a regular basis and let them fix whatever they find.

If you are using any of the browsers listed just below, the following online Virus scanning site is compatable.
http://be.trendmicro-europe.com/consumer/h…call_launch.php
If you are using any of these browsers:
Microsoft Internet Explorer
Netscape (6+)
Mozilla (1+)
Firefox (all)
Opera (7.5+)

Internet Explorer users can also use the following links.

When using Trend Micro, be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location, so you can delete it yourself.
TrendMicro HouseCall
http://www.kaspersky.com/virusscanner
http://www.kaspersky.co.uk/news.html?id=146100010
Bitdefender and let it delete everything it finds.
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed.

Please reboot when finished.

And here is a link to Ewidos new online Malware/Trojan scanner. As with the Virus scanners above, run this regularly.

Run ewido anti-spyware's online malware scan and perform a full system scan (works only with MS Internet Explorer)
  • Install the ActiveX control when prompted
  • You will see a message that says "Please wait while the signature database is being downloaded…"
  • When the scan is ready to start, you will see a list of options:
    • Cookies
    • Registry
    • Memory
    • A list of your drives
    Leave all the options checked, and click "Start Scan"
    When the scan finishes, if any infections are found, select "Remove Infections", and click OK in the window that pops up.

    The following is very important and should be done at this time.

    One of the best features of Windows XP is the System Restore option, however if Malware infects a computer with this operating system the Malware can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.

    To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

    (winXP)

    1. Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    2. Reboot.

    3. Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.

    Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following free applications:
    • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
    • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.

      Download the new Ad-Aware SE version, and follow the instructions on how to do a full scan: http://forums.spywareinfo.com/index.php?showtopic=11150
      -reboot after using Ad-Aware SE. Also while there get the VX2 plugin and follow the instructions to run it also.
    • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
    To protect yourself further:
      MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
      Google Toolbar <= Get the free google toolbar to help stop pop up windows.

      * Clean your Cache and Cookies in IE:
      Close all instances of Outlook Express and Internet Explorer
      Go to Control Panel > Internet Options > General tab
      Click the "Delete Cookies" button
      Next to it, Click the "Delete Files" button
      When prompted, place a check in: "Delete all offline content", click OK

      * Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):

      Go to Tools > Options.
      Click Privacy in the menu on the left side of the Options window.
      Click the Clear button located to the right of each option (History, Cookies, Cache).
      Click OK to close the Options window
      Alternatively, you can clear all information stored while browsing by clicking Clear All.
      A confirmation dialog box will be shown before clearing the information.
      * Clean other Temporary files + Recycle bin

      Go to start > run and type: cleanmgr and click ok.
      Let it scan your system for files to remove.
      Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
      Press OK to remove them.

      If you are not using an alternate browser to Internet Explorer, I suggest trying the Firefox browser. It is much safer than IE. Be sure to have a look at the Extensions available for it and get those you need, or want.
      Please use the following link to download the Firefox browser.
      http://www.mozilla.org/

      And also see TonyKlein's good advice
      http://castlecops.com/postlite7736-.html
      So how did I get infected in the first place?

      Safe surfing. :wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI