This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

adw_winstool.b ewido report and hijack this report

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i did what you said and ran ewido. when i applied all actions it said there was an error while quarantining downloader-wintool.a. here is the ewido report and the hijack this report: thanks for your help

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 1:42:52 PM 8/16/2006

+ Scan result:



C:\Documents and Settings\Jeff\Application Data\osms.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{03DC267E-E749-4D24-805B-D67F13951BFF}\RP33\A0000737.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Temp\backups\backup-20060814-183912-594.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\tаskmgr.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\toolbar.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\WTA1\WinTA.cab/WToolsA.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~490848.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~502773.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~540051.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~540199.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~540651.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~563535.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~587382.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~638341.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~645839.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~647873.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~667632.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~668580.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~670003.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~674731.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~702678.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~795539.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~872180.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Local Settings\Temp\~882962.tmp -> Adware.Wintol : Cleaned with backup (quarantined).
C:\Downloads\trace.zip/nc.exe -> Backdoor.Ncx.a : Cleaned with backup (quarantined).
C:\WINDOWS\bfmncqv.dll -> Downloader.Lemmy.t : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\~640869.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~703396.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~749846.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~760089.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~793149.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\Documents and Settings\Jeff\Cookies\jeff@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Cookies\jeff@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Cookies\jeff@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Jeff\Cookies\jeff@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\WINDOWS\msbbi.exe -> Trojan.Imiserv.c : Cleaned with backup (quarantined).


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 2:00:38 PM, on 8/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\Software by Design\TrayTool.exe
C:\Program Files\YCIII\YankClip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTSVCCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Fast.exe
C:\WINDOWS\system32\devldr32.exe
C:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Tray Tools 2000.lnk = C:\Program Files\Software by Design\TrayTool.exe
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-p3.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Search for using AltaVista - C:\Program Files\Search Bar\SBIEAddon\AltaVista.html
O8 - Extra context menu item: Search for using Excite - C:\Program Files\Search Bar\SBIEAddon\Excite.html
O8 - Extra context menu item: Search for using Google - C:\Program Files\Search Bar\SBIEAddon\Google.html
O8 - Extra context menu item: Search for using HotBot - C:\Program Files\Search Bar\SBIEAddon\HotBot.html
O8 - Extra context menu item: Search for using Lycos - C:\Program Files\Search Bar\SBIEAddon\Lycos.html
O8 - Extra context menu item: Search for using Yahoo - C:\Program Files\Search Bar\SBIEAddon\Yahoo.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/big/1.1….g/GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1154292067033
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2003012…all/xscan53.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSVCCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
Hello houseman and Welcome to TomCoyote,

Please do the following:

STEP 1.
======
Trojan Hunter
  • Download the free trial version of TrojanHunter
  • Install (allow registry entry to be changed if necessary – THGuard) and update. You will get an evaluation notice – choose “Continue Evaluation”.
  • You will see window titled “TrojanHunter – UNLICENSED EVALUATION COPY”
    Click icon “Full Scan” and let it scan- this may take awhile
  • If you have Trojans then a window titled “Clean Trojans” will open after the scan.
  • Be sure the entries are checked and click the “Clean” button.
  • Go to the window “TrojanHunter – UNLICENSED EVALUATION COPY”
    Go the “File” on the top menu =>Save Scan Report”.
Please copy and paste the Scan Report in your reply.

Scan with HijackThis. Place a check against each of the following:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Post (reply) with the results from Trojan Hunter and a fresh HijackThis log and we will take another look. Let's me know how your computer is running now.
here is the report after running trojanhorse. i then ran hijack this report and deleted the 2 lines you suggested

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
Error: Directory not found: C:\Documents and Settings\Jeff\Application Data\M?crosoft
Error: Directory not found: C:\Documents and Settings\Jeff\Application Data\??crosoft.NET
Error: Directory not found: C:\Documents and Settings\Jeff\Application Data\?racle
Error: Directory not found: C:\Documents and Settings\Jeff\Application Data\?ymantec
Found trojan file: C:\Documents and Settings\Jeff\Desktop\combofix.exe/bJfLJRZ5.exe (Worm.Qiv.100)
Error: Directory not found: C:\Documents and Settings\Jeff\Shared\My Documents\?racle
Error: Directory not found: C:\Documents and Settings\Jeff\Shared\My Documents\??sks
Error: Directory not found: C:\Program Files\Common Files\?racle
Error: Directory not found: C:\Program Files\Common Files\??sks
Error: Directory not found: C:\Program Files\Common Files\??curity
Error: Directory not found: C:\Program Files\Common Files\?dobe
Error: Directory not found: C:\Program Files\Common Files\?ppPatch
Error: Directory not found: C:\Program Files\W?nSxS
Error: Directory not found: C:\Program Files\?ppPatch
Error: Directory not found: C:\Program Files\??crosoft
Found adware file: C:\System Volume Information\_restore{03DC267E-E749-4D24-805B-D67F13951BFF}\RP44\A0001273.exe/kT6xLy.exe (Adware.IEPlugin.100)
Found adware file: C:\System Volume Information\_restore{03DC267E-E749-4D24-805B-D67F13951BFF}\RP44\A0001274.exe/obKkM2.exe (Adware.MediaTickets.104)
Error: Directory not found: C:\WINDOWS\F?nts
Error: Directory not found: C:\WINDOWS\system32\F?nts
Error: Directory not found: C:\WINDOWS\system32\?racle
Error: Directory not found: C:\WINDOWS\system32\??stem32
Error: Directory not found: C:\WINDOWS\system32\?racle
Error: Directory not found: C:\WINDOWS\s?mbols
Error: Directory not found: C:\WINDOWS\W?nSxS
Error: Directory not found: C:\WINDOWS\?ystem32
Error: Directory not found: C:\WINDOWS\?racle
3 files identified

Logfile of HijackThis v1.99.1
Scan saved at 6:11:08 PM, on 8/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\Program Files\Software by Design\TrayTool.exe
C:\Program Files\YCIII\YankClip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTSVCCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Fast.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [spywarebot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - Startup: Tray Tools 2000.lnk = C:\Program Files\Software by Design\TrayTool.exe
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-p3.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Search for using AltaVista - C:\Program Files\Search Bar\SBIEAddon\AltaVista.html
O8 - Extra context menu item: Search for using Excite - C:\Program Files\Search Bar\SBIEAddon\Excite.html
O8 - Extra context menu item: Search for using Google - C:\Program Files\Search Bar\SBIEAddon\Google.html
O8 - Extra context menu item: Search for using HotBot - C:\Program Files\Search Bar\SBIEAddon\HotBot.html
O8 - Extra context menu item: Search for using Lycos - C:\Program Files\Search Bar\SBIEAddon\Lycos.html
O8 - Extra context menu item: Search for using Yahoo - C:\Program Files\Search Bar\SBIEAddon\Yahoo.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/en/big/1.1….g/GoogleNav.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1154292067033
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2003012…all/xscan53.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSVCCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\Program Files\Speed Disk\nopdb.exe
We need to disable a few items to allow the hijackthis fix to take place.

Disable Trojan Hunter Guard:
Please disable Trojan Hunter Guard, as it may interfere with the fix.
To disable Trojan Hunter Guard:
  • Go to TrojanHunter Guard in the lower right corner of your screen. It is a light blue icon with a magnifying glass that can be difficult to see but the handle is red.
  • Right click it and select settings. Uncheck "Load at startup" and "Enabled"
Once your log is clean you can re-enable Trojan Hunter Guard.

Disable Microsoft Windows Defender:
We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
  • Click on Tools, General Settings.
  • Under Real-time protection options, unselect the Turn on real-time protection check box
  • Click Save
After all of the fixes are complete it is very important that you enable Real-time Protection again.

Scan with HijackThis. Place a check against each of the following:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Post(reply) with a fresh HijackThis log and we will take another look.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI