This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan horse Generic.XFV, Trojan horse Clicker.FR, then Trojan horse G

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I know there have been a few resolved logs on this topic, but nevertheless i wanted to make sure i fixed this right. My AVP is having a rapid fire attack of these three trojans (Generic XFV, Clicker.FR, and Generic.XKS) and cannot fix it. Please help, here is my log…

Logfile of HijackThis v1.99.1
Scan saved at 11:18:55 PM, on 9/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\Russell\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jmu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [ntwpq.exe] C:\WINDOWS\system32\ntwpq.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0020C09-6C80-4B71-B192-77E9D2A386D7}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)

Thanks a bunch.
Hi I'm Angelfire777 and it'll be my pleasure to assist you in your problem. Reasearching Hijackthis logs could take sometime so please, be patient while I research a fix for you. Also, I have to let experts check my fixes first before bringing them to you. Please observe these while we work: 1.) Please stick with this thread until we are finished, do not start a new topic here or start a new thread at other forums. Do not worry, We were trained to help and never give up until we get you all fixed up. 2.) Stop if you have questions!! Never proceed if something is unclear to you. We don't want to start all over again. 3.) Avoid downloading other applications or other anti-spyware programs unless you really need to. 4.) Lastly, please be patient and never lose hope. Sometimes, it will take us several tries and posts to get something done. Sit back tight, I'll be back for you!
Hijackthis needs to be in its own folder:

a.) While in your desktop, Right click in the background > Go to new > Click folder > Name the folder HJT

b.) After creating the folder, find your Hijackthis.exe (it looks like a detonator with some dynamites). Then drag and drop that file to the new folder you created.
==========================
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download Fixwareout.exe by LonnyRJones from one of these two locations, and save it to your Desktop:

http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

2) Download the trial version of Ewido anti-spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating Ewido: below.

* Please note that these instructions are for the new version - Ewido anti-spyware. If you have the old version - Ewido anti-malware and it is the:
  • paid-for version - you will need to go here and obtain an updated license code before you upgrade.
  • free version - you will need to uninstall it and reboot before installing the new version.
Double click the ewido-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, Ewido anti-spyware will open.
  • Updating Ewido:

    By default Ewido is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either Ewido will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed Ewido, double click ewido-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close Ewido anti-spyware.

Ewido anti-spyware is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that Ewido will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) You will need to know how to boot into Safe Mode.
Instructions can be found here.

Please Note: You will need to remain connected to the internet during this fix.

Removal


1) Double click Fixwareout.exe to start the Fixwareout Setup Wizard
  • Click Next > Install.
  • Ensure that the box to the left of Run fixit is checked.
  • Click on Finish.
  • Follow the prompts.
  • You will be asked to reboot your computer - please do so. Your system may take longer than usual to load - this is normal.
2) Go to Start > Control Panel >Network Connections. Right click your default connection, usually Local Area Connection or Dial-up Connection if you are using dial-up, and left click on Properties.
* Make a note of the settings before you change them just in case you need to put them back how they were.
Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice.

3) Go to Start > Run, enter CMD and click OK.
  • At the Dos Prompt Screen, type in cd\ and then press .
  • Now type in ipconfig /flushdns and then press . (notice the space after ipconfig)
  • Close the command prompt window.
4) Boot into Safe Mode.

5) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

6) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

7) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

8) Ensure that ALL open Windows / Programs / Folders are closed and then run Ewido anti-spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that Ewido has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When Ewido has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\ewido anti-spyware 4.0\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close Ewido Anti-Spyware.

9) Boot into Normal Mode.

Post a new HJT log, the Ewido log, the contents of the logfile C:\fixwareout\report.txt AND a description of how your PC is running.
hi, thanks for the help, you rock…but this system is tanking fast…i now have some kind of faux spyware ad as my desktop background :angry: sigh…anyway, i ran the fixwareout program but when it started its check after reboot it got hungup at 4% on the search process with the win2k2 file i think. Any thoughts? Here is my current log…

Logfile of HijackThis v1.99.1
Scan saved at 1:31:20 PM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [hovcy.exe] C:\WINDOWS\system32\hovcy.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0020C09-6C80-4B71-B192-77E9D2A386D7}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)
ok, i'm stupid and figured out the fixwareout thing, i just looked for the win2k2 file and then hit execute, and then followed your other instructions. my computer seems better now, but there is still slow-down and my desktop background is now blinking between grey and white. first, here is what i get when i right click on my desktop and hit source:


***** This file is automatically generated by Microsoft Windows *****
——–>

style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none"
bottomMargin=0 bgColor=#3a6ea5 leftMargin=0 background="" topMargin=0
rightMargin=0>
style="LEFT: 0px; WIDTH: 1024px; POSITION: absolute; TOP: 0px; HEIGHT: 768px">[image unavailable: image] style="LEFT: 0px; WIDTH: 100%; POSITION: absolute; TOP: 0px; HEIGHT: 100%" cache
src="file:///C:/WINDOWS/Firefox%20Wallpaper.bmp">


 


its properties also say it is an http file, non-encrypted, and is located at
file://C:\WINDOWS\desktop.html


also, here is the log from ewido and an updated hijackthis
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 5:05:49 PM 9/2/2006

+ Scan result:



C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\e9e0c67a4854855d514f79c8670ce366 -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\FLEOK\msbb.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msbb.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\180solutions -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\180solutions\msbb -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\catsrv51.exe.q_8047002_q -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\Overpro-347.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\acledit4.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\camocx03.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\iehost34.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\terabyte.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\WINDOWS\system32\unwise56.exe -> Adware.AdSrve : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\35569fe9c3ec913aa556b9f4541fe3c1 -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\d75ac80aa00f31286174cb9ab9122d84 -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network\bin -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\Program Files\BullsEye Network\bin\bargains.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\MoreResultsSetup.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msbb321.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\eXactUtil -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\09a4b1807ce9cbd972dda1ee484c83ef -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\6c1b8ef6e3ca2f2aa8d663295f6433bf -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\6f3d872e841a1e4b557e91d32a1d54a9 -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\89015e0ad3bb8187347e383786c6524e -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\9b9bdb9a1e5f77a33f390d75f887bcd7 -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\preInsMt.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\preInsTT.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao.1 -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao\CLSID -> Adware.BlazeFind : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Jao.jao\CurVer -> Adware.BlazeFind : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{49F365E8-0D7B-4236-85E0-CBD6E2696F11}.exe -> Adware.Casino : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\CSIE.DLL.q_FFC8401_q -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\ff42e1ba6190a2ebcf3123dd869c772d -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\IEagent\CSBIINST.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\IEagent\CSSSINST.DLL -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\Lycos\Sidesearch\ClrSchUninstall_78_86.exe -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\Loader -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\SideBars -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\SideSearch -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClrSch\resolvers -> Adware.ClearSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ToolBand.ToolBandObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0f12c6b15f848517c04793a55a6fb5d3 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\24fa7d5443c3f99b0772c569420402a5 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\5ad00ef2bf2b15f86aa5d8b2d132a111 -> Adware.EZula : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\684a2a4cda9d45a1f64fd535b0c654cc -> Adware.EZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer -> Adware.eZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer\CHPON.dll -> Adware.eZula : Cleaned with backup (quarantined).
C:\Program Files\Web Offer\wo.exe -> Adware.eZula : Cleaned with backup (quarantined).
C:\WINDOWS\woinstall.exe -> Adware.EZula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaMain.eZulaPopSearchPipe\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer\Setup -> Adware.Ezula : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Web Offer\Setup\ID -> Adware.Ezula : Cleaned with backup (quarantined).
C:\WINDOWS\system32\GrlNt0i.dll -> Adware.F1Organizer : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0865BE98-4E6A-45FE-BAA2-D91EBEB21A2E}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0E310E29-5AC3-4BCD-BC8F-A9D1931DBE21}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{121787DC-BF4C-405A-8BCC-06168B887D37}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{1AAE6EFA-3277-4F8F-AF0C-4979CF8833EF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{29353D1E-1E8B-4FA7-BB26-F5A336AD2ABF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2B9DF4CE-1863-4BB3-B7D8-B41E50B3DB6B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{68A54CE1-4A90-40F1-B142-204428E8EEEE}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{6E3C1B44-7519-4551-91AE-5A38DE10DC16}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{98464BFC-E5CC-472A-A616-D506DB707F67}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A5163EE6-6B60-4E35-AEC8-FDE8241DF678}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AC18ECBC-F384-4404-95A3-9CCBCDD41FC0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AE3E6357-DA83-4120-B392-FED7213FEC7A}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B3A74C2C-DDA1-488F-BFB5-9336F2EFF5FD}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B3BAB8E4-E2F0-437D-867C-989D72133A2B}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B5E13677-A0E8-4CBA-A1E1-9E7507D78115}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B91E5A77-F487-4371-A24A-2D3FFBB68D01}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BEFEA71B-BC62-472E-BC89-E7DB0208FB58}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C50061AC-2CF5-4E1B-ADC9-D4A125773E2D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C59339E6-C790-4BE2-BA69-52BB717346B3}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C8C13E1E-BB07-4A97-B160-6D05DBB5B486}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{CD6E6D3D-1E36-482A-AECA-D2F371D7EDC0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E793F7C1-1F84-4C2D-B220-BA85E879F8A8}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{EDC9AB10-FF90-4492-AD79-56B4A066BD94}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FBAF4904-FB6B-4CCB-B5C2-DD3868C426EA}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Media-Codec.Chl -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Media-Codec.Chl\CLSID -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\b66fb5c26f91a2dbd4a3ad17dcccdb8d/systb.dll -> Adware.ImiBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-515967899-1532298954-839522115-1003\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\updater -> Adware.KeenValue : Cleaned with backup (quarantined).
HKLM\SOFTWARE\updater\{8D15A72D-62E0-4733-B057-0A81B4FFEB3D} -> Adware.KeenValue : Cleaned with backup (quarantined).
HKLM\SOFTWARE\MaxSpeed -> Adware.Maxspeed : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\EULA.URL -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\MemoryWatcher.exe -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
C:\Program Files\MemoryWatcher\TrayIcon.ocx -> Adware.MemoryWatcher : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\midADdle -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WildMedia -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WildMedia\LicenseStores -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\midADdle -> Adware.MidAddle : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{76F6B2F3-2B46-4F52-9BF0-23BC630D3B78}.exe -> Adware.Msnagent : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\rvqhr.dll.q_8048002_q -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\urpo.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rυndll.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\ClickSpring -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{398B84A7-D2E7-4760-85A4-EC3F120E8FBA}.exe -> Adware.Raze : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA Software Installer -> Adware.SafeSurfing : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer Software Installer -> Adware.SafeSurfing : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\8c18963519f11c3036a5401b81b44287 -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\SahHtml_.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SahHtml.exe -> Adware.Sahat : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sahagent1019.exe -> Adware.Sahat : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SEP -> Adware.SEP : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Privacy Info.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Terms and Conditions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\MaxSpeed\Uninstall Instructions.url -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\SEP -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Program Files\SEP\sep.dll -> Adware.SideFind : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\b05d7c2eb5067ccbf631742e510fb8f4 -> Adware.Sidesearch : Cleaned with backup (quarantined).
C:\Program Files\Alcohol Soft\Alcohol 120% Toolbar\a120_tb.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan\ceutil58.exe.q_8041001_q -> Adware.UrlSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\clbcatex.exe -> Adware.UrlSpy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DMO -> Adware.VX2 : Cleaned with backup (quarantined).
C:\Program Files\Common Files\midaddle\WildWinTracker.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
C:\WINDOWS\system32\silent.exe -> Adware.WinFetcher : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer.1 -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CurVer -> Adware.YourSiteBar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\csero.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\setup_incred_8.exe -> Downloader.Keenval : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2A22AD41-B07E-4A5D-ADB2-F6F3B075F6B6}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{4BE76ACB-8C56-4448-9436-5B30858B822B}.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\0021-bdl94126.EXE -> Downloader.VB.ca : Cleaned with backup (quarantined).
C:\WINDOWS\desktop.html -> Not-A-Virus.Hoax.Win32.Aflac.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0D61E880-95AE-4DA7-8FC6-506214682135}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{12FCD71D-951A-4602-B930-E426494F1DF0}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\28df04be958b091cd20727d43b04b445 -> Trojan.MemwatchAd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0A58A3FA-CB40-4898-96E5-D1798781A352}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{14EB22AD-772D-4613-B57A-FD9E68DB27A6}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{293FB7E7-028C-4AE5-A976-388C643A6248}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2D171C5A-A472-4527-A46E-5F527420B2D4}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3980395F-2F6E-4EF5-9D10-FF84C9951391}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{61AAE436-77E6-48B5-B799-763E9CFB1D7B}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{67778CCF-08DD-4DDA-86AF-310B1EE7BBC7}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{8DBAE51C-4459-493E-846F-449E04D0D5A1}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9079F124-FBB0-43E6-AF0A-2E613717BB43}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{994848BD-04C6-4D18-9374-623F8DCB4F6A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9D1EF86C-5CFC-4B0F-B0AE-1DA650E51679}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B096A208-4C4B-4322-85BD-95134831368A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BBF11D71-7228-43B2-BB3C-BE6903D2D9DF}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C16928FB-948F-4987-8A24-B26504FF399A}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C9773CDE-5334-4ACA-BCC4-A9DE2184F358}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{CD08F5A8-0918-4677-ACB8-61DA88A76ACD}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{D5DE4E05-75DB-4C42-8E7E-F44553E945FE}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{DC51C070-123F-4881-B2EB-988E86BA95DA}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E0B9D55D-BA29-4A5A-8AF9-565867BB3BA6}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E23837B2-51BC-43FF-92A4-D5C44681F19C}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E8E73C4A-87D7-427B-9AA1-99AF61D34915}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{ED14F2A3-075C-43D7-A18B-4BBC7F9040B8}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F4D19EB8-7ECD-47FA-81A9-E89E83BEE606}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FCDC95E7-C462-49B5-8E1E-E8B52CDBEACD}.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\0e5c4ef61a2b9aca928117ec6c55f33f -> Trojan.Septic.a : Cleaned with backup (quarantined).
C:\SEPinst.exe -> Trojan.Septic.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmawg.exe -> Trojan.Small.fb : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{14474303-759F-4799-8AA6-FD26D12069DA}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2A0C71B9-1C12-4E0B-B46B-C6CE020E4248}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2DB8D9E7-B6F5-4CB2-858F-998C8291BF3E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2EB39867-B32D-4B3B-999A-26D92D336FEA}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3348AF28-46A0-41B3-AB1A-531D6C4B92C5}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3C066E59-41F8-48A1-8AEB-35B849E91003}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{43E285EF-6E5D-4EEC-850D-0A02B095A000}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{51D978CF-476E-4A29-9749-4437F8718509}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{6E9B416A-C5EF-46F9-B487-030A5CDFD43F}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{73A98F53-171A-42ED-8418-A25F0AA90628}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{7476B804-C7B6-4466-B81C-D6B9BBACF18C}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{7F069BF6-B387-4EC5-8F49-221DAAD904A5}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{9259A184-6783-4EB6-8F51-4F91D6F5CF75}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A1B8DD77-C91E-4750-A984-2B507CF3CBD1}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{A99C0143-B559-4F7F-92BD-6BC1092622F6}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AB5D8654-249E-480C-BC10-13096FB574B6}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B13895B7-3B14-4432-BF08-71CF9A02A11B}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{B24BC282-1798-4BFB-A012-B1274248B2F9}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{BE147E5C-AE30-4060-8D0D-50F1CE93FDF1}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{EF50BE81-BBFB-4DAC-BD62-F9B2B8301B0E}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F08DE81C-F62D-4299-8CB5-98F8A6C3885F}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{F80A01D1-EF7C-42C9-871E-6B4A7B16F247}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FD3350B3-AE33-4E45-8833-B5D4EB11C85B}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FF5DF0CC-85EB-4F15-9085-EA0064FDFB68}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
C:\Documents and Settings\Russell\Application Data\Tenebril\GhostSurf\3.0\Spyware history\Restore\8240a5782c881b8508f89fcb144b9143 -> Trojan.VB.od : Cleaned with backup (quarantined).


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 5:19:08 PM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\SYMANT~1\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\system32\{51D33DF5-4CAF-4857-AFE9-AD83A889F459}.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [hovcy.exe] C:\WINDOWS\system32\hovcy.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

any help in tying up any loose viruses/malware etc…would be greatly appreciated (especially making sure those three trojans are gone, because i don't remember seeing those particular trojans on the ewido list)

also, this ewido program rocks, i'm going to buy a copy of it after i get my computer cleaned up (and possibley reformatted). peace.
and yeah, they're still there, as soon as i opened firefox i started seeing the spybot trojan horse gneric.xfv etc. warnings, though this time it was able to quarantine. weird. so i still have the desktop background blinking white and grey with the normal right click properties disabled and the trojans are still on my system, though they appear to be quarantined at the moment anyway…
ok, another update.

still have grey and white blinking background, but ran the fixwareout program again and it seems to have actually worked this time.

here's its log:

Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5CE8A4D7E34A-A8E9-BD94-7126-F7164EB3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5C29B4C6D135-A1BA-3B14-0A64-82FA8433{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D2E377521A4D-9CDA-B1E4-5FC2-CA16005C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}87B3D036CB32-0FB9-25F4-64B2-3F2B6F67{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}853F4812ED9A-4CCB-ACA4-4335-EDC3779C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}360CB47FEF9B-68B9-B514-7DF0-E526EF54{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E0B1038B2B9F-26DB-CAD4-BFBB-18EB05FE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}684B5BBD50D6-061B-79A4-70BB-E1E31C8C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A6F4BCD8F326-4739-81D4-6C40-DB848499{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E088EC6DBD2C-3B7A-95E4-2AF5-E06E7947{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}30019E948B53-BEA8-1A84-8F14-95E660C3{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}85BF8020BD7E-98CB-E274-26CB-B17AEFEB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6A72BD86E9DF-A75B-3164-D277-DA22BE41{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1A9FBAD00333-9A09-E244-27E3-7E612608{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F34DFDC5A030-784B-9F64-FE5C-A614B9E6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}49DB660A4B65-97DA-2944-09FF-01BA9CDE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}253A1878971D-5E69-8984-04BC-AF3A85A0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ED66306E2F50-AE09-9594-E9A3-DE85CB24{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}5A409DAAD122-94F8-5CE4-783B-6FB960F7{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AE624C8683DD-2C5B-BCC4-B6BF-4094FABF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8B0409F7CBB4-B81A-7D34-C570-3A2F41DE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}91D574C42ED9-1FA8-CB84-D430-3C64F376{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A8D69B7A3D76-6A78-B9B4-35F7-5C858139{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B11A20A9FC17-80FB-2344-41B3-7B59831B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3B643717BB25-96AB-2EB4-097C-6E93395C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}51943D16FA99-1AA9-B724-7D78-A4C37E8E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6E67ED8B51FE-C86B-DB34-7718-88EDB761{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD96021D62DF-6AA8-9974-F957-30347441{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FE3388FC9794-C0FA-F8F4-7723-AFE6EAA1{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C91F18644C5D-4A29-FF34-CB15-2B73832E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F09F55F5F54D-14EB-0984-AA64-9A9DF185{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6F2262901CB6-DB29-F7F4-955B-3410C99A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}61CD01ED83A5-EA19-1554-9157-44B1C3E6{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4D2B024725F5-E64A-7254-274A-A5C171D2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E397389BA8A8-FB6A-2994-8B54-4B839BD4{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E3FB1928C899-F858-2BC4-5F6B-7E9D8BD2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8A8F978E58AB-022B-D2C4-48F1-1C7F397E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EF549E35544F-E7E8-24C4-BD57-50E4ED5D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}D8CAD2CE55A5-CCEA-4594-4FC8-3002FE63{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1DBC3FC705B2-489A-0574-E19C-77DD8B1A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}12EBD1391D9A-F8CB-DCB4-3CA5-92E013E0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1A5D0D40E944-F648-E394-9544-C15EABD8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}3C9C7210AED1-CBD8-80D4-7561-4A60E2AB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}000A590B20A0-D058-CEE4-D5E6-FE582E34{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B2A33127D989-C768-D734-0F2E-4E8BAB3B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}606EEB38E98E-9A18-AF74-DCE7-8BE91D4F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0F37C8A1F501-C7A8-8D84-B090-D1DDBF7E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8424E020EC6C-B64B-B0E4-21C1-9B17C0A2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0CF14DDCBCC9-3A59-4044-483F-CBCE81CA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}97615E056AD1-EA0B-F0B4-CFC5-C68FE1D9{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1289FF48935F-B1B9-84F4-6715-87FEF62B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9F2B8424721B-210A-BFB4-8971-282CB42B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}10D86BBFF3D2-A42A-1734-784F-77A5E19B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8426A346C883-679A-5EA4-C820-7E7BF392{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}676B9067B94D-3DAA-EBE4-4285-2310E28D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1FDF39EC1F05-D0D8-0604-03EA-C5E741EB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DF5FFE2F6339-5BFB-F884-1ADD-C2C47A3B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A86313843159-DB58-2234-B4C4-802A690B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}4443CD9B80AB-84F9-2C54-AB6A-04961665{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}C81FCABB9B6D-C18B-6644-6B7C-408B6747{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FBA2DA633A5F-62BB-7AF4-B8E1-E1D35392{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B7D1BFC9E367-997B-5B84-6E77-634EAA16{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8435A83FD79E-3EF8-5594-A532-E09ED789{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}82609AA0F52A-8148-DE24-A171-35F89A37{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}EEEE8E824402-241B-1F04-09A4-1EC45A86{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DCA67A88AD16-8BCA-7764-8190-8A5F80DC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E5CC0A5A11BE-953A-2144-29F3-7D61733D{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F5883C6A8F89-5BC8-9924-D26F-C18ED80F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}E2A12BEBE19D-2AAB-EF54-A6E4-89EB5680{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}34BB717316E2-A0FA-6E34-0BBF-421F9709{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}ED62EEBF2EEC-761A-B814-9FE7-04F48C35{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6B475BF69031-01CB-C084-E942-4568D5BA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B6BD3B05E14B-8D7B-3BB4-3681-EC4FD9B2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}7CBB7EE1B013-FA68-ADD4-DD80-FCC87776{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8B410144BBCE-ED1B-C674-074A-D199DF36{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}57FC5F6D19F4-15F8-6BE4-3876-481A9529{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}76F707BD605D-616A-A274-CC5E-CFB46489{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}6AB3BB768565-9FA8-A5A4-92AB-D55D9B0E{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}BAE1200710B9-D1BA-6B64-2565-D2C0C372{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}531286412605-6CF8-7AD4-EA59-088E16D0{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\gwamd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0FD1F494624E-039B-2064-A159-D17DCF21{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AEF633D29D62-A999-B3B4-D23B-76893BE2{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}51187D7057E9-1E1A-ABC4-8E0A-77631E5B{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}AD59AB68E889-BE2B-1884-F321-070C15CD{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A77279D5AF8E-E16A-AE24-5870-0705D379{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}742F61B7A4B6-E178-9C24-C7FE-1D10A08F{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}876FD1428EDF-8CEA-53E4-06B6-6EE3615A{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}1931599C48FF-01D9-5FE4-E6F2-F5930893{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8F3E63186230-3B29-5AF4-28F7-8FC0E6C8{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}9058178F7344-9479-92A4-E674-FC879D15{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A7CEF3127DEF-293B-0214-38AD-7536E3EA{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}DCAEBDC25B8E-E1E8-5B94-264C-7E59CDCF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}69875E6593EC-0E3B-B8B4-B2BC-5FD9A9EE{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}86BFDF4600AE-5809-51F4-BE58-CC0FD5FF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}73D788B86160-CCB8-A504-C4FB-CD787121{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}A993FF40562B-42A8-7894-F849-BF82961C{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}F1F97928C615-7FB8-29E4-9B76-D61EEE96{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}B58C11BE4D5B-3388-54E4-33EA-3B0533DF{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0CDE7D173F2D-ACEA-A284-63E1-D3D6E6DC{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}FD9D2D3096EB-C3BB-2B34-8227-17D11FBB{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}0576CEEEBD06-6B08-8724-F195-EBD49F47{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\swen
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\eerht
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\ypszr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\putesprpgd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\onisacputes
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names…

»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal

Other suspects.
Directory of C:\WINDOWS\system32
{74F94DBE-591F-4278-80B6-60DBEEEC6750}.exe
{69EEE16D-67B9-4E92-8BF7-516C82979F1F}.exe
{EE9A9DF5-CB2B-4B8B-B3E0-CE3956E57896}.exe
{8C6E0CF8-7F82-4FA5-92B3-03268136E3F8}.exe
{E3B106D0-2AE4-4C0D-8492-3281358D05D9}.exe
{273C0C2D-5652-46B6-AB1D-9B0170021EAB}.exe
{63FD991D-A470-476C-B1DE-ECBB441014B8}.exe
{53C84F40-7EF9-418B-A167-CEE2FBEE26DE}.exe
{56616940-A6BA-45C2-9F48-BA08B9DC3444}.exe
{E7FBDD1D-090B-48D8-8A7C-105F1A8C73F0}.exe
{36EF2003-8CF4-4954-AECC-5A55EC2DAC8D}.exe
{4DB938B4-45B8-4992-A6BF-8A8AB983793E}.exe
{581FD9A9-46AA-4890-BE41-D45F5F55F90F}.exe
{167BDE88-8177-43BD-B68C-EF15B8DE76E6}.exe
{673F46C3-034D-48BC-8AF1-9DE24C475D19}.exe
{42BC58ED-3A9E-4959-90EA-05F2E60366DE}.exe
{806216E7-3E72-442E-90A9-33300DABF9A1}.exe
{7497E60E-5FA2-4E59-A7B3-C2DBD6CE880E}.exe
{45FE625E-0FD7-415B-9B86-B9FEF74BC063}.exe

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.

also, here is an updated hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 5:55:54 PM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)

so, still trying to clean system and get my desktop back and fix slowdown (trojans are still possibly on the system?)

thanks
ok. got desktop back and everything seems ok…however, i just want to post my final log to make sure someone wiser doesn't see a problem i don't…the trojans had a nasty way of seeming gone and then magically appearing all of a sudden…

Logfile of HijackThis v1.99.1
Scan saved at 11:35:05 PM, on 9/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)

thanks
ok, thought everything was fine and began updating stuff and adding new security updates. now, my computer gets stuck before booting windows with this weird black, purple, and white swirly screen. when i boot up in safe mode it just flashes for a second and then windows boots up. any thoughts?
Logfile of HijackThis v1.99.1
Scan saved at 12:23:16 AM, on 9/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Russell\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - http://www.netpaloffers.net/NetpalOffers/DMO1/GrlNt0i.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/048868ac7c072b…ip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1156535059545
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/d…/ITDetector.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)
Open notepad. It must be notepad, not wordpad.
Copy and paste the text inside thequote box below into notepad
Choose file save as and set file type to all files.
Type delete.bat in the file name and save it to your desktop.

attrib -r -s -h C:\WINDOWS\desktop.html
attrib -r -s -h C:\WINDOWS\System32\SearchBar.htm
attrib -r -s -h C:\WINDOWS\system32\hovcy.exe
attrib -r -s -h C:\WINDOWS\system32\{74F94DBE-591F-4278-80B6-60DBEEEC6750}.exe
attrib -r -s -h C:\WINDOWS\system32\{69EEE16D-67B9-4E92-8BF7-516C82979F1F}.exe
attrib -r -s -h C:\WINDOWS\system32\{EE9A9DF5-CB2B-4B8B-B3E0-CE3956E57896}.exe
attrib -r -s -h C:\WINDOWS\system32\{8C6E0CF8-7F82-4FA5-92B3-03268136E3F8}.exe
attrib -r -s -h C:\WINDOWS\system32\{E3B106D0-2AE4-4C0D-8492-3281358D05D9}.exe
attrib -r -s -h C:\WINDOWS\system32\{273C0C2D-5652-46B6-AB1D-9B0170021EAB}.exe
attrib -r -s -h C:\WINDOWS\system32\{63FD991D-A470-476C-B1DE-ECBB441014B8}.exe
attrib -r -s -h C:\WINDOWS\system32\{53C84F40-7EF9-418B-A167-CEE2FBEE26DE}.exe
attrib -r -s -h C:\WINDOWS\system32\{56616940-A6BA-45C2-9F48-BA08B9DC3444}.exe
attrib -r -s -h C:\WINDOWS\system32\{E7FBDD1D-090B-48D8-8A7C-105F1A8C73F0}.exe
attrib -r -s -h C:\WINDOWS\system32\{36EF2003-8CF4-4954-AECC-5A55EC2DAC8D}.exe
attrib -r -s -h C:\WINDOWS\system32\{4DB938B4-45B8-4992-A6BF-8A8AB983793E}.exe
attrib -r -s -h C:\WINDOWS\system32\{581FD9A9-46AA-4890-BE41-D45F5F55F90F}.exe
attrib -r -s -h C:\WINDOWS\system32\{167BDE88-8177-43BD-B68C-EF15B8DE76E6}.exe
attrib -r -s -h C:\WINDOWS\system32\{673F46C3-034D-48BC-8AF1-9DE24C475D19}.exe
attrib -r -s -h C:\WINDOWS\system32\{42BC58ED-3A9E-4959-90EA-05F2E60366DE}.exe
attrib -r -s -h C:\WINDOWS\system32\{45FE625E-0FD7-415B-9B86-B9FEF74BC063}.exe
attrib -r -s -h C:\WINDOWS\system32\{806216E7-3E72-442E-90A9-33300DABF9A1}.exe
attrib -r -s -h C:\WINDOWS\system32\{7497E60E-5FA2-4E59-A7B3-C2DBD6CE880E}.exe
attrib -r -s -h C:\WINDOWS\System32\maxspeed.exe
del C:\WINDOWS\desktop.html
del C:\WINDOWS\System32\SearchBar.htm
del C:\WINDOWS\system32\hovcy.exe
del C:\WINDOWS\system32\{74F94DBE-591F-4278-80B6-60DBEEEC6750}.exe
del C:\WINDOWS\system32\{69EEE16D-67B9-4E92-8BF7-516C82979F1F}.exe
del C:\WINDOWS\system32\{EE9A9DF5-CB2B-4B8B-B3E0-CE3956E57896}.exe
del C:\WINDOWS\system32\{8C6E0CF8-7F82-4FA5-92B3-03268136E3F8}.exe
del C:\WINDOWS\system32\{E3B106D0-2AE4-4C0D-8492-3281358D05D9}.exe
del C:\WINDOWS\system32\{273C0C2D-5652-46B6-AB1D-9B0170021EAB}.exe
del C:\WINDOWS\system32\{63FD991D-A470-476C-B1DE-ECBB441014B8}.exe
del C:\WINDOWS\system32\{53C84F40-7EF9-418B-A167-CEE2FBEE26DE}.exe
del C:\WINDOWS\system32\{56616940-A6BA-45C2-9F48-BA08B9DC3444}.exe
del C:\WINDOWS\system32\{E7FBDD1D-090B-48D8-8A7C-105F1A8C73F0}.exe
del C:\WINDOWS\system32\{36EF2003-8CF4-4954-AECC-5A55EC2DAC8D}.exe
del C:\WINDOWS\system32\{4DB938B4-45B8-4992-A6BF-8A8AB983793E}.exe
del C:\WINDOWS\system32\{581FD9A9-46AA-4890-BE41-D45F5F55F90F}.exe
del C:\WINDOWS\system32\{167BDE88-8177-43BD-B68C-EF15B8DE76E6}.exe
del C:\WINDOWS\system32\{673F46C3-034D-48BC-8AF1-9DE24C475D19}.exe
del C:\WINDOWS\system32\{42BC58ED-3A9E-4959-90EA-05F2E60366DE}.exe
del C:\WINDOWS\system32\{45FE625E-0FD7-415B-9B86-B9FEF74BC063}.exe
del C:\WINDOWS\system32\{806216E7-3E72-442E-90A9-33300DABF9A1}.exe
del C:\WINDOWS\System32\maxspeed.exe

==========================
Open hijackthis > choose scan only > tick the boxes beside these entries in bold

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\System32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
R3 - URLSearchHook: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: LookSmart Toolbar - {CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS1\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS3\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212
O17 - HKLM\System\CS4\Services\Tcpip\..\{1015A3D8-E89E-4FE3-814D-D214AE1800C5}: NameServer = 85.255.114.72,85.255.112.212
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.72 85.255.112.212


close ALL browsers and windows/programs that are running, leave only hijackthis running then click "Fix Checked"
==========================
click start > run > type in taskmgr.exe

DO NOT CLOSE THIS UNTIL INSTRUCTED TO DO SO!!

Go to the process tab then end these processes if you see them:

explorer.exe

Your desktop will disappear, but that is normal. It will come back when you reboot.

Still in taskmanager, in the menu bar > click file > click new task(run) > on the new windows that opens, click browse then navigate to your desktop then click delete.bat then hit open then ok.

Browse to c:\fixwareout and click Fixit.bat –> open –> OK

This will start Fixwareout again then your computer will reboot automatically.
==========================
Now lets check some settings on your system.
(2000/XP) Only
  • In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections.
  • Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties.
  • Click the Networking tab.
  • Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
  • Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems


Next Go start > run > type cmd and hit OK

type ipconfig /flushdns

then hit enter, type exit hit enter
(that space between g and / is needed)
==========================
On your next reply, please include:
  • A Fresh Hijackthis log
  • fixwareout report
  • A detailed description on how your computer is behaving

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI