This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan problem..

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to help a friend and his daughter. They have a laptop which I believe is infected with a number of Trojans. I have removed their out of date Norton Security suite and run AGV and Adware. Found a variety of trojans but can not remove them . Could you please check the log file and advise. Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 21:32:25, on 27/08/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\Common Files\Services\wsys.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Dixons\Picture Suite\InsDetect.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Rachel\Local Settings\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {60D8B5EB-5CE9-47B8-8002-9D3D17858807} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Enumeration Service ] C:\Program Files\Common Files\Services\wsys.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [Dixons Insert Detect] C:\Program Files\Dixons\Picture Suite\InsDetect.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Recycled\Q330995.exe
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1156372311565
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
Apologies for posting log before I had done a complete Self-Help job. I have now followed the instructions in full.

Aditional info: on restart a message comes up saying wsys.exe can not start due to a missing dll.

Hijackthis and exido Log files:-

Logfile of HijackThis v1.99.1
Scan saved at 13:26:53, on 28/08/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Dixons\Picture Suite\InsDetect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\TextPad 4\textpad.exe
C:\Documents and Settings\Rachel\Desktop\analyse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {60D8B5EB-5CE9-47B8-8002-9D3D17858807} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [Enumeration Service ] C:\Program Files\Common Files\Services\wsys.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [Dixons Insert Detect] C:\Program Files\Dixons\Picture Suite\InsDetect.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Recycled\Q330995.exe
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1156372311565
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe


———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 09:49:25 28/08/2006

+ Scan result:



HKLM\SOFTWARE\DelFin -> Adware.Delfin : No action taken.
HKLM\SOFTWARE\DelFin\PromulGate -> Adware.Delfin : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DelFin Media Viewer -> Adware.Delfin : No action taken.
HKU\S-1-5-21-3825283475-2669302297-488748980-1005\Software\DelFin -> Adware.Delfin : No action taken.
HKU\S-1-5-21-3825283475-2669302297-488748980-1005\Software\DelFin\PromulGate -> Adware.Delfin : No action taken.
C:\System Volume Information\_restore{9BF0096A-DB0E-4D06-B5C4-7B2F27AA7BDC}\RP355\A0051642.exe -> Adware.NewDotNet : No action taken.
C:\System Volume Information\_restore{9BF0096A-DB0E-4D06-B5C4-7B2F27AA7BDC}\RP356\A0051686.exe -> Adware.NewDotNet : No action taken.
C:\WINDOWS\NDNuninstall4_80.exe -> Adware.NewDotNet : No action taken.
C:\WINDOWS\NDNuninstall4_88.exe -> Adware.NewDotNet : No action taken.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : No action taken.
C:\Program Files\Common Files\Services\wsys.dll -> Not-A-Virus.Monitor.Win32.Iopus.A : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@amazonms.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@bellglobemediapublishing.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@cneteurope.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@ford.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@marksandspencer.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@maximintegratedproducts.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@propertyfinderltd.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@redcats.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@thomascook.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@oewabox[1].txt -> TrackingCookie.Oewabox : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Rachel\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Rachel\Cookies\rachel@web-stat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\System Volume Information\_restore{9BF0096A-DB0E-4D06-B5C4-7B2F27AA7BDC}\RP355\A0051640.exe -> Trojan.Dialer.gg : No action taken.
C:\WINDOWS\system32\r4yle.dll -> Trojan.Kolweb.f : No action taken.
C:\Documents and Settings\Rachel\Local Settings\Temp\qr045rg.sys -> Trojan.Kolweb.g : No action taken.
C:\WINDOWS\qr045rg.sys -> Trojan.Kolweb.g : No action taken.
C:\WINDOWS\system32\71u9c7.exe -> Trojan.Kolweb.g : No action taken.
C:\WINDOWS\system32\qb9wk.exe -> Trojan.Kolweb.g : No action taken.
C:\WINDOWS\system32\qr045rg.sys -> Trojan.Kolweb.g : No action taken.
C:\WINDOWS\Clearer.exe -> Trojan.Small : No action taken.
C:\WINDOWS\system32\Clearer.exe -> Trojan.Small : No action taken.


::Report end
Hello and welcome at TomCoyoteforum, Sorry for the delay in responding, it's been pretty busy here and not all logs get answered as quickly as we'd like. If you still need help with your problem, please reply to this message with a new HijackThis log. Also: Scan again with Ewido and then click "apply all actions" to move the file to the quarantine. I will be notified automatically when you reply. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI