This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hjt log

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was just sitting around on the computer and then all of the sudden a bunch of ad windows popped up and ad icons started being put on my desktop. I ran Adaware and it made things a little bit calmer, but im still getting ad pop-ups.


Logfile of HijackThis v1.99.1
Scan saved at 4:59:02 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\acs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\foiatqqA.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\WINDOWS\system32\zqskw.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
c:\windows\system32\ondsregk.exe
C:\WINDOWS\system32\pwinopez.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\toshiba\ivp\netint\netint.exe
C:\Program Files\DivX\DivX Player\DivX Player.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Randy Jones\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ounjd.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,yqunncv.exe
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Personal Firewall] C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe /waitservice
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [foiatqqA] C:\WINDOWS\foiatqqA.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [EndTask Pro] C:\Program Files\EndTask\EndTask Pro\EndTaskPro.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\ZICORN003.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Randy Jones\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\foiatqq.exe


Thanks in advance for any help
Welcome !! Please take note of the following while we are working together:
  • Your fix may take a couple posts so please be patient even if you don't see immediate results.
  • I will working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's definitely better to be sure and safe than sorry.
***************************************


Please install an antivirus and firewall first, because it doesn't make any sense to remove malware from your system if no scanner is preventing them from reinfecting your computer.

AVG Anti-Virus, Avira OR Avast Home Edition are good FREE antivirus scanners.
After installing ONE antivirus program, download the latest signatures, and do a full system scan.

Without a firewall your computer is susceptible to being hacked and taken over:
Kerio Personal Firewall OR ZoneAlarm are good FREE firewalls.

Read Understanding and using firewalls to learn more about using firewalls

VERY IMPORTANT: Never install more than ONE antivirus scanner and firewall on your system! Several together can give problems and decrease their reliability and effectiveness!

**************************

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.



In your next post, please include
  • new hijackthis log
  • combofix log
*use separate posts to ensure the logs don't get cut off!
Well, first off I went to another forum to see if I would get an answer faster. I did get an answer and they told me to use qoofix.

Although I used the other forum at first, i think ill be patient from now on and just use this one (it looks better to me)

Here is the log from qoofix

Qoofix v1.02 by http://www.malwarebytes.org
Scan started on [7/23/2006] at [7:19:16 PM]
————————————————————-
Terminated module: esvfteh.dll found in Qoofix.exe (2312)
Terminated module: esvfteh.dll found in explorer.exe (1948)
Terminated module: esvfteh.dll found in ounjd.exe (1172)
Terminated module: esvfteh.dll found in xlwfdv.exe (1188)
Terminated module: esvfteh.dll found in ounjd.exe (1368)
Terminated module: esvfteh.dll found in ounjd.exe (1468)
Terminated module: esvfteh.dll found in qttask.exe (180)
Terminated module: esvfteh.dll found in atiptaxx.exe (224)
Terminated module: esvfteh.dll found in SynTPLpr.exe (340)
Terminated module: esvfteh.dll found in SynTPEnh.exe (1140)
Terminated module: esvfteh.dll found in Hotkey.exe (1924)
Terminated module: esvfteh.dll found in PadExe.exe (2056)
Terminated module: esvfteh.dll found in SmoothView.exe (2080)
Terminated module: esvfteh.dll found in NDSTray.exe (2116)
Terminated module: esvfteh.dll found in gcasServ.exe (2224)
Terminated module: esvfteh.dll found in foiatqqA.exe (2352)
Terminated module: esvfteh.dll found in ctfmon.exe (2380)
Terminated module: esvfteh.dll found in Ad-Watch.exe (2436)
Terminated module: esvfteh.dll found in RAMASST.exe (2568)
Terminated module: esvfteh.dll found in gcasDtServ.exe (2972)
Terminated module: esvfteh.dll found in YahooWidgetEngine.exe (3780)
Terminated module: esvfteh.dll found in YahooWidgetEngine.exe (3832)
Terminated module: esvfteh.dll found in pwinopez.exe (2552)
Terminated module: esvfteh.dll found in IEXPLORE.EXE (2496)
Terminated module: esvfteh.dll found in netint.exe (3168)
Terminated module: esvfteh.dll found in Ivpsvmgr.exe (248)
Terminated module: esvfteh.dll found in firefox.exe (1760)
————————————————————-
C:\WINDOWS\system32\djlio.dat will be deleted on reboot!
C:\WINDOWS\system32\esvfteh.dll will be deleted on reboot!
C:\WINDOWS\system32\ounjd.exe will be deleted on reboot!
C:\WINDOWS\system32\xlwfdv.exe will be deleted on reboot!
C:\WINDOWS\system32\yqunncv.exe will be deleted on reboot!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\qsigj.exe will be deleted on reboot!
C:\WINDOWS\unwn.exe will be deleted on reboot!
C:\WINDOWS\system32\dmonwv.dll will be deleted on reboot!

User prompted YES to reboot, system now rebooting…
————————————————————-
Scan COMPLETED SUCCESSFULLY on [7/23/2006] at [7:21:01 PM]

Note: Some registry keys may have been removed.


Sorry for any confusion, I'll stay loyal from now on
Here is the combofix log Start Time= Sun 07/23/2006 20:40:16.93 Running from: C:\Documents and Settings\[removed]\Desktop (((((((((((((((((((((((((((((((((((((((((((((((( Ssk's Log ))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\repairs303169590.dll C:\Documents and Settings\Randy Jones\Application Data\Sskknwrd.dll C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Ssk.log C:\Program Files\SurfSideKick 3\Ssk.exe C:\Program Files\SurfSideKick 3\SskBho.dll C:\Program Files\SurfSideKick 3\SskCore.dll * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * 20:42:18.98 (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\drsmartload.exe C:\drsmartload1.exe C:\drsmartload45a7e.exe C:\drsmartload46a7e.exe C:\drsmartload849a7e.exe C:\dfndred_7.exe C:\nwnmed_7.exe C:\kybrded_7.exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\762F35RA\kybrded_7[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\B3D7VP8K\drsmartload45a[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\B3D7VP8K\dfndred_7[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\B3D7VP8K\nwnmed_7[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\CFEPELOV\drsmartload[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\GCE8EJTX\drsmartload849a[1].exe C:\Documents and Settings\Randy Jones\Local Settings\Temporary Internet Files\Content.IE5\YVX1LME8\drsmartload46a[1].exe C:\WINDOWS\newname.dat C:\WINDOWS\keyboard1.dat C:\WINDOWS\uninstall_nmon.vbs C:\WINDOWS\system32\atmtd.dll.tmp C:\Documents and Settings\LocalService\Application Data\NetMon (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-07-23 20:42 467,914,752 C:\hiberfil.sys 2006-07-23 20:39 C:\Program Files\mozilla firefox 2006-07-23 20:39 C:\Program Files\microsoft antispyware 2006-07-23 20:15 116 C:\WINDOWS\nerodigital.ini 2006-07-23 18:40 386 C:\WINDOWS\whdmt.dll 2006-07-23 16:27 924 C:\WINDOWS\system32\nt68rrtc12.sys 2006-07-23 16:26 45,076 C:\WINDOWS\system32\ondsregk.exe 2006-07-23 16:10 1,063 C:\WINDOWS\system32\yxwe02b1.sys 2006-07-23 16:08 C:\Program Files\common files 2006-07-23 15:59 69,632 C:\WINDOWS\system32\gjemekoj.dll 2006-07-23 15:59 38,412 C:\WINDOWS\ssqbn.exe 2006-07-23 15:59 33,012 C:\WINDOWS\system32\tpuninstall.exe 2006-07-23 15:59 1,057 C:\WINDOWS\system32\w01e02b0.ini 2006-07-23 15:59 0 C:\Documents and Settings\Randy Jones\Application Data\internaldb41.dat 2006-07-23 15:59 C:\Program Files\windows nt 2006-07-23 15:59 C:\Program Files\windows media player 2006-07-23 15:59 C:\Program Files\messenger 2006-07-23 15:59 C:\Program Files\batty 2006-07-23 15:58 69,632 C:\WINDOWS\system32\plpfciki.dll 2006-07-23 15:58 61,440 C:\WINDOWS\system32\yxwe02b1.dll 2006-07-23 15:58 51,712 C:\WINDOWS\system32\w00963de.dll 2006-07-23 15:58 51,712 C:\WINDOWS\system32\w00962a6.dll 2006-07-23 15:58 48,167 C:\WINDOWS\system32\vsl05.exe 2006-07-23 15:58 45,090 C:\WINDOWS\system32\dwdsregt.exe 2006-07-23 15:58 45,068 C:\WINDOWS\system32\zicorn003.exe 2006-07-23 15:58 389,632 C:\webnexmknew.exe 2006-07-23 15:58 32,976 C:\WINDOWS\system32\uninsticn.exe 2006-07-23 15:58 29,696 C:\WINDOWS\system32\w009449e.dll 2006-07-23 15:58 27,648 C:\dist13.exe 2006-07-23 15:58 235,134 C:\WINDOWS\srvgdlcgjv.exe 2006-07-23 15:58 20,480 C:\stub_sca3.exe 2006-07-23 15:58 184,829 C:\WINDOWS\srvjnfpykg.exe 2006-07-23 15:58 159,874 C:\WINDOWS\system32\pwinopez.exe 2006-07-23 15:58 159,744 C:\WINDOWS\system32\redist.dll 2006-07-23 15:58 143,360 C:\WINDOWS\ms0639300-12626.exe 2006-07-23 15:58 126,464 C:\WINDOWS\system32\redistributor.exe 2006-07-23 15:58 111,104 C:\numbsoftnew.exe 2006-07-23 15:58 C:\Program Files\pshope 2006-07-23 15:58 C:\Program Files\cas2stub 2006-07-23 15:57 57,344 C:\fym9bvo.exe 2006-07-23 15:57 467,968 C:\visfx500new.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32n9nyb.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32\n9nyb.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\iqqr.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\bez6n4r21.exe 2006-07-23 15:57 232,749 C:\WINDOWS\pf78.exe 2006-07-23 15:57 221,184 C:\WINDOWS\system32\xeymi.dll 2006-07-23 15:57 0 C:\WINDOWS\system32bez6n4r21.exe 2006-07-23 15:52 749 C:\WINDOWS\win.ini 2006-07-23 15:52 C:\Program Files\microsoft office 2006-07-23 15:52 C:\Program Files\Common Files\system 2006-07-23 15:52 C:\Program Files\Common Files\microsoft shared 2006-07-23 15:52 C:\Program Files\Common Files\designer 2006-07-23 15:38 C:\Documents and Settings\Randy Jones\Application Data\utorrent 2006-07-23 12:28 C:\Program Files\trillian 2006-07-22 16:57 C:\Program Files\winamp 2006-07-22 16:55 C:\Program Files\google 2006-07-22 16:32 C:\Program Files\yahoo! 2006-07-22 03:36 7,516 C:\Documents and Settings\Randy Jones\Application Data\wklnhst.dat 2006-07-22 00:37 C:\Program Files\divx 2006-07-21 23:02 C:\Program Files\ipod 2006-07-21 23:02 C:\Program Files\installshield installation information 2006-07-21 23:01 C:\Program Files\gaim 2006-07-20 16:31 36,864 C:\WINDOWS\system32\zqskw.exe 2006-07-20 16:31 1,163,264 C:\WINDOWS\system32\wfxqhv.exe 2006-07-20 16:30 159,744 C:\WINDOWS\system32\cvn0.exe 2006-07-13 03:26 441,626 C:\WINDOWS\system32\perfstringbackup.ini 2006-07-11 00:30 C:\Program Files\microsoft works 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx0c.dll 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx07.dll 2006-07-03 17:40 761,856 C:\WINDOWS\system32\divx_xx11.dll 2006-07-03 17:40 620,180 C:\WINDOWS\system32\divx.dll 2006-06-29 10:07 61,440 C:\WINDOWS\system32\battyrun.dll 2006-06-23 11:22 9,216 C:\WINDOWS\sfctidscgq.dll 2006-06-21 06:49 53,248 C:\WINDOWS\system32\dpugui10.dll 2006-06-21 06:43 520,192 C:\WINDOWS\system32\divxsm.exe 2006-06-21 06:43 3,596,288 C:\WINDOWS\system32\qt-dx331.dll 2006-06-21 06:42 200,704 C:\WINDOWS\system32\ssldivx.dll 2006-06-21 06:42 1,044,480 C:\WINDOWS\system32\libdivx.dll 2006-06-21 06:34 90,112 C:\WINDOWS\system32\dpl100.dll 2006-06-21 06:34 593,920 C:\WINDOWS\system32\dpugui11.dll 2006-06-21 06:34 57,344 C:\WINDOWS\system32\dpv11.dll 2006-06-21 06:34 344,064 C:\WINDOWS\system32\dpus11.dll 2006-06-21 06:34 294,912 C:\WINDOWS\system32\dpu11.dll 2006-06-21 06:34 294,912 C:\WINDOWS\system32\dpu10.dll 2006-06-21 06:34 200,704 C:\WINDOWS\system32\dtu100.dll 2006-06-21 06:33 12,288 C:\WINDOWS\system32\divxwmpexttype.dll 2006-06-21 06:33 118,784 C:\WINDOWS\system32\divxcodecupdatechecker.exe 2006-06-20 20:55 389,120 C:\WINDOWS\system32\nodeipproc.dll 2006-06-20 01:04 C:\Program Files\internet explorer 2006-06-09 01:39 C:\Program Files\limewire 2006-06-04 21:08 C:\Program Files\quicktime 2006-05-31 22:31 424 C:\WINDOWS\lexstat.ini 2006-05-23 08:49 C:\Program Files\morpheus 2006-05-19 08:59 94,720 C:\WINDOWS\system32\iphlpapi.dll 2006-05-19 08:59 148,480 C:\WINDOWS\system32\dnsapi.dll 2006-05-19 08:59 111,616 C:\WINDOWS\system32\dhcpcsvc.dll 2006-05-15 18:19 272 C:\WINDOWS\_delis32.ini (((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))) 2006-07-23 16:27 924 C:\WINDOWS\system32\nt68rrtc12.sys 2006-07-23 16:26 45,076 C:\WINDOWS\system32\ondsregk.exe 2006-07-23 15:59 69,632 C:\WINDOWS\system32\gjemekoj.dll 2006-07-23 15:59 38,412 C:\WINDOWS\ssqbn.exe 2006-07-23 15:59 1,057 C:\WINDOWS\system32\w01e02b0.ini 2006-07-23 15:58 69,632 C:\WINDOWS\system32\plpfciki.dll 2006-07-23 15:58 61,440 C:\WINDOWS\system32\yxwe02b1.dll 2006-07-23 15:58 587,776 C:\626_101newer.exe 2006-07-23 15:58 51,712 C:\WINDOWS\system32\w00963de.dll 2006-07-23 15:58 51,712 C:\WINDOWS\system32\w00962a6.dll 2006-07-23 15:58 48,167 C:\WINDOWS\system32\VSL05.exe 2006-07-23 15:58 45,090 C:\WINDOWS\system32\dwdsregt.exe 2006-07-23 15:58 45,068 C:\WINDOWS\system32\ZICORN003.exe 2006-07-23 15:58 389,632 C:\webnexmknew.exe 2006-07-23 15:58 386 C:\WINDOWS\whdmt.dll 2006-07-23 15:58 33,012 C:\WINDOWS\system32\tpuninstall.exe 2006-07-23 15:58 32,976 C:\WINDOWS\system32\uninstIcn.exe 2006-07-23 15:58 29,696 C:\WINDOWS\system32\w009449e.dll 2006-07-23 15:58 27,648 C:\dist13.exe 2006-07-23 15:58 235,134 C:\WINDOWS\srvgdlcgjv.exe 2006-07-23 15:58 20,480 C:\stub_sca3.exe 2006-07-23 15:58 2,560 C:\ac3_0003.exe 2006-07-23 15:58 184,829 C:\WINDOWS\srvjnfpykg.exe 2006-07-23 15:58 159,874 C:\WINDOWS\system32\pwinopez.exe 2006-07-23 15:58 159,744 C:\WINDOWS\system32\redist.dll 2006-07-23 15:58 143,360 C:\WINDOWS\ms0639300-12626.exe 2006-07-23 15:58 126,464 C:\WINDOWS\system32\redistributor.exe 2006-07-23 15:58 111,104 C:\numbsoftnew.exe 2006-07-23 15:58 1,063 C:\WINDOWS\system32\yxwe02b1.sys 2006-07-23 15:57 683,728 C:\WINDOWS\foiatqq.exe 2006-07-23 15:57 644,304 C:\WINDOWS\foiatqqA.exe 2006-07-23 15:57 57,344 C:\fym9bvo.exe 2006-07-23 15:57 467,968 C:\visfx500new.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32n9nyb.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32\zqskw.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32\n9nyb.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\iqqr.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\bez6n4r21.exe 2006-07-23 15:57 232,749 C:\WINDOWS\pf78.exe 2006-07-23 15:57 221,184 C:\WINDOWS\system32\xeymi.dll 2006-07-23 15:57 21,504 C:\WINDOWS\offun.exe 2006-07-23 15:57 159,744 C:\WINDOWS\system32\cvn0.exe 2006-07-23 15:57 1,163,264 C:\WINDOWS\system32\wfxqhv.exe 2006-07-23 15:57 0 C:\WINDOWS\system32bez6n4r21.exe 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx0c.dll 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx07.dll 2006-07-03 17:40 761,856 C:\WINDOWS\system32\divx_xx11.dll 2006-07-03 17:40 620,180 C:\WINDOWS\system32\DivX.dll 2006-06-29 10:07 61,440 C:\WINDOWS\system32\BattyRun.dll 2006-06-23 11:22 9,216 C:\WINDOWS\sfctidscgq.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\"" "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe" "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "Toshiba Hotkey Utility"="\"c:\\Program Files\\Toshiba\\Windows Utilities\\Hotkey.exe\" /lang en" "PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe" "SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe" "NDSTray.exe"="NDSTray.exe" "Pinger"="c:\\toshiba\\ivp\\ism\\pinger.exe /run" "drsmartloadb"="c:\\\\drsmartloadb.exe" "Notebook Maximizer"="C:\\Program Files\\Notebook Maximizer\\maximizer_startup.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\"" "Personal Firewall"="C:\\Program Files\\Lavasoft\\Personal Firewall\\lpfw.exe /waitservice" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "k6mmN5IOU"="\"C:\\WINDOWS\\system32\\wfxqhv.exe\"" "BrowserUpdateSched"="C:\\WINDOWS\\system32\\pwinopez.exe CORN003" "foiatqqA"="C:\\WINDOWS\\foiatqqA.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "AWMON"="\"C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\Ad-Watch.exe\"" "EndTask Pro"="C:\\Program Files\\EndTask\\EndTask Pro\\EndTaskPro.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex] "flags"=dword:00000008 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000] [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="C:\\Program Files\\Windows Media Player\\kyzeqe.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] "Source"="C:\\Program Files\\Messenger\\howynyka.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\ 00,00,01,00,00,00 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "miiu"="C:\\Program Files\\Common Files\\miiu\\miium.exe" "Rcjvlrwx"="C:\\WINDOWS\\system32\\??crosoft.NET\\chkntfs.exe" [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "smlrpo"="" "POSTRBT"="" [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "miiu"="C:\\Program Files\\Common Files\\miiu\\miium.exe" "Rcjvlrwx"="C:\\WINDOWS\\system32\\??crosoft.NET\\chkntfs.exe" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce] "smlrpo"="" "POSTRBT"="" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{9EF34FF2-3396-4527-9D27-04C8C1C67806}"="Microsoft AntiSpyware Service Hook" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Randy Jones^Start Menu^Programs^Startup^LimeWire On Startup.lnk] "path"="C:\\Documents and Settings\\Randy Jones\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk" "backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup" "item"="LimeWire On Startup" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="realsched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "inimapping"="0" Contents of the 'Scheduled Tasks' folder Completion time: Sun 07/23/2006 20:42:25.79 ComboFix ver 06.07.22 - This logfile is located at C:\ComboFix.txt ComboFix.txt ComboFix2.txt
Hi, thanks for the qoofix log; but its not one of the ones i requested ;) If you want to continue here, please close your thread at the other forum as a courtesy to the other helper and myself. Please follow the instructions in my first post and post the requested logs. thanks,
The uninstall list: AC97 Data Fax SoftModem with SmartCP Ad-Aware SE Professional Adobe Acrobat 5.0 Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player 9 ActiveX Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Stock Photos 1.0 America Online (Choose which version to remove) ArcSoft Software Suite Atheros Client Utility Atheros Wireless LAN MiniPCI card Driver ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver AutoCAD 2006 - English Autodesk DWF Viewer CCleaner (remove only) CD/DVD Drive Acoustic Silencer Conexant AC-Link Audio DivX DivX Converter DivX Player DivX Web Player DVD-RAM Driver Enhanced Ads by Zeno removal Forethought GTK+ Runtime 2.6.9 rev a (remove only) Higher Score on the New SAT 1.0 HijackThis 1.99.1 Hotfix for Windows XP (KB894871) Hotfix for Windows XP (KB895200) Icons InterVideo WinDVD for TOSHIBA J2SE Runtime Environment 5.0 Update 2 Learn2 Player (Uninstall Only) Lexmark X5100 Series Logitech QuickCam Software Macromedia Shockwave Player Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft AntiSpyware Microsoft Works Mozilla Firefox ([removed]) MSN Messenger 7.5 Nero 6 Demo Notebook Maximizer Quicken 2005 Quicklinks QuickTime QuickTime 3.0 REALTEK Gigabit and Fast Ethernet NIC Driver RelevantKnowledge Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Spybot - Search & Destroy 1.4 Surf SideKick Synaptics Pointing Device Driver TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA PC Diagnostic Tool Toshiba Q4 Retail Demo ScreenSaver Toshiba Registration TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 Toshiba Tbiosdrv Driver Toshiba Touchpad Utility Toshiba Utility TOSHIBA Zooming Utility Touch and Launch TrillPack v3.1 Final build 2 (remove only) Undisker Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Viewpoint Media Player Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows Overlay Components Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB884018 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893056 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Yahoo! Central Yahoo! Widget Engine Yahoo! Widget Engine Zeno Search Assistant removal
And my latest Hjt:

Logfile of HijackThis v1.99.1
Scan saved at 8:46:57 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\foiatqq.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\system32\zqskw.exe
C:\WINDOWS\foiatqqA.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
c:\windows\system32\ondsregk.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\pwinopez.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Randy Jones\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Personal Firewall] C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinopez.exe CORN003
O4 - HKLM\..\Run: [foiatqqA] C:\WINDOWS\foiatqqA.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [EndTask Pro] C:\Program Files\EndTask\EndTask Pro\EndTaskPro.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinopez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\ZICORN003.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Randy Jones\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\foiatqq.exe
I don't know if you missed this:

If you want to continue here, please close your thread at the other forum as a courtesy to the other helper and myself.


Please install an antivirus and firewall first, because it doesn't make any sense to remove malware from your system if no scanner is preventing them from reinfecting your computer.

AVG Anti-Virus, Avira OR Avast Home Edition are good FREE antivirus scanners.
After installing ONE antivirus program, download the latest signatures, and do a full system scan.

Without a firewall your computer is susceptible to being hacked and taken over:
Kerio Personal Firewall OR ZoneAlarm are good FREE firewalls.

Read Understanding and using firewalls to learn more about using firewalls

VERY IMPORTANT: Never install more than ONE antivirus scanner and firewall on your system! Several together can give problems and decrease their reliability and effectiveness!

then reboot, and post a new hijackthis log.
Ok, I did everything you asked for. Here is my latest Hjt:

Logfile of HijackThis v1.99.1
Scan saved at 9:25:43 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\zqskw.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
c:\windows\system32\ondsregk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\WINDOWS\system32\pwinopez.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Randy Jones\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "c:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang en
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
O4 - HKLM\..\Run: [Notebook Maximizer] C:\Program Files\Notebook Maximizer\maximizer_startup.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Personal Firewall] C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [EndTask Pro] C:\Program Files\EndTask\EndTask Pro\EndTaskPro.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinopez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\ZICORN003.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…arch.jhtml?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Randy Jones\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\foiatqq.exe (file missing)
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


Please remove these entries from Add or Remove Programs in the Control Panel(if present):

Enhanced Ads by Zeno removal
Forethought
Quicklinks
RelevantKnowledge
Surf SideKick
Viewpoint Media Player
Windows Overlay Components
Zeno Search Assistant removal

Please note any other programs that you dont recognize in that list in your next response

(an easy way to get to Add or Remove programs is to go to start–>run and type appwiz.cpl)

***************************************

Please download Ewido to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install Ewido by double clicking the installer.
  • Follow the prompts. Make sure that Launch Ewido is checked.
  • On the main screen under Your Computer's security.
  • Click on Change state next to Resident shield. It should now change to inactive.
  • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
  • Wait until you see the Update succesfull message.
    Note: If the Update now option is grayed out, follow the steps below.
  • Click on Update on the toolbar.
  • Under Manual update, click on the Start Update button.
  • Wait until you see the Update succesfull message.
[*]Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.

Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

***************************************

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml

***************************************

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Then, Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
***************************************

reboot your system back into Normal Mode

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
then run combofix for me one more time and post the log

in your next post, please include
  • new hijackthis log
  • ewido log
  • panda log
  • combofix log
Your may need several replies to post the requested logs, otherwise they might get cut off.
I'm going through the add/remove programs right now and I see something called "Icons" I dont know what it is, do you think it would be ok to remove?
I tried to run ewido 3 times in safe mode, and all three were failures. Here are the other logs though Combofix: Start Time= Mon 07/24/2006 0:24:39.09 Running from: C:\Documents and Settings\[removed]\Desktop\Computer Fix Stuff (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-07-24 00:13 C:\Program Files\quicktime 2006-07-24 00:13 C:\Program Files\msn messenger 2006-07-24 00:13 C:\Program Files\mozilla firefox 2006-07-24 00:12 C:\Program Files\microsoft antispyware 2006-07-24 00:11 C:\Program Files\internet explorer 2006-07-24 00:11 C:\Program Files\ewido anti-spyware 4.0 2006-07-24 00:10 C:\Program Files\Common Files\autodesk shared 2006-07-24 00:06 C:\Program Files\trillian 2006-07-23 23:59 808 C:\WINDOWS\win.ini 2006-07-23 23:50 467,914,752 C:\hiberfil.sys 2006-07-23 22:12 425 C:\WINDOWS\lexstat.ini 2006-07-23 21:43 116 C:\WINDOWS\nerodigital.ini 2006-07-23 21:13 C:\Program Files\windows nt 2006-07-23 20:58 C:\Program Files\zone labs 2006-07-23 20:50 776,096 C:\WINDOWS\system32\drivers\avg7core.sys 2006-07-23 20:50 4,992 C:\WINDOWS\system32\drivers\avgtdi.sys 2006-07-23 20:50 4,288 C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-07-23 20:50 27,776 C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-07-23 20:50 23,424 C:\WINDOWS\system32\drivers\avgmfrs.sys 2006-07-23 20:50 C:\Program Files\grisoft 2006-07-23 20:50 C:\Documents and Settings\Randy Jones\Application Data\avg7 2006-07-23 18:40 386 C:\WINDOWS\whdmt.dll 2006-07-23 16:27 924 C:\WINDOWS\system32\nt68rrtc12.sys 2006-07-23 16:10 1,063 C:\WINDOWS\system32\yxwe02b1.sys 2006-07-23 16:08 C:\Program Files\common files 2006-07-23 15:59 69,632 C:\WINDOWS\system32\gjemekoj.dll 2006-07-23 15:59 33,012 C:\WINDOWS\system32\tpuninstall.exe 2006-07-23 15:59 1,057 C:\WINDOWS\system32\w01e02b0.ini 2006-07-23 15:59 0 C:\Documents and Settings\Randy Jones\Application Data\internaldb41.dat 2006-07-23 15:59 C:\Program Files\windows media player 2006-07-23 15:59 C:\Program Files\messenger 2006-07-23 15:59 C:\Program Files\batty 2006-07-23 15:58 69,632 C:\WINDOWS\system32\plpfciki.dll 2006-07-23 15:58 61,440 C:\WINDOWS\system32\yxwe02b1.dll 2006-07-23 15:58 48,167 C:\WINDOWS\system32\vsl05.exe 2006-07-23 15:58 29,696 C:\WINDOWS\system32\w009449e.dll 2006-07-23 15:58 235,134 C:\WINDOWS\srvgdlcgjv.exe 2006-07-23 15:58 20,480 C:\stub_sca3.exe 2006-07-23 15:58 184,829 C:\WINDOWS\srvjnfpykg.exe 2006-07-23 15:58 C:\Program Files\pshope 2006-07-23 15:57 36,864 C:\WINDOWS\system32n9nyb.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32\n9nyb.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\iqqr.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\bez6n4r21.exe 2006-07-23 15:57 232,749 C:\WINDOWS\pf78.exe 2006-07-23 15:57 0 C:\WINDOWS\system32bez6n4r21.exe 2006-07-23 15:52 C:\Program Files\microsoft office 2006-07-23 15:52 C:\Program Files\Common Files\system 2006-07-23 15:52 C:\Program Files\Common Files\microsoft shared 2006-07-23 15:52 C:\Program Files\Common Files\designer 2006-07-23 15:38 C:\Documents and Settings\Randy Jones\Application Data\utorrent 2006-07-22 16:57 C:\Program Files\winamp 2006-07-22 16:55 C:\Program Files\google 2006-07-22 16:32 C:\Program Files\yahoo! 2006-07-22 03:36 7,516 C:\Documents and Settings\Randy Jones\Application Data\wklnhst.dat 2006-07-22 00:37 C:\Program Files\divx 2006-07-21 23:02 C:\Program Files\ipod 2006-07-21 23:02 C:\Program Files\installshield installation information 2006-07-21 23:01 C:\Program Files\gaim 2006-07-13 03:26 441,626 C:\WINDOWS\system32\perfstringbackup.ini 2006-07-11 00:30 C:\Program Files\microsoft works 2006-07-09 13:42 83,960 C:\WINDOWS\system32\zlcomm.dll 2006-07-09 13:42 83,960 C:\WINDOWS\system32\vsdata.dll 2006-07-09 13:42 71,672 C:\WINDOWS\system32\zlcommdb.dll 2006-07-09 13:42 71,672 C:\WINDOWS\system32\vsregexp.dll 2006-07-09 13:42 59,384 C:\WINDOWS\system32\vswmi.dll 2006-07-09 13:42 440,312 C:\WINDOWS\system32\vsutil.dll 2006-07-09 13:42 392,824 C:\WINDOWS\system32\vsdatant.sys 2006-07-09 13:42 268,280 C:\WINDOWS\system32\vspubapi.dll 2006-07-09 13:42 157,688 C:\WINDOWS\system32\vsinit.dll 2006-07-09 13:42 104,440 C:\WINDOWS\system32\vsmonapi.dll 2006-07-09 13:42 100,344 C:\WINDOWS\system32\vsxml.dll 2006-07-09 13:41 796,584 C:\WINDOWS\system32\libeay32_0.9.6l.dll 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx0c.dll 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx07.dll 2006-07-03 17:40 761,856 C:\WINDOWS\system32\divx_xx11.dll 2006-07-03 17:40 620,180 C:\WINDOWS\system32\divx.dll 2006-06-29 10:07 61,440 C:\WINDOWS\system32\battyrun.dll 2006-06-21 06:49 53,248 C:\WINDOWS\system32\dpugui10.dll 2006-06-21 06:43 520,192 C:\WINDOWS\system32\divxsm.exe 2006-06-21 06:43 3,596,288 C:\WINDOWS\system32\qt-dx331.dll 2006-06-21 06:42 200,704 C:\WINDOWS\system32\ssldivx.dll 2006-06-21 06:42 1,044,480 C:\WINDOWS\system32\libdivx.dll 2006-06-21 06:34 90,112 C:\WINDOWS\system32\dpl100.dll 2006-06-21 06:34 593,920 C:\WINDOWS\system32\dpugui11.dll 2006-06-21 06:34 57,344 C:\WINDOWS\system32\dpv11.dll 2006-06-21 06:34 344,064 C:\WINDOWS\system32\dpus11.dll 2006-06-21 06:34 294,912 C:\WINDOWS\system32\dpu11.dll 2006-06-21 06:34 294,912 C:\WINDOWS\system32\dpu10.dll 2006-06-21 06:34 200,704 C:\WINDOWS\system32\dtu100.dll 2006-06-21 06:33 12,288 C:\WINDOWS\system32\divxwmpexttype.dll 2006-06-21 06:33 118,784 C:\WINDOWS\system32\divxcodecupdatechecker.exe 2006-06-09 01:39 C:\Program Files\limewire 2006-05-19 08:59 94,720 C:\WINDOWS\system32\iphlpapi.dll 2006-05-19 08:59 148,480 C:\WINDOWS\system32\dnsapi.dll 2006-05-19 08:59 111,616 C:\WINDOWS\system32\dhcpcsvc.dll 2006-05-15 18:19 272 C:\WINDOWS\_delis32.ini (((((((((((((((((((((((((((((((((((((( Files Created - Last 30days ))))))))))))))))))))))))))))))))))))))))))) 2006-07-23 23:57 73,728 C:\WINDOWS\system32\asuninst.exe 2006-07-23 23:57 11,776 C:\WINDOWS\system32\ZPORT4AS.dll 2006-07-23 23:50 467,914,752 C:\hiberfil.sys 2006-07-23 21:17 83,960 C:\WINDOWS\system32\zlcomm.dll 2006-07-23 21:17 796,584 C:\WINDOWS\system32\libeay32_0.9.6l.dll 2006-07-23 21:17 71,672 C:\WINDOWS\system32\zlcommdb.dll 2006-07-23 21:17 71,672 C:\WINDOWS\system32\vsregexp.dll 2006-07-23 21:17 59,384 C:\WINDOWS\system32\vswmi.dll 2006-07-23 21:17 392,824 C:\WINDOWS\system32\vsdatant.sys 2006-07-23 21:17 268,280 C:\WINDOWS\system32\vspubapi.dll 2006-07-23 21:17 104,440 C:\WINDOWS\system32\vsmonapi.dll 2006-07-23 21:17 100,344 C:\WINDOWS\system32\vsxml.dll 2006-07-23 21:16 83,960 C:\WINDOWS\system32\vsdata.dll 2006-07-23 21:16 440,312 C:\WINDOWS\system32\vsutil.dll 2006-07-23 21:16 157,688 C:\WINDOWS\system32\vsinit.dll 2006-07-23 16:27 924 C:\WINDOWS\system32\nt68rrtc12.sys 2006-07-23 15:59 69,632 C:\WINDOWS\system32\gjemekoj.dll 2006-07-23 15:59 1,057 C:\WINDOWS\system32\w01e02b0.ini 2006-07-23 15:58 69,632 C:\WINDOWS\system32\plpfciki.dll 2006-07-23 15:58 61,440 C:\WINDOWS\system32\yxwe02b1.dll 2006-07-23 15:58 48,167 C:\WINDOWS\system32\VSL05.exe 2006-07-23 15:58 386 C:\WINDOWS\whdmt.dll 2006-07-23 15:58 33,012 C:\WINDOWS\system32\tpuninstall.exe 2006-07-23 15:58 29,696 C:\WINDOWS\system32\w009449e.dll 2006-07-23 15:58 235,134 C:\WINDOWS\srvgdlcgjv.exe 2006-07-23 15:58 20,480 C:\stub_sca3.exe 2006-07-23 15:58 184,829 C:\WINDOWS\srvjnfpykg.exe 2006-07-23 15:58 1,063 C:\WINDOWS\system32\yxwe02b1.sys 2006-07-23 15:57 57,344 C:\fym9bvo.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32n9nyb.exe 2006-07-23 15:57 36,864 C:\WINDOWS\system32\n9nyb.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\iqqr.exe 2006-07-23 15:57 28,672 C:\WINDOWS\system32\bez6n4r21.exe 2006-07-23 15:57 232,749 C:\WINDOWS\pf78.exe 2006-07-23 15:57 0 C:\WINDOWS\system32bez6n4r21.exe 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx0c.dll 2006-07-03 17:40 778,240 C:\WINDOWS\system32\divx_xx07.dll 2006-07-03 17:40 761,856 C:\WINDOWS\system32\divx_xx11.dll 2006-07-03 17:40 620,180 C:\WINDOWS\system32\DivX.dll 2006-06-29 10:07 61,440 C:\WINDOWS\system32\BattyRun.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\"" "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe" "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe" "Toshiba Hotkey Utility"="\"c:\\Program Files\\Toshiba\\Windows Utilities\\Hotkey.exe\" /lang en" "PadTouch"="C:\\Program Files\\TOSHIBA\\Touch and Launch\\PadExe.exe" "SmoothView"="C:\\Program Files\\TOSHIBA\\TOSHIBA Zooming Utility\\SmoothView.exe" "NDSTray.exe"="NDSTray.exe" "Pinger"="c:\\toshiba\\ivp\\ism\\pinger.exe /run" "drsmartloadb"="c:\\\\drsmartloadb.exe" "Notebook Maximizer"="C:\\Program Files\\Notebook Maximizer\\maximizer_startup.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "gcasServ"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\"" "Personal Firewall"="C:\\Program Files\\Lavasoft\\Personal Firewall\\lpfw.exe /waitservice" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "VSOCheckTask"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcmnhdlr.exe\" /checktask" "VirusScan Online"="\"c:\\PROGRA~1\\mcafee.com\\vso\\mcvsshld.exe\"" "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe" "MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe" "MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskDetct.exe /startup" "McRegWiz"="C:\\PROGRA~1\\McAfee.com\\Agent\\mcregwiz.exe /autorun" "New.net Startup"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~1.DLL,NewDotNetStartup -s" "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "AWMON"="\"C:\\PROGRA~1\\Lavasoft\\AD-AWA~1\\Ad-Watch.exe\"" "EndTask Pro"="C:\\Program Files\\EndTask\\EndTask Pro\\EndTaskPro.exe" "SurfSideKick 3"="C:\\Program Files\\SurfSideKick 3\\Ssk.exe" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="C:\\Program Files\\Windows Media Player\\kyzeqe.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=dword:40000001 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] "Source"="C:\\Program Files\\Messenger\\howynyka.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=dword:40000001 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,00 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,ec,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=dword:40000004 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\ 00,00,01,00,00,00 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "miiu"="C:\\Program Files\\Common Files\\miiu\\miium.exe" "Rcjvlrwx"="C:\\WINDOWS\\system32\\??crosoft.NET\\chkntfs.exe" "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "smlrpo"="" "POSTRBT"="" [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "miiu"="C:\\Program Files\\Common Files\\miiu\\miium.exe" "Rcjvlrwx"="C:\\WINDOWS\\system32\\??crosoft.NET\\chkntfs.exe" "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce] "smlrpo"="" "POSTRBT"="" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{9EF34FF2-3396-4527-9D27-04C8C1C67806}"="Microsoft AntiSpyware Service Hook" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Randy Jones^Start Menu^Programs^Startup^LimeWire On Startup.lnk] "path"="C:\\Documents and Settings\\Randy Jones\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk" "backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup" "location"="Startup" "command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup" "item"="LimeWire On Startup" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="realsched" "hkey"="HKLM" "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "inimapping"="0" Contents of the 'Scheduled Tasks' folder Completion time: Mon 07/24/2006 0:25:00.81 ComboFix ver 06.07.22 - This logfile is located at C:\ComboFix.txt ComboFix.txt ComboFix2.txt ComboFix3.txt
Activescan: Incident Status Location Adware:Adware/PurityScan Not disinfected c:\windows\system32\??crosoft.net\chkntfs.exe Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\RICHED20.dll Potentially unwanted tool:application/sysprotect Not disinfected c:\windows\system32\drivers\sscan.sys Spyware:spyware/virtumonde Not disinfected c:\windows\system32\ddaya.dll Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr Adware:adware program Not disinfected c:\windows\system32\key.~ Spyware:spyware/marketscore Not disinfected c:\windows\system32\rk.bin Potentially unwanted tool:application/winfixer2005 Not disinfected c:\windows\downloaded program files\USYP_0001_N69M1703NetInstaller.exe Adware:adware/dollarrevenue Not disinfected c:\windows\gimmygames1.dat Adware:adware/whenusearch Not disinfected C:\Documents and Settings\Randy Jones\Start Menu\Programs\WhenU Adware:adware/wupd Not disinfected c:\program files\MediaGateway Potentially unwanted tool:application/winantivirus2006 Not disinfected c:\documents and settings\all users\application data\WinAntiVirus Pro 2006 Adware:adware/commad Not disinfected Windows Registry Adware:adware/popper Not disinfected Windows Registry Potentially unwanted tool:application/seekmo Not disinfected hkey_local_machine\software\seekmo Adware:adware/yazzlesudoku Not disinfected Windows Registry Potentially unwanted tool:application/funweb Not disinfected hkey_classes_root\clsid\{00A6FAF6-072E-44cf-8957-5838F569A31D} Spyware:spyware/new.net Not disinfected Windows Registry Spyware:spyware/surfsidekick Not disinfected Windows Registry Adware:adware/cws.aboutblank Not disinfected Windows Registry Adware:adware/searchresults Not disinfected Windows Registry Adware:adware/searchexe Not disinfected Windows Registry Adware:adware/xplugin Not disinfected Windows Registry Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.adrevolver.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\yubs1m6q.default\cookies.txt[.z1.adserver.com/] Spyware:Cookie/Allthatsearch Not disinfected C:\Documents and Settings\LocalService\Cookies\system@10102[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][2].txt Spyware:Cookie/aff504 Not disinfected C:\Documents and Settings\LocalService\Cookies\system@aff504[1].txt Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\LocalService\Cookies\system@burstnet[2].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\LocalService\Cookies\system@errorsafe[1].txt Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\LocalService\Cookies\system@paypopup[2].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\LocalService\Cookies\[removed][1].txt Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\LocalService\Start Menu\Programs\UCmore - The Search Accelerator\How To Uninstall.lnk Adware:Adware/Ucmore Not disinfected C:\Documents and Settings\LocalService\Start Menu\Programs\UCmore - The Search Accelerator\UCmore Tour.lnk Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.perf.overture.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.overture.com/] Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.clickbank.net/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.statcounter.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fastclick.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.revenue.net/] Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ads.addynamix.com/] Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.as-us.falkag.net/] Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.as-eu.falkag.net/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.2o7.net/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.findwhat.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[servedby.advertising.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.advertising.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[servedby.advertising.com/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.zedo.com/] Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adtech.de/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.burstnet.com/] Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.fortunecity.com/] Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bravenet.com/] Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.yadro.ru/] Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bfast.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.z1.adserver.com/] Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bluestreak.com/] Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[counter.hitslink.com/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.hitbox.com/] Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.peel.com/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.bs.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adrevolver.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.atwola.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[landing.domainsponsor.com/] Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.ct.360i.com/] Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.adultfriendfinder.com/] Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.qksrv.net/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.phg.hitbox.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.com.com/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Randy Jones\Application Data\Mozilla\Firefox\Profiles\ioji888z.default\cookies.txt[.maxserving.com/] Spyware:Cookie/nCase Not disinfected C:\Documents and Settings\Randy Jones\Cookies\randy [removed][1].txt Spyware:Spyware/7r7t Not disinfected C:\Documents and Settings\Randy Jones\My Documents\bibleblack3b.exe Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Documents and Settings\Randy Jones\My Documents\ZwinkyFFSetup2.2.50.1.exe Potentially unwanted tool:Application/Zango Not disinfected C:\mg1.exe Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK.dll Adware:Adware/CommAd Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\B69CB9AA-5955-44C2-8197-BD263E\C357E013-A5AB-4E4B-8684-AD7EAD Adware:Adware/CommAd Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C63B7ED0-72F5-4628-864F-BB748C\08EE61C5-5326-4123-BFAD-83E506 Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\DF5CE968-0CB8-4D72-ABC0-21BEB4\3E1B2B6D-DF21-427F-8A46-82FD60 Spyware:Spyware/New.net Not disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\F9B279FD-E935-4765-86AE-A81B9E\B26173CD-2193-43F5-BA4C-F920CC Potentially unwanted tool:Application/Zango Not disinfected C:\Program Files\Mozilla Firefox\plugins\npclntax.dll Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Spyware:Spyware/7r7t Not disinfected C:\Program Files\PSHope\PSHope.exe Spyware:Spyware/7r7t Not disinfected C:\Program Files\PSHope\Uninstall.exe Potentially unwanted tool:Application/Zango Not disinfected C:\WINDOWS\Downloaded Program Files\SAIX.dll Virus:Trj/Downloader.HPZ Not disinfected C:\WINDOWS\pf78.exe[pms111x.exe] Virus:Trj/VB.MC Not disinfected C:\WINDOWS\pf78.exe[SYSC00.exe] Spyware:Spyware/7r7t Not disinfected C:\WINDOWS\srvjnfpykg.exe Virus:Trj/Downloader.JKC Disinfected C:\WINDOWS\ssqbn.exe Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqn.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqo.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqp.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqq.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtqr.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtsp.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtsr.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awtss.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awvtq.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\awvtu.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayv.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayw.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddayx.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddccc.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddccy.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyv.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyx.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\ddcyy.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebcb.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebya.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyv.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyw.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyx.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\gebyy.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geeba.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geebb.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geebc.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geeby.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geedd.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\geede.dll Adware:Adware/NewAds Not disinfected C:\WINDOWS\system32\gjemekoj.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfd.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfe.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhff.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkhfg.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkji.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkli.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkklj.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkkll.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\jkklm.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljgd.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjg.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjh.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mljjj.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljg.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljh.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mlljk.dll Virus:Trj/Moli.CN Disinfected C:\WINDOWS\system32\mllmm.dll Adware:Adware/NewAds Not disinfected C:\WINDOWS\system32\plpfciki.dll Virus:Trj/Moli.CN Disinfected
if you can't run ewido in safe mode, run it in normal mode, then give me another combofix log and the ewido log. thanks,

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI