This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need help with HJT log

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Am having problems with pop ups and other types of ads making my XP PC unusable. Am also finding (and deleting) dozens of exe files download to my PC. I've also uninstalled tons of programs recently installed without my knowledge. Still having problems and basically can't use the PC connected to the internet.

HJT log pasted below. I also have a StartUpList log if that would be helpful. Any guidence would be greatly appreciated. Thanks, Scott in Cleveland

——————————————————-

Logfile of HijackThis v1.99.1
Scan saved at 12:22:07 PM, on 8/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\U2NvdHQ\command.exe
C:\WINDOWS\system32\dnsapi.exe
C:\WINDOWS\system32\inetpp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\ssn6tuu.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\cfg32.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\MSAgentXP.exe
C:\WINDOWS\system32\nr1rnqm8.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\msdadiag.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\system32\test2.exe
C:\WINDOWS\system32\kbdtat.exe
C:\WINDOWS\system32\wiascr.exe
C:\WINDOWS\SMBOLS~1\winspool.exe
C:\PROGRA~1\ASEMBL~1\RGSVR3~1.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\uhqud.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fcwxnes.exe
O1 - Hosts: 255.255.255.255 www.casinoxo.com
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: Yvakt Class - {5C3E6596-C64F-48E0-AC1E-B9C6EB3A5915} - C:\WINDOWS\system32\x3cqp0.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [keyboard] C:\\kybrdc_2.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrc_2.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmb_2.exe
O4 - HKLM\..\Run: [{E0-0E-EF-F3-ZN}] C:\windows\system32\pldsregs.exe GID003
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\pwinmqez.exe GID003
O4 - HKLM\..\Run: [Hhl7RfpJ] "C:\WINDOWS\system32\ssn6tuu.exe"
O4 - HKLM\..\Run: [w003e4b4.dll] RUNDLL32.EXE w003e4b4.dll,I2 001533820003e4b4
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSAgentXP] C:\WINDOWS\system32\MSAgentXP.exe
O4 - HKCU\..\Run: [msdadiag] C:\WINDOWS\system32\msdadiag.exe
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [test2] C:\WINDOWS\system32\test2.exe
O4 - HKCU\..\Run: [kbdtat] C:\WINDOWS\system32\kbdtat.exe
O4 - HKCU\..\Run: [wmgr] C:\WINDOWS\system32\wmgr.exe
O4 - HKCU\..\Run: [wiascr] C:\WINDOWS\system32\wiascr.exe
O4 - HKCU\..\Run: [Acli] "C:\WINDOWS\SMBOLS~1\winspool.exe" -vt yazr
O4 - HKCU\..\Run: [Bkv] C:\PROGRA~1\ASEMBL~1\RGSVR3~1.EXE
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - C:\WINDOWS\system32\x3cqp0.dll
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U2NvdHQ\command.exe
O23 - Service: dnsapi - Unknown owner - C:\WINDOWS\system32\dnsapi.exe
O23 - Service: inetpp.exe - Unknown owner - C:\WINDOWS\system32\inetpp.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Welcome to the forum, I am sorry to hear you are having these problems and will do what I can to help. First I will tell you what you already know, that you are very infected and wise to keep the computer offline, this junk will attract others.
It is going to take a little work and multiple tools to clean you up. If this works for you, then we will start like this.

Thanks to Metallica and any others who helped with this fix.

1. Please download Ewido Anti-Malware
  • Install ewido anti-malware
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.

    You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
  • Exit Ewido, do not run the scan yet!
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

2. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C: ) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

4. Once in Safe Mode, Open Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.

5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log. Include any comments you think will help.

This is just a start, we have other junk including a Qoologic trojan. I will respond as soon as possible after you post with the next instructions.

Thanks…Phil
Phil -

Thanks. Everything seemed to go as you decribed. As you can see, Ewido found a lot of junk. After completing everything, there are three things you may find interesting:

1) At startup, Ewido flags "Downloader.Qoologic.bj", pointing to various EXE and DLL files (e.g. WINDOWS\System32\kfyqthe.dll). It does not seem able to clean them.

2) Upon startup, I get a Windows error box: RUNDLL: Error loading w003e4b4.dll. Specified module could not be found.

3) At startup, a Windows explorer window pops, displaying WINDOWS\System32. This has been happening for a while.


Logs below.

Scott


===================

Logfile of HijackThis v1.99.1
Scan saved at 1:57:33 PM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\exyqdy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\uhqud.exe
C:\WINDOWS\system32\uhqud.exe
C:\WINDOWS\system32\uhqud.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\uhqud.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fcwxnes.exe
O1 - Hosts: 255.255.255.255 www.casinoxo.com
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: (no name) - {5C3E6596-C64F-48E0-AC1E-B9C6EB3A5915} - (no file)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [{E0-0E-EF-F3-ZN}] C:\windows\system32\pldsregs.exe GID003
O4 - HKLM\..\Run: [dodhdw] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKLM\..\Run: [w003e4b4.dll] RUNDLL32.EXE w003e4b4.dll,I2 001533820003e4b4
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [alkje] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: vflrj.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: dnsapi - Unknown owner - C:\WINDOWS\system32\dnsapi.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: inetpp.exe - Unknown owner - C:\WINDOWS\system32\inetpp.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


=======================================


———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 1:07:40 PM 8/26/2006

+ Scan result:



C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043824.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044821.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046073.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044828.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044850.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044874.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044999.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045039.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045040.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045045.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047101.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048249.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32o.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32p.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32r.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32s.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension.5 -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\C9UF4DY3\!update-3945[1].0000 -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Тasks\Тasks\!update-3945.0000 -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046093.exe -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\WINDOWS\U2NvdHQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\WINDOWS\U2NvdHQ\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043808.exe -> Adware.Enbrow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044875.exe -> Adware.Enbrow : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044852.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044859.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044988.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044995.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044997.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045003.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045007.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0008.CHK -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044836.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044879.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044888.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044951.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044967.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045012.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045017.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045034.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045047.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045053.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045068.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046071.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046088.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046092.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047120.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047124.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047145.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047156.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047159.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047169.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047175.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047189.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047194.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047197.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047201.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0048200.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048219.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048230.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\LBMSP80N.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WCWIZDLL.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WRNSSPI.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cbrtmgr.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dPnim.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\damsrpcn.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dgcpcsvc.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\diutil.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\e220lcfm1f2a.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ejts.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fp2603fse.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\i6jq0g15e6.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixxwan.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jt6007jme.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kmdfc.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ktl0l73m1.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lv6009jme.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mhdadiag.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mkjter40.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\o2480chuef480.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\owbccr32.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sbhannel.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\uwrrtosa.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wdhnetbs.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wnv8dmoe.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044982.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WinNB57.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043811.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044835.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044851.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044866.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044867.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044943.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045002.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047096.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047106.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047118.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047158.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047184.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048236.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand.1 -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CLSID -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CurVer -> Adware.PowerStrip : Cleaned with backup (quarantined).
C:\Program Files\aѕsembly\rеgsvr32.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046095.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047165.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\logonui.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Program Files\UpromiseRemindU\UpromiseRemindU1.exe -> Adware.Rebates : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044854.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044971.EXE -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044987.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044994.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045001.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045008.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048242.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048246.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048247.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048250.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048251.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048262.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048263.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048265.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046072.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048261.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SpySheriff -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/wfxqhv.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/nr1rnqm8.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/ssn6tuu.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044860.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044990.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044998.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045005.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045041.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045042.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045043.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045044.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047091.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047109.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048239.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048240.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048244.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048252.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gbe90qs.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nr1rnqm8.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ssn6tuu.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\x3cqp0.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\i30.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\i7D.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044883.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044884.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044885.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044887.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047185.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047186.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047187.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047188.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046086.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\Program Files\Toolbar888 -> Adware.ToolBar888 : Cleaned with backup (quarantined).
C:\Program Files\UpromiseRemindU\UpromiseRemindU.exe -> Adware.TopMoxie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043812.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043813.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043814.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044825.exe/whAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044958.EXE -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044963.EXE -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044964.DLL -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044965.DLL -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044966.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044842.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044858.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044863.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044872.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044873.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043810.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046080.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044846.exe -> Downloader.Adload.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044826.exe -> Downloader.Adload.bv : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0004.CHK -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0005.CHK -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047123.exe -> Downloader.Adload.cn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048255.exe -> Downloader.Adload.dv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmonwv.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003dfc2.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003e4b4.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w00416ef.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044838.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047125.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048253.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\WINDOWS\system32\MSAgentXP.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msdadiag.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045011.DLL -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047138.dll -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044848.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044871.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047108.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047128.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\F7Z91BLM\!update-3895[1].0000 -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Тasks\services.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\F7Z91BLM\!update-4120[1].0000 -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048235.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048286.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\!update.exe -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\6YW01EIM\!update-4220[1].0000 -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\WINDOWS\sуmbols\winspool.exe -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043809.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047084.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\WINDOWS\system32\juoto.dat -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\uhqud.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[688] C:\WINDOWS\system32\kfyqthe.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dnsapi.exe -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\WINDOWS\system32\test.bmp -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003bad5.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\Program Files\MSN Gaming Zone\auxe.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042810.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042811.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042812.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046097.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047206.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044841.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047095.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047126.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044833.exe -> Downloader.Small.cpu : Cleaned with backup (quarantined).
C:\Program Files\MSN Gaming Zone\wogexisu.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046096.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047205.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\VSL.dl_ -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047093.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046075.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046083.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046082.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044840.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047100.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046074.exe -> Downloader.TSUpdate.p : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044845.exe -> Downloader.VB.abm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047131.exe -> Downloader.VB.afv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046081.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047080.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047081.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047130.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047122.exe -> Downloader.VB.agi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047094.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048260.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043806.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043807.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047082.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047083.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044839.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047103.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044830.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044831.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044832.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047097.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047092.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044834.exe -> Dropper.Mudrop.bq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044837.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047099.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044864.exe -> Dropper.VB.mz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047115.exe -> Dropper.VB.mz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042816.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046100.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047129.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047143.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048270.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Program Files\Microsoft Works\zynela.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\Online Services\wolyjuju.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047119.exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044827.exe -> Hijacker.StartPage.aju : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047098.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046098.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\WINDOWS\fzhtelx.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044847.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048259.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045010.exe -> Not-A-Virus.Downloader.Win32.FunWeb : Ignored.
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IGBFYK9V\WinAntiVirusPro2006ScannerInstall[1].cab/UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048258.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048269.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048248.exe -> Not-A-Virus.Hoax.Win32.Renos.dc : Ignored.
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\FOUND.004\FILE0002.CHK -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\FOUND.004\FILE0003.CHK -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048256.exe -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\jessi@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@112.2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\scott@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@7search[1].txt -> TrackingCookie.7search : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@ad-flow[2].txt -> TrackingCookie.Ad-flow : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@ad-logics[2].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed]-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@ad-logics[2].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\jessi@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\[removed][2].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed][2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings
Hi Scott, be patient guy, these infections are harder to remove than they are to get on. A good reason to avoid the infections. Let's see how you did.

Ewido removed a load of junk, you are picking up a hugh amount of adware from someplace. Your System Restore is infected also, so avoid using it until we clean it before we finish.

We are going to hit the stuff hard, I may duplicate efforts and I don't think we can get it all in on run through, let's see what the next HJT log looks like.

Before we start, I need to know about these two services, I think they are both trojans but need to be sure, use one or more of these free online scans and let me know the results.
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html
Here are the questionable services:
C:\WINDOWS\system32\dnsapi.exe
C:\WINDOWS\system32\inetpp.exe

Once you know they are bad, then stop them from running like this:
Click Start > Run and type services.msc.
Scroll down to the Service and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled.
The service you will be stopping are: dnsapi and inetpp.exe

Credit to Rubber Ducky for the tool…and Lonny for the original fix

1) Please download Qoofix by Rubber Ducky to your desktop.
  • Right click on the Qoofix folder, and choose "Extract All". Extract Qoofix to your C: drive
  • Close all windows and programs, including internet windows.
  • Go to C:\Qoofix and open the folder, then double click on Qoofix.exe
  • Click Begin Removal and wait for the scan to finish
  • If Qoofix finds an infection, select yes to restart your computer
  • You will now find a log from this tool, located at C:\Qoofix\Qoofix Logfile.txt Copy and paste the contents of that report into your next reply here.
2) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

3) Please download ATF Cleaner by Atribune
http://www.atribune.org/public-beta/ATF-Cleaner.exe
Save it to your Desktop. We will use this later.

4) Start > Control Panel > Add Remove programs and uninstall TClock if there, also uninstall any programs you know do not belong there. If you are not sure, let me know and I will look.

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\uhqud.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fcwxnes.exe
O1 - Hosts: 255.255.255.255 www.casinoxo.com
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: (no name) - {5C3E6596-C64F-48E0-AC1E-B9C6EB3A5915} - (no file)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O4 - HKLM\..\Run: [{E0-0E-EF-F3-ZN}] C:\windows\system32\pldsregs.exe GID003
O4 - HKLM\..\Run: [dodhdw] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKLM\..\Run: [w003e4b4.dll] RUNDLL32.EXE w003e4b4.dll,I2 001533820003e4b4
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [alkje] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: vflrj.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
(If you have found these two are bad, check and remove them also)
O23 - Service: dnsapi - Unknown owner - C:\WINDOWS\system32\dnsapi.exe (file missing)
O23 - Service: inetpp.exe - Unknown owner - C:\WINDOWS\system32\inetpp.exe

Close all programs but HJT and all browser windows, then click on "Fix Checked"

RIGHT Click on Start then click on Explore. Locate and delete these items:

(some will be removed with the trojan, just do not miss them if they are there)

C:\WINDOWS\system32\exyqdy.exe <<< file

C:\WINDOWS\system32\fcwxnes.exe <<< file

C:\windows\system32\pldsregs.exe <<< file

C:\WINDOWS\system32\test.exe <<< file

C:\WINDOWS\system32\uhqud.exe <<< file

C:\Program Files\TClock\ <<< folder

Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart the computer and post the Qoofix Logfile.txt, a new HJT log and any comments you think will help. We may have more to do, but take your time and work through those instruction and that should be most of it.

Thanks…Phil

You also need to update your Java program, see this information: http://forums.spybot.info/showpost.php?p=1…amp;postcount=2
C:\Program Files\Java\jre1.5.0_06\ <<< out of date.
Hi Phil -

Here's how it went.

Two suspicious files

C:\WINDOWS\system32\dnsapi.exe: I could not find this file. It showed as an inactive service, but one of your previous actions must have already taken care of it.

C:\WINDOWS\system32\inetpp.exe: Flunked the virus test, but was not an active service (I disabled it). You did not say to delete the file (it also has an associated DLL file). Should I delete it? - It's still there after doing everything else.

1) Qoofix found and fixed something, log below.

4) I had reviewed installed programs before posting and removed about a dozen programs, including TClock. The only questionable one left is "Command", with no info (last used, etc.) about it.

5) About a half dozen on your HJT hit list (including the two suspicious EXE files) were not longer there. Fixed the rest. Several still remain, even after attempting to fix them:

O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)

None of the specific EXE files you listed survived to this point. I removed a couple of TClock scraps.

I cleaned my temp files and updated JRE.

Latest HJT log below.

What say thee now?

thanks,

scott


==================================

Qoofix v1.03 by http://www.malwarebytes.org
Scan started on [8/27/2006]
at [9:11:29 AM]
————————————————————-
No malicious modules found!
————————————————————-
C:\WINDOWS\system32\juoto.dat will be deleted on reboot!

User prompted YES to reboot, system now rebooting…
————————————————————-
Scan COMPLETED SUCCESSFULLY on [8/27/2006] at [9:12:23 AM]

Note: Some registry keys may have been removed.


====================================


Logfile of HijackThis v1.99.1
Scan saved at 10:13:10 AM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Thanks for returning your information, I gave you a lot to do at once and I understand that, good job :thumbup: Looking at your feedback first.

You did not say to delete the file (it also has an associated DLL file). Should I delete it? - It's still there after doing everything else.

But I did give you the tools to check the file before removing it, I have no way of knowing if they are good or bad from here.

The only questionable one left is "Command",


I will post instructions for letting me look at your uninstall list a little later.

Several still remain, even after attempting to fix them:

You used HJT to remove them? Those must go, could be a program is blocking removal?

We have stuff that we must remove with HJT. The only program I see that might be stopping them is ewido's realtime protestion. Turn it off:
Under 'Your security status', if the real time protection is active, deactivate it by clicking 'real time protection' until the status says 'inactive'

Let me explain that HJT is a small processor, and when you check and remove items it stops the running processe so that we can delete the files. You must go to and delete those files just after you use HJT and before a reboot when they will be running again. If you need to, use your Search Companion to locate any of the files you need to delete. This must be done before you computer will be clean.

ewido is turned off, now open HJT and carefully check each of these items and then click "Fix Checked". Then move to the files and delete them

Make sure hidden files and folders is still enabled from before, if not follow the directions again. If the junk is hidden, even Search Companion can't see them.

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
(the next item I can not ididy, remove it. If it is valid it will be put back the next time you visit the site)
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

RIGHT Click on Start then click on Explore. Locate and delete these items:

sysmon.exe <<< delete that file (search for it)

C:\WINDOWS\system32\test.exe <<< delete that file

C:\Program Files\TClock\ <<< delete that folder

Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Uninstall list
Start HiJackThis
Press 'Config'
Press 'Misc Tools'
Press 'Open Uninstall Manager'
Press 'Save List'
Save the log to a convenient location
Copy the log and post its contents in this thread.

The good news is that Qoologic has been removed, post a new HJT log, the Uninstall list and let me know how the computer is running.

Thanks…Phil
Hi Phil -

Thanks for the fast reponse. Here's the latest.

I did as you instructed (diabled Ewido and checked the items in the HJT list). The checked items are still not removed. But I did find and delete inetpp.exe and sysmon.exe. (test.exe and tclock-anything could not be found).

Latest HJT log and Uninstall list below. The only program I don't recognize is "Command".

scott

==================
Logfile of HijackThis v1.99.1
Scan saved at 7:23:22 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

==================================

ABBYY FineReader 5.0 Sprint
Ad-aware 6 Personal
Adobe Acrobat 5.0
Adobe Photoshop 7.0
Amazing Animals
Arthur's Computer Adventure
Arthur's Wilderness Rescue
Command
Disney's Mickey Mouse Toddler
Disney's Winnie the Pooh Toddler
DivX 4.12 Codec
Doom 3
ewido anti-spyware 4.0
EXEtender Player
FaxTools
GameSpy Arcade
Hijackthis 1.99.1
HijackThis 1.99.1
Intel® Create & Share® Software
InterActual Player
J2SE Runtime Environment 5.0 Update 8
JumpStart Spanish
LeapFrog Mind Station
Learn About Animals
Lernout & Hauspie TruVoice American English TTS Engine
Lexmark X74-X75
Little People® Discovery Airport
Macromedia Flash Player 8
Magic 3D Coloring Book Amazing Animals
Microsoft .NET Framework 1.1
Microsoft Halo
Microsoft Office XP Professional
Microsoft XML Parser and SDK
MSXML 4.0 SP2 Parser and SDK
MUSICMATCH Jukebox
Napster
Napster Burn Engine
NEOedit
Nero - Burning Rom
Network Play System (Patching)
NVIDIA Windows 2000/XP Display Drivers
OLYMPUS CAMEDIA Master 2.0
Palm Desktop
PCFriendly
Perfect Attorney - Business
Perfect Attorney - Divorce & Video
Perfect Attorney - Federal
Perfect Attorney - Forms
Perfect Attorney - Tutorials
Pinball Panic
ProntoNEO Firmware Update Tool
Quicken 2005
QuickTime
QuickTime for Windows (32-bit)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Shockwave
Sound Blaster Live! Web 2K/XP
Spybot - Search & Destroy 1.2
Star Wars JK II Jedi Outcast
TaxCut 2003
TaxCut 2004
TaxCut Deluxe 2005
ThumbsPlus version 4.50-R
TSA
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Upromise remindU
Viewpoint Media Player (Remove Only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888240
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinMX
Winnie the Pooh Toddler Compatibility Update
WinZip
Yahoo! Messenger
I am not sure what you are doing, but stuff that we remove all of the time easily, is still in the HJT log. We will start over. Follow these directions:

1) The Uninstall list, I see a lot of junk but no "malware", I suggest you uninstall anything you no longer use. I do not know the Command item either, open the program to see what it is. If you don't use the program, uninstall it.

2) Trusted Zone removal:
Right click http://mvps.org/winhelp2002/DelDomains.inf and select Save As to download WinHelp2002's DelDomains.inf.
Please save the file somewhere you can find it like on the desktop.
To run the inf file, right click on it and select Install.

Thanks to Atribune and any other who helped with this fix.

3) Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If Look2Me-Destroyer does not reopen automatically, reboot and try again.

If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX

More info:

If for some reason Look2Me-Destroyer doesn't reopen check that task scheduler is running.
If it isnt you can use sc.exe to start it

start>run sc start schedule press enter.

Make sure the computer is restarted and post the two logs bolded above.

4) You need to make sure you have followed these directions:
How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Now you need to use Search Companion, sometimes it takes a while for it to locate the junk, be patient. Locate and delete these files, even if you have to delete then in safe mode:

C:\WINDOWS\system32\test.exe <<< delete that file

C:\Program Files\TClock\ <<< delete that folder

If you have trouble deleting them, then use this tool:

http://www.bleepingcomputer.com/tutorials/…l42.html#delreb
How to use the Delete on Reboot tool

At times you may find a file that stubbornly refuses to be deleted by conventional means. HijackThis introduced, in version 1.98.2, a method to have Windows delete the file as it boots up, before the file has the chance to load. To do this follow these steps:

Start Hijackthis
Click on the Config button
Click on the Misc Tools button
Click on the button labeled Delete a file on reboot…
A new window will open asking you to select the file that you would like to delete on reboot. Navigate to the file and click on it once, and then click on the Open button.
You will now be asked if you would like to reboot your computer to delete the file. Click on the Yes button if you would like to reboot now, otherwise click on the No button to reboot later.

Thanks
Hi Phil -

Here's what I've done recently:

1) You seem very surprised that HJT is not fixing the items you ask me to check. So I tried something else before starting with your latest instructions. I ran HJT in safe mode to see if it would make a difference. They are still there.

2) I ran L2M Destroyer. It found a bunch of restore files, log below.

3) I checked for the third time: no filed called test.exe exists on my hard drive. There is no TClock folder or file either. I do have the folder file display settings as you instructed.

4) I ran HJT one more time, checking the 8 remaining items we are trying to still get rid of. They are still there. Last HJT log below. I bolded the 8 items we have been repeatedly trying to fix.

My computer seems to be running fine now. I haven't had any popups, ads, or strange programs downloaded. The only slightly unusual thing is that a windows explorer window pointed to C:/WINDOWS/
system32 still pops up when Windows starts. It started doing this right before all the trouble began.

regards,

scott


==========================

Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 8/28/2006 8:01:09 PM

Infected! C:\WINDOWS\system32\guard.tmp
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048333.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048334.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048335.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048336.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048337.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048338.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048339.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048340.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048341.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048342.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048343.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048344.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048345.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048346.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048347.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048348.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048349.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048350.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048351.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048352.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048353.dll
Infected! C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048354.dll

Attempting to delete infected files…

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048333.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048333.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048334.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048334.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048335.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048335.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048336.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048336.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048337.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048337.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048338.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048338.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048339.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048339.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048340.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048340.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048341.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048341.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048342.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048342.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048343.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048343.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048344.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048344.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048345.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048345.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048346.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048346.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048347.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048347.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048348.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048348.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048349.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048349.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048350.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048350.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048351.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048351.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048352.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048352.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048353.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048353.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048354.dll
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048354.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F449501E-5E79-4BD3-89B6-C427E848AD2B}"
HKCR\Clsid\{F449501E-5E79-4BD3-89B6-C427E848AD2B}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{ED767CFC-038A-47ED-95E6-03F4763B641D}"
HKCR\Clsid\{ED767CFC-038A-47ED-95E6-03F4763B641D}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F5DC7FF0-2DE5-4EE1-9CBB-A324D6344EF1}"
HKCR\Clsid\{F5DC7FF0-2DE5-4EE1-9CBB-A324D6344EF1}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{DD3B27E3-1549-4A6E-8A95-5BD89B84A97E}"
HKCR\Clsid\{DD3B27E3-1549-4A6E-8A95-5BD89B84A97E}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

==============================================

Logfile of HijackThis v1.99.1
Scan saved at 8:24:06 PM, on 8/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
OK Scott and thanks for the information, you did still have Look2me infecting you, go ahead and clean your System Restore files like this:
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgen…src=sec_doc_nam
Make sure you reboot between turning it off and turning it back on.

This one worries me: O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab I can't open the link: http://download.cdn.winsoftware.com/ and it looks like an installer. Do you know what it is? If not, try this.
Internet Explorer > Tools > Internet Options > Settings > View Objects > locate that Program File and highlite it, then hit delete. Let me know what happens.

Let's make sure something in the Hosts file is not causing the problem, download funkytoad from here:
http://www.funkytoad.com/hoster.htm When you have it, hit the button "Restore Microsoft's Original Hosts File.

Looks like DelDomains got rid of this one: O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) :angry:

Let me see a BlackLight scan please, download from here: https://europe.f-secure.com/blacklight/try.shtml
Just run the scan and post the results, do not fix anything until I look.

Last, if you would, this program has been doing a great job, though I am new to it. Download the free program and remove anything it says is bad, unless you know otherwise.
http://www.prevx.com/ Let me know what it locates. If it creates a scan report, would you post that for me.

Make sure you restart the computer, post any information I requested, the results of the BlackLight scan, the results of the Prevx scan if there is one, or at least verbal information. Also, please continue to include any comments you think will help.

I am interested in any problems you are having with the computer now.

Thanks…Phil
Hi Phil - Tonite's accomplishments: 1) Turned System Restore off -> on 2) O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}: I do not recognize the website associated with this item. Used IE to view program files. There were about a dozen (half alpha-numeric strings and half names I could read like Shockwave and JRE). The string (above) we are trying to get rid of was NOT listed. The properites for all the entries showed legit sources. 3) Used funkytoad to restore MS hosts. The program didn't give me any feedback other than to say it did it. 4) Blacklight did not find anything 5) I had problems with Prevx. I downloaded the installer and it seemed to run fine. It said it was done and asked me to hit OK to reboot. Upon restart, I went into the the MS disk scan and got a Windows error message. I could not find any Prevx program folder, icon, or file - so I ran the installer again. It said Prevx was already installed. I searched the HDD for any Prevx file/folder and only found the install program. Not sure what to do with this one… I have not had any problems with the computer since I did the lion's share of what you suggested. The only two minor issues I can think of are the System32 folder that pops up upon startup and that internet surfing seems a little slow (but that could be network traffic and/or the fact that all my temp files were blown away). later, scott
There is no doubt that ActiveX is a bad one, probably the source of all the problems:
http://www.castlecops.com/ActiveX.html
X {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} WinAntiVirusPro2006FreeInstall.cab Related to the rogue program WinAntiVirus Pro2006.

These lowlife get better and better at hiding this junk from us. For some reason you choose to ignore these items?

C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045010.exe -> Not-A-Virus.Downloader.Win32.FunWeb : Ignored.
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IGBFYK9V\WinAntiVirusPro2006ScannerInstall[1].cab/UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Ignored. <<< that is the Winfixer installer
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048258.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048269.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048248.exe -> Not-A-Virus.Hoax.Win32.Renos.dc : Ignored.
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored. No doubt that one is bad, scan it to find out:

The Google on netmon.exe:
http://www.google.com/search?sourceid=navc…;q=netmon%2Eexe

http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html


The System Restore files should be gone but would you please boot to safe mode and run ewido again, remove anything it locates, and post the scan results. Once you do that, then try to remove that bad Active X:
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab With HJT.

I still need you to explain this better:

The only two minor issues I can think of are the System32 folder that pops up upon startup


and that internet surfing seems a little slow (but that could be network traffic and/or the fact that all my temp files were blown away).

Not sure, once we have a clean computer we can discuss this one.


I know Prevx runs and runs well on Windows XP, see if you can uninstall it completely, we may try it again later.

Thanks
Hi Phil - You totally lost me - I'm not following your last post. You were explaining that you want to get rid of the bad ActiveX, and I saw on CastleCops what you were talking about (…3F3A). But what's all that stuff afterward about ignoring things? I don't get what you are saying - it doesn't seem to apply to me. Please explain… I ran Ewido in Safe Mode and it found some more stuff (log below). I've had Ewido disabled since I've been running all this scanning programs. System32: when Windows starts up, a Windows Explorer window opens up, displaying the contents of WINDOWS/System32. Not a big deal, but this started about when all my problems did - thought it might be a clue for you. Only unusual thing I've noticed. I'm still having no luck with Prevx. I went to Add/Remove Programs and selected Prevx. It told me the program was already removed and asked if I wanted to remove it from the program list. I said yes and tried to reinstall. The installer stops and tells me it is already installed, but it is nowhere to be found. Wierd. scott =================================== ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 9:41:41 PM 8/30/2006 + Scan result: C:\Documents and Settings\Scott\Cookies\scott@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Scott\Cookies\scott@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Scott\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\Scott\Cookies\scott@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Scott\Cookies\scott@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Scott\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Scott\Cookies\scott@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Scott\Cookies\scott@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Scott\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\WINDOWS\system32\service\explorer.exe -> Trojan.Egold : Cleaned with backup (quarantined). ::Report end
Scott, in this post: Aug 26 2006, 02:21 PM in this ewido scan report:
ewido anti-spyware - Scan Report Created at: 1:07:40 PM 8/26/2006

Look closely at the report, there is a lot of junk and you are showing everything cleaned until you hit the ones I posted for you and they show "Ignored". Those were the items we were having trouble with. I do not see them in this last scan.

System32: when Windows starts up, a Windows Explorer window opens up,

Here are possible solutions:
http://support.microsoft.com/?kbid=170086
http://www.google.com/search?sourceid=navc…32+folder+opens

Everything else is running ok?

Thanks
Phil - I understand. That's strange because I always tell Ewido to fix everything. But sounds like they are gone now. The System32 folder thing sounds like a sleeping dog that I will let lie. I don't need to be editting registry files to try to fix it. Just wanted to make sure it wasn't due to some program trying to access that directory - seems a lot of the junk has been living in that directory. PC seems to be running fine. Now the question that you have probably gotten a thousand times - what do you recommend for a cost effective virus/malware program? I have a cable modem, don't go online a whole lot with this PC, and use Yahoo mail. thanks, scott

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI