This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Needs A Lot Of Work - HELP!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 6:47:50 PM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\SymSetup\Temp{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe
C:\Documents and Settings\mike\Desktop\hijackthis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoomtown.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO Plugin\plugin.dll (file missing)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [win_drivr32] C:\WINDOWS\System32\spizohst.exe
O4 - Startup: PowerReg Scheduler V3.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
STEP 1.
======
SpySweeper
Please download http://www.webroot.com/consumer/products/s…af1&rc=3597
(It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it.
  • Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply.
STEP 2.
======
Download Ewido
  • Download and install Ewido Security Suite It is a free trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
STEP 3.
======
Update Ewido
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use Ewido manual updates

STEP 4.
======
Ewido Scan
Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    o You will need to step through the process of cleaning files one-by-one.
    o If ewido detects a file you KNOW to be legitimate, select none as the action.
    o DO NOT select "Perform action on all infections"
    o If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")


STEP 5.
======
CWShredder

Please download and run CWShredder
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

STEP 6.
======

Please do an onlione scan here http://housecall.trendmicro.com/ and allow it to clean/remove what it finds.


Please post the results from SpySweeper, ewido and a new hijackthis log.
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 8:58:12 PM 8/13/2006

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Documents and Settings\mike\Local Settings\Temp\1639188_2112_2132_2656_73.41.tmp -> Adware.EliteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\WINDOWS\wfcnhm.dll -> Downloader.Lemmy.t : Cleaned with backup (quarantined).
C:\WINDOWS\sbruqzuy.dll -> Downloader.Lemmy.u : Cleaned with backup (quarantined).
C:\WINDOWS\suclyedy.dll -> Downloader.Lemmy.u : Cleaned with backup (quarantined).
C:\WINDOWS\system32\taskdir~.exe -> Downloader.Small.djf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kernels8.exe -> Downloader.Tibs.hh : Cleaned with backup (quarantined).
C:\WINDOWS\system32\slx.exe -> Downloader.Tibs.hh : Cleaned with backup (quarantined).
C:\Documents and Settings\mike\Local Settings\Temp\377.tmp -> Logger.Agent.nl : Cleaned with backup (quarantined).
C:\Documents and Settings\mike\Local Settings\Temp\9.tmp -> Logger.Agent.nl : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\l6sc3ij9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\l6sc3ij9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\l6sc3ij9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.69:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.70:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.71:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.72:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.73:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.74:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.75:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.76:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.77:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.162:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.163:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.164:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.165:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.166:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.153:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.154:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.18:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.21:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.22:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.23:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.24:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.25:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.26:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.27:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.28:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.29:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.32:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.33:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.34:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.35:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.36:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.37:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.38:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.39:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.40:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.41:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.42:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.43:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.44:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.45:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.46:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.47:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.48:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.49:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.50:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.51:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.52:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.53:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.54:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.59:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.60:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.61:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.62:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.64:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.99:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.108:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.109:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.111:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.112:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.113:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.114:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.115:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.116:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.117:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.101:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.17:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\l6sc3ij9.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.84:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.118:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.119:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.120:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.121:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.68:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.143:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.39:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\l6sc3ij9.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.100:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.95:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.96:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.97:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.98:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.89:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
:mozilla.176:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.177:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.90:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.91:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.92:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.93:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.94:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.184:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.185:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.186:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.187:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.188:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.189:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.190:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.125:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.126:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.171:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.172:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.178:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.179:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.180:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.181:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.182:C:\Documents and Settings\mike\Application Data\Mozilla\Firefox\Profiles\lkoxuh14.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ED67ADF3\setup_file[1].exe -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp526807.tmp -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\tmp871162.tmp -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8P6R892B\setup_file[2].exe -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8P6R892B\setup_file[3].exe -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GXE5YVYT\setup_file[2].exe -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\setup89(2)(2).exe -> Trojan.EliteBar.h : Cleaned with backup (quarantined).
C:\WINDOWS\DictComp3s.exe -> Trojan.VB.sx : Cleaned with backup (quarantined).


::Report end




Spy Sweeper


********
9:53 AM: Removal process completed. Elapsed time 00:08:39
9:51 AM: Quarantining All Traces: zedo cookie
9:51 AM: Quarantining All Traces: adserver cookie
9:51 AM: Quarantining All Traces: trafficmp cookie
9:51 AM: Quarantining All Traces: targetnet cookie
9:51 AM: Quarantining All Traces: servedby advertising cookie
9:51 AM: Quarantining All Traces: rn11 cookie
9:51 AM: Quarantining All Traces: reunion cookie
9:51 AM: Quarantining All Traces: realmedia cookie
9:51 AM: Quarantining All Traces: partypoker cookie
9:51 AM: Quarantining All Traces: touchclarity cookie
9:51 AM: Quarantining All Traces: mediaplex cookie
9:51 AM: Quarantining All Traces: maxserving cookie
9:51 AM: Quarantining All Traces: clickandtrack cookie
9:51 AM: Quarantining All Traces: fastclick cookie
9:51 AM: Quarantining All Traces: empnads cookie
9:51 AM: Quarantining All Traces: ru4 cookie
9:51 AM: Quarantining All Traces: atlas dmt cookie
9:51 AM: Quarantining All Traces: falkag cookie
9:51 AM: Quarantining All Traces: advertising cookie
9:51 AM: Quarantining All Traces: addynamix cookie
9:51 AM: Quarantining All Traces: hbmediapro cookie
9:51 AM: Quarantining All Traces: adknowledge cookie
9:51 AM: Quarantining All Traces: yieldmanager cookie
9:51 AM: Quarantining All Traces: netpal
9:51 AM: Quarantining All Traces: weirdontheweb
9:51 AM: Quarantining All Traces: webhancer
9:51 AM: Quarantining All Traces: my daily horoscope
9:51 AM: Quarantining All Traces: couponsandoffers
9:51 AM: Quarantining All Traces: tvmedia
9:51 AM: Quarantining All Traces: drsnsrch.com hijack
9:51 AM: Quarantining All Traces: networkessentials
9:51 AM: Quarantining All Traces: moneytree
9:50 AM: Quarantining All Traces: gsim
9:50 AM: Quarantining All Traces: ebates money maker
9:50 AM: Quarantining All Traces: webrebates
9:50 AM: Quarantining All Traces: mindset interactive - favoriteman
9:50 AM: Quarantining All Traces: topfivesearch hijacker
9:46 AM: Quarantining All Traces: sidesearch
9:45 AM: Quarantining All Traces: shopathomeselect
9:45 AM: Quarantining All Traces: elitemediagroup-mediamotor
9:45 AM: Quarantining All Traces: internetoptimizer
9:45 AM: Quarantining All Traces: hotbar
9:45 AM: Quarantining All Traces: blazefind
9:45 AM: Quarantining All Traces: 180search assistant/zango
9:45 AM: Quarantining All Traces: directrevenue-abetterinternet
9:44 AM: Quarantining All Traces: elitebar
9:44 AM: Removal process initiated
8:02 AM: Access to Hosts file allowed for C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGW.EXE
Operation: File Access
Target:
Source: C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGW.EXE
8:01 AM: Tamper Detection
2:08 AM: Traces Found: 126
2:08 AM: Full Sweep has completed. Elapsed time 00:33:58
2:08 AM: File Sweep Complete, Elapsed Time: 00:27:15
2:08 AM: Warning: Failed to access drive E:
2:08 AM: Warning: Failed to access drive D:
2:08 AM: C:\WINDOWS\inf\biini.inf (ID = 83199)
2:08 AM: C:\Documents and Settings\mike\Favorites\Netpal Games\FlyorDie Games.url (ID = 70890)
2:07 AM: C:\Documents and Settings\mike\Favorites\Netpal Games\Big Fish Games.url (ID = 70885)
2:07 AM: Found Adware: netpal
2:07 AM: C:\WINDOWS\system32\umqltg4cl.ini (ID = 75960)
2:07 AM: C:\WINDOWS\system32\hqrhil7kg.ini (ID = 75789)
2:07 AM: C:\Documents and Settings\mike\Favorites\WeirdOnTheWeb.url (ID = 87896)
2:07 AM: Found Adware: weirdontheweb
2:06 AM: C:\Documents and Settings\mike\Desktop\Unused Desktop Shortcuts\hbtools-1.exe (ID = 280632)
2:06 AM: C:\Documents and Settings\mike\Desktop\Unused Desktop Shortcuts\hbtools.exe (ID = 280632)
1:57 AM: C:\Documents and Settings\mike\Local Settings\Temp\cd3CE.tmp.exe (ID = 291732)
1:57 AM: C:\Documents and Settings\mike\Local Settings\Temp\nstFC.EXE (ID = 71031)
1:56 AM: C:\Program Files\CdmFiles\lhjlwnfmfj.exe (ID = 71031)
1:55 AM: C:\Documents and Settings\mike\Local Settings\Temp\res1DB.tmp (ID = 93786)
1:54 AM: C:\WINDOWS\system32\shawn_1.dll (ID = 69864)
1:54 AM: Found Adware: mindset interactive - favoriteman
1:50 AM: C:\Program Files\CdmFiles\lhjlwnfmfj.dll (ID = 71030)
1:49 AM: C:\WINDOWS\system32\SahHtml.exe (ID = 75914)
1:49 AM: C:\Documents and Settings\mike\Local Settings\Temp\suicidetb.exe (ID = 60028)
1:48 AM: C:\Documents and Settings\mike\Local Settings\Temp\1803DE.mht (ID = 147169)
1:48 AM: Found Adware: 180search assistant/zango
1:46 AM: C:\Program Files\WebSavingsfromEbates\WebSavingsfromEbates1.exe (ID = 79661)
1:46 AM: Found Adware: topfivesearch hijacker
1:46 AM: C:\Documents and Settings\mike\Local Settings\Temp\btgupg.exe (ID = 83224)
1:46 AM: Found Adware: directrevenue-abetterinternet
1:46 AM: C:\WINDOWS\prelimhanse.exe (ID = 83803)
1:46 AM: Found Adware: webhancer
1:45 AM: C:\WINDOWS\setup_silent_15139.exe (ID = 70241)
1:45 AM: Found Adware: my daily horoscope
1:45 AM: C:\WINDOWS\inf\gsim.inf (ID = 61964)
1:44 AM: c:\windows\downloaded program files\roing17.inf (ID = 74131)
1:44 AM: C:\Program Files\WebSavingsfromEbates\WebSavingsfromEbates.exe (ID = 54707)
1:44 AM: Found Adware: couponsandoffers
1:44 AM: C:\Documents and Settings\mike\Application Data\tvmknwrd.dll (ID = 81726)
1:44 AM: Found Adware: tvmedia
1:44 AM: C:\Documents and Settings\mike\Local Settings\Temp\2360292_2460_672_2832_63.41.tmp1 (ID = 137430)
1:43 AM: C:\Documents and Settings\mike\Local Settings\Temp\4129786_2460_672_2220_63.41.tmp1 (ID = 137430)
1:43 AM: C:\Documents and Settings\mike\Local Settings\Temp\3998526_2460_672_1868_63.41.tmp1 (ID = 137430)
1:43 AM: C:\Documents and Settings\mike\Local Settings\Temp\1442786_2460_672_2124_63.41.tmp1 (ID = 137430)
1:43 AM: C:\Documents and Settings\mike\Local Settings\Temp\2818894_2460_672_276_63.41.tmp1 (ID = 137430)
1:43 AM: C:\WINDOWS\EbatesMoeMoneyMaker.exe (ID = 59618)
1:43 AM: C:\Documents and Settings\mike\Local Settings\Temp\65876_1688_684_1884_63.41.tmp1 (ID = 137430)
1:42 AM: C:\Documents and Settings\mike\Local Settings\Temp\1312598_4024_2264_2688_63.41.tmp1 (ID = 137430)
1:42 AM: C:\Documents and Settings\mike\Local Settings\Temp\1114672_3456_1836_2424_63.41.tmp1 (ID = 137430)
1:42 AM: C:\Documents and Settings\mike\Local Settings\Temp\3867208_4024_2264_2280_63.41.tmp1 (ID = 137430)
1:42 AM: Found Adware: elitebar
1:41 AM: C:\Program Files\Ebates_MoeMoneyMaker (16 subtraces) (ID = 2147486228)
1:41 AM: C:\Program Files\WebSavingsfromEbates (14 subtraces) (ID = 2147486229)
1:41 AM: Starting File Sweep
1:41 AM: Warning: Failed to access drive A:
1:41 AM: Cookie Sweep Complete, Elapsed Time: 00:00:04
1:41 AM: c:\documents and settings\localservice\cookies\system@zedo[1].txt (ID = 3762)
1:41 AM: Found Spy Cookie: zedo cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][1].txt (ID = 2142)
1:41 AM: Found Spy Cookie: adserver cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@yieldmanager[1].txt (ID = 3749)
1:41 AM: c:\documents and settings\localservice\cookies\system@trafficmp[1].txt (ID = 3581)
1:41 AM: Found Spy Cookie: trafficmp cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@targetnet[2].txt (ID = 3489)
1:41 AM: Found Spy Cookie: targetnet cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 3335)
1:41 AM: Found Spy Cookie: servedby advertising cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@rn11[2].txt (ID = 3261)
1:41 AM: Found Spy Cookie: rn11 cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@reunion[2].txt (ID = 3255)
1:41 AM: Found Spy Cookie: reunion cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@realmedia[1].txt (ID = 3235)
1:41 AM: Found Spy Cookie: realmedia cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@partypoker[2].txt (ID = 3111)
1:41 AM: Found Spy Cookie: partypoker cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][1].txt (ID = 3567)
1:41 AM: Found Spy Cookie: touchclarity cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@mediaplex[1].txt (ID = 6442)
1:41 AM: Found Spy Cookie: mediaplex cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@maxserving[1].txt (ID = 2966)
1:41 AM: Found Spy Cookie: maxserving cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 2397)
1:41 AM: Found Spy Cookie: clickandtrack cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@fastclick[2].txt (ID = 2651)
1:41 AM: Found Spy Cookie: fastclick cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@empnads[1].txt (ID = 5012)
1:41 AM: Found Spy Cookie: empnads cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@edge.ru4[1].txt (ID = 3269)
1:41 AM: Found Spy Cookie: ru4 cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@atdmt[2].txt (ID = 2253)
1:41 AM: Found Spy Cookie: atlas dmt cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 2650)
1:41 AM: Found Spy Cookie: falkag cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@advertising[1].txt (ID = 2175)
1:41 AM: Found Spy Cookie: advertising cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 2062)
1:41 AM: Found Spy Cookie: addynamix cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 2768)
1:41 AM: Found Spy Cookie: hbmediapro cookie
1:41 AM: c:\documents and settings\localservice\cookies\system@adknowledge[1].txt (ID = 2072)
1:41 AM: Found Spy Cookie: adknowledge cookie
1:41 AM: c:\documents and settings\localservice\cookies\[removed][2].txt (ID = 3751)
1:41 AM: Found Spy Cookie: yieldmanager cookie
1:41 AM: Starting Cookie Sweep
1:41 AM: Registry Sweep Complete, Elapsed Time:00:01:34
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {946b3e9e-e21a-49c8-9f63-900533fafe15} (ID = 1058296)
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {000007c6-17df-4438-92a4-de5537471ba3} (ID = 530423)
1:40 AM: Found Adware: sidesearch
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
1:40 AM: Found Adware: drsnsrch.com hijack
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {946b3e9e-e21a-49c8-9f63-900533fafe14} (ID = 127575)
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\dynamic toolbar\gsim\ (ID = 127017)
1:40 AM: HKU\S-1-5-21-484763869-920026266-854245398-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {6685509e-b47b-4f47-8e16-9a5f3a62f683} (ID = 125587)
1:40 AM: HKLM\software\classes\spamblockerconfig.application.1\ (ID = 968867)
1:40 AM: HKCR\spamblockerconfig.application.1\ (ID = 968312)
1:40 AM: HKLM\software\ || test (ID = 141678)
1:40 AM: Found Adware: shopathomeselect
1:40 AM: HKLM\software\ssprint\ (ID = 140214)
1:40 AM: Found Adware: elitemediagroup-mediamotor
1:40 AM: HKLM\software\np\ (ID = 136176)
1:40 AM: HKLM\software\novo\ (ID = 136175)
1:40 AM: HKLM\software\microsoft\windows\currentversion\uninstall\cdm\ (ID = 136172)
1:40 AM: Found Adware: networkessentials
1:40 AM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\1.0\helpdir\ (ID = 135205)
1:40 AM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\1.0\flags\ (ID = 135204)
1:40 AM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\1.0\0\win32\ (ID = 135203)
1:39 AM: HKCR\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (ID = 128933)
1:39 AM: HKCR\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (ID = 128933)
1:39 AM: HKLM\software\classes\typelib\{b999b42b-863d-4a6c-aa2b-ce6d2137d628}\ (ID = 128897)
1:39 AM: HKLM\software\classes\dyfuca_bh_bucket.bucket\ (ID = 128895)
1:39 AM: HKLM\software\classes\dyfuca_bh_bucket.bucket.1\ (ID = 128894)
1:39 AM: HKLM\software\classes\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\versionindependentprogid\ (ID = 128891)
1:39 AM: HKLM\software\classes\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\typelib\ (ID = 128890)
1:39 AM: HKLM\software\classes\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\ (ID = 128889)
1:39 AM: HKLM\software\classes\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\ (ID = 128889)
1:39 AM: HKCR\dyfuca_bh_bucket.bucket\ (ID = 128884)
1:39 AM: HKCR\dyfuca_bh_bucket.bucket.1\ (ID = 128883)
1:39 AM: HKCR\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\ (ID = 128880)
1:39 AM: Found Adware: moneytree
1:39 AM: HKCR\clsid\{00000001-c003-4a2f-9142-7cb1d78de6c1}\ (ID = 128880)
1:39 AM: Found Adware: internetoptimizer
1:39 AM: HKCR\spamblockerconfig.application\ (ID = 127634)
1:39 AM: HKLM\software\classes\spamblockerconfig.application\ (ID = 127536)
1:39 AM: Found Adware: hotbar
1:39 AM: HKLM\software\microsoft\windows\currentversion\uninstall\gsim\ (ID = 127019)
1:39 AM: Found Adware: gsim
1:39 AM: HKLM\software\microsoft\windows\currentversion\uninstall\unebmm350\ (ID = 125601)
1:39 AM: Found Adware: ebates money maker
1:39 AM: HKLM\software\microsoft\windows\currentversion\uninstall\unebmm350\ (ID = 125601)
1:39 AM: Found Adware: webrebates
1:39 AM: HKLM\software\microsoft\windows\currentversion\uninstall\windows sr 2.0\ (ID = 104552)
1:39 AM: Found Adware: blazefind
1:39 AM: Starting Registry Sweep
1:39 AM: Memory Sweep Complete, Elapsed Time: 00:04:24
1:35 AM: Starting Memory Sweep
1:34 AM: Sweep initiated using definitions version 691
1:34 AM: Spy Sweeper 5.0.5.1286 started
1:34 AM: | Start of Session, Sunday, August 13, 2006 |







Logfile of HijackThis v1.99.1
Scan saved at 9:19:36 PM, on 8/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mike\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoomtown.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO Plugin\plugin.dll (file missing)
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [win_drivr32] C:\WINDOWS\System32\spizohst.exe
O4 - Startup: PowerReg Scheduler V3.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Please scan this file

C:\WINDOWS\System32\spizohst.exe

At the link below and post the log it produces please.

Scan here >>>> http://virusscan.jotti.org/

Please scan this file

C:\WINDOWS\System32\spizohst.exe

At the link below and post the log it produces please.

Scan here >>>> http://virusscan.jotti.org/


That file does not exist.
New Log

Logfile of HijackThis v1.99.1
Scan saved at 6:05:46 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\mike\Desktop\Unused Desktop
Shortcuts\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.zoomtown.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO
Plugin\plugin.dll (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All
Users\Documents\Settings\artm_new.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - (no
file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. -
C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak
Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -
C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. -
C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation
- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot
Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
No, the log just looks really short.

Please scan with hijackthis and put a check ebside these lines and choose FIX

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost

O2 - BHO: BHO - {9BB5B49C-0D59-418d-A6A5-F6373B8FEF64} - C:\Program Files\BHO
Plugin\plugin.dll (file missing)

O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All
Users\Documents\Settings\artm_new.dll (file missing)

O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - (no
file)

Then reboot and a new log.

It also looks like you have 2 active anti virus programs on your system. This can cause all kinds of conflicts and you should remove one of them.
I thought there was only AVG that I put on this machine?


New log:

Logfile of HijackThis v1.99.1
Scan saved at 10:23:09 PM, on 8/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\mike\Desktop\Unused Desktop Shortcuts\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoomtown.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
These look like you had Norton loaded at one time. O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe How are things running?
Oh, the owner of this computer tried installing NIS2006 after his computer was taken over by about 650 different viruses. I can't figure out how to completely uninstall it? Everything seems okay, but the computer is still pretty slow..I think it's due to the fact of 256 RAM and 890 MHz proc running XP. The owner never installed any Microsoft updates and never scans for adware/viruses. Anything else I can do? Thanks so much!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI