This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spy-agent.BC

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I was recently hit with the virus spy-agent.bc. I tried to get it off myself but my laptop seems to be acting a little weird. Could someone please take a look at my HijackThis log to see if there is anything that shouldn't be there. Thank you so much for your help! C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Network Associates\VirusScan\VsStat.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Network Associates\VirusScan\Vshwin32.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\Program Files\Network Associates\VirusScan\Webscanx.exe C:\Program Files\Network Associates\VirusScan\Avconsol.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\Program Files\Spyware Doctor\swdoctor.exe C:\Program Files\HijackThis\HijackThis.exe O1 - Hosts: localhost 127.0.0.1 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe" O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{DD340A94-F9F7-417C-8CA7-BBBEA43D4CAD}: NameServer = 85.255.114.53,85.255.112.16 O17 - HKLM\System\CCS\Services\Tcpip\..\{FCE008D5-45EA-470D-87B3-4842188BCE6B}: NameServer = 85.255.114.53,85.255.112.16 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16 O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
Hello Billie :)

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Step 1.

First Disable Spyware Doctor real-time protection.

Click the Onguard button to the left.
Remove the check from the Activate OnGuard option in the next window to disable all protection.


Please then download FixWareout from one of these sites:
http://forums.subratam.org/index.php?act=A…st&id=43811
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items:

O1 - Hosts: localhost 127.0.0.1
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD340A94-F9F7-417C-8CA7-BBBEA43D4CAD}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCE008D5-45EA-470D-87B3-4842188BCE6B}: NameServer = 85.255.114.53,85.255.112.16
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.53 85.255.112.16


Click Fix Checked. Close HijackThis, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.


Step 2.

Before doing this write down all the settings. Note that not all system/setups even have these settings, While some connection service's will require them.
These instruction's are basically for home users.
Enter your Control Panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically. Make sure the radio dial has the Green Dot in it!!


Go to Start > Run, enter CMD and click OK.

* At the Dos Prompt Screen, type in cd\ and then press <ENTER>.
* Now type in ipconfig /flushdns and then press <ENTER>. (notice the space after ipconfig)
* Close the command prompt window.

Reboot when Finished


Step 3.

Download Ewido Anti-Spyware
http://www.ewido.net/en/download/

The program should launch automatically after installation. If not, double-click the desktop icon.

Deactivate the "Ewido Resident Shield" as this may prevent changes to the registry.
To do this, click "Change State" to the right of the Resident Shield option in the main window.
You will clearly see the status change to Inactive if you have done this correctly.

Ewido automatically updates the spyware definitions if you are connected to the net during installation.
As a precaution, click the "Update" icon from the main menu.
Then click the "Start Update" button.
When you receive the "Update successful" prompt, close Ewido.
Note: If you have any problems with the updater, you can Update Ewido Manually.
Do not Scan with this yet!

Please Reboot your System into Safe Mode Shut down your system, then Restart your computer
as soon as it starts booting up again continuously tap F8 from the menu select the option to enter Safe Mode

Please go to Add/Remove Programs and uninstall the following: ( If listed )

KillAndClean

Now Hold Down The Windows Key + E to Open Windows Explorer,
Navigate to these Files/Folders then Right Click on and Delete these Bold Files/Folders:

C:\Program Files\KillAndClean\

Reopen Ewido Anti-Spyware and click the "Scanner" icon from the main menu.
Click "Complete System Scan" to start scanning.
When the scan completes, click "Recommended action" beneath the results window and select "Quarantine".
Then click the "Apply all actions" button to quarantine everything detected.
Then click Save report > Save report as and save the Report-Scan.txt to your desktop.
Then Reboot back into Normal Mode


Step 4.

Please Update your Sun Java console

Close any programmes you may have running, ESPECIALLY your web browser
Then using Add/Remove Select any item with Java Runtime Environment (JRE) in the name and uninstall.
Repeat as many times as necessary to remove all versions of Java from your system.

Reboot your computer

Then CLICK HERE select the Download button next to "J2SE Runtime Environment (JRE) 5.0 Update 8"

[external image: Posted Image]

"Accept" the License Agreement

Then choose the First download link Windows Offline Installation, Multi-language

You must Install this version Offline

Reboot your System


Now Re-Scan with Hijack This and post the new HJT log
the contents of the logfile C:\fixwareout\report.txt & the Ewido Report-Scan.txt

Thank You,
ourwilly.
Hi ourwilly, Thank you so much for your help! Here are my logs: ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 11:45:53 PM 8/16/2006 + Scan result: HKLM\SOFTWARE\Classes\Media-Codec.Chl -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Media-Codec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-507921405-1993962763-839522115-1003\Dc160.dll -> Adware.SBSoft : Cleaned with backup (quarantined). :mozilla.183:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.184:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.15:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.16:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.18:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.19:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.209:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.20:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.21:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.23:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.240:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.24:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.25:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.26:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.27:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.28:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.29:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.30:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.31:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.32:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.330:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.33:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.342:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.361:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.371:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.68:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@rcn.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.186:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.187:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.188:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.191:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.468:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.469:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.470:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.471:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.441:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.442:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned. :mozilla.6:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.7:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.8:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.9:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@advertising[1].txt -> TrackingCookie.Advertising : Cleaned. :mozilla.34:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.143:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.224:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.246:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@com[1].txt -> TrackingCookie.Com : Cleaned. :mozilla.22:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned. :mozilla.269:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.270:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.101:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.200:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.201:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.202:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.98:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.99:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.108:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.109:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.110:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.111:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.112:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned. :mozilla.182:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.523:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.123:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.125:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.126:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.128:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.158:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.159:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.160:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.476:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.477:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.478:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.48:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.49:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.79:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.80:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.81:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.82:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.83:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.372:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.373:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.374:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.278:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.279:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.147:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.148:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.149:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.150:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.151:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\branwen\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.485:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.399:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.400:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.414:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.415:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.419:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.10:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.11:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.12:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.13:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.14:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.47:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.449:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.450:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.451:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.446:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.447:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.448:C:\Documents and Settings\branwen\Application Data\Mozilla\Firefox\Profiles\xgqrirp4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\branwen\Cookies\branwen@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\system32\dmadj.exe -> Trojan.Small.fb : Cleaned with backup (quarantined). ::Report end Fixwareout ver 1.003 Last edited 8/11/2006 Post this report in the forums please Reg Entries that were deleted HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}114F2B5E811F-B059-3644-6D67-7739F0C9{ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\iqnmd HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eno HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\owt HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ruof HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\evif … Microsoft ® Windows Script Host Version 5.6 Random Runs removed from HKLM … PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»» Searching by size/names… »»»»» Search five digit cs, dm and jb files. This WILL/CAN also list Legit Files, Submit them at Virustotal C:\WINDOWS\SYSTEM32\DMNQI.EXE 62,048 2004-08-04 Other suspects. Directory of C:\WINDOWS\system32 {27306886-14DE-4D92-93B7-989CFE7BB5B9}.exe »»»»» Misc files. »»»»» Checking for older varients covered by the Rem3 tool. Logfile of HijackThis v1.99.1 Scan saved at 12:00:25 AM, on 8/17/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\Program Files\Network Associates\VirusScan\VsStat.exe C:\Program Files\Network Associates\VirusScan\Vshwin32.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Google\Gmail Notifier\gnotify.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ewido anti-spyware 4.0\ewido.exe C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Network Associates\VirusScan\Webscanx.exe C:\Program Files\Network Associates\VirusScan\Avconsol.exe C:\Program Files\HijackThis\HijackThis.exe C:\WINDOWS\system32\wuauclt.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
Hello Billie. :)

Very Sorry to keep you waiting..

Copy and Paste this post into a new text document or print it for reference

Please go to : http://virusscan.jotti.org/

I would like you Copy & Paste this Full path

C:\WINDOWS\SYSTEM32\DMNQI.EXE

into the address box and then select submit.
Please Save these result's from the Jotti scanner.

Please do the same for this file
C:\WINDOWS\system32\{27306886-14DE-4D92-93B7-989CFE7BB5B9}.exe


Can you then post both Result's in your Next Reply..
and please let me know how your system is running now.

Thank you,
ourwilly. :)
Hi Ourwilly, Thanks for the reply. Here are the results for this file: C:\WINDOWS\system32\{27306886-14DE-4D92-93B7-989CFE7BB5B9}.exe Scanner results AntiVir Found Trojan/Dldr.DNSChan.R.5 ArcaVir Found nothing Avast Found nothing AVG Antivirus Found Collected.8.AQ BitDefender Found Trojan.FakeAlert.CR ClamAV Found nothing Dr.Web Found Trojan.Fakealert F-Prot Antivirus Found nothing Fortinet Found Misc/UnSpyPC Kaspersky Anti-Virus Found nothing NOD32 Found Win32/Adware.KAC application Norman Virus Control Found nothing UNA Found nothing VirusBuster Found nothing VBA32 Found Trojan.Fakealert I was unable to upload this file: C:\WINDOWS\SYSTEM32\DMNQI.EXE The program says: The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file Could you please offer more advise on this? Thank you so much for your help! My computer is running much quicker now. Thanks! Billie
Hello Billie,

Sorry to keep you waiting.. :)

Please Hold Down The Windows Key + E to Open Windows Explorer,
Navigate to these Files/Folders then Right Click on and Delete these Bold Files/Folders:

C:\WINDOWS\system32\{27306886-14DE-4D92-93B7-989CFE7BB5B9}.exe
C:\WINDOWS\SYSTEM32\DMNQI.EXE



* Now Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
* Clean your Cache and Cookies in Firefox:
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
* Clean other Temporary files + Recycle bin:
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
Can you please let me know how your system is running

Thank you,
ourwilly. :)
Due to lack of feedback, this topic is closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI