This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cant do system restore

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there!

Was wondering if anyone out there can help me? My computer wont let me do a system restore?
Here is my hijack log. I had some spyware and removed it, but still no go. Any suggestions.

Thankyou in advance!



Logfile of HijackThis v1.99.1
Scan saved at 8:37:32 PM, on 5/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\Chris\My Documents\Unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.iprimus.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iprimus.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.iprimus.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iprimus.com.au
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://au.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.iprimus.com.au:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.31.*;192.168.*;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CBHOBJObj Object - {8A406068-D45C-40B9-A096-38AC717FB608} - C:\WINDOWS\BHOBJ.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus Photo R310 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE /P30 "EPSON Stylus Photo R310 Series" /O6 "USB001" /M "Stylus Photo R310"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131105775901
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello originalwitty,

Let's make sure your system is clean before we work on the system restore problem.



STEP 1.
======
SpySweeper
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
  • If you are taken to the internet page, just close the page.
  • You will be prompted to check for updated definitions, please do so.
    (This may take several minutes)
  • Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
  • Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
  • When the sweep has finished, click Remove. Click Select All and then Next
  • From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
Please post the results from SpySweeper, ewido and a new hijackthis log.
Hello there!

Thankyou for replying so quickly. Here is the logs:

Spy Sweeper

8:19 PM: Removal process completed. Elapsed time 00:00:14
8:19 PM: Quarantining All Traces: whenu savenow
8:19 PM: Quarantining All Traces: whenu
8:19 PM: Quarantining All Traces: zedo cookie
8:19 PM: Quarantining All Traces: yadro cookie
8:19 PM: Quarantining All Traces: xiti cookie
8:19 PM: Quarantining All Traces: myaffiliateprogram.com cookie
8:19 PM: Quarantining All Traces: clixgalore cookie
8:19 PM: Quarantining All Traces: web-stat cookie
8:19 PM: Quarantining All Traces: videodome cookie
8:19 PM: Quarantining All Traces: valuead cookie
8:19 PM: Quarantining All Traces: tribalfusion cookie
8:19 PM: Quarantining All Traces: tradedoubler cookie
8:19 PM: Quarantining All Traces: tacoda cookie
8:19 PM: Quarantining All Traces: reliablestats cookie
8:19 PM: Quarantining All Traces: statcounter cookie
8:19 PM: Quarantining All Traces: onestat.com cookie
8:19 PM: Quarantining All Traces: spylog cookie
8:19 PM: Quarantining All Traces: serving-sys cookie
8:19 PM: Quarantining All Traces: server.iad.liveperson cookie
8:19 PM: Quarantining All Traces: rn11 cookie
8:19 PM: Quarantining All Traces: starpulse cookie
8:19 PM: Quarantining All Traces: revenue.net cookie
8:19 PM: Quarantining All Traces: partypoker cookie
8:19 PM: Quarantining All Traces: overture cookie
8:19 PM: Quarantining All Traces: maxserving cookie
8:19 PM: Quarantining All Traces: webtrends cookie
8:19 PM: Quarantining All Traces: domainsponsor cookie
8:19 PM: Quarantining All Traces: hypertracker.com cookie
8:19 PM: Quarantining All Traces: humanclick cookie
8:19 PM: Quarantining All Traces: go.com cookie
8:19 PM: Quarantining All Traces: fastclick cookie
8:19 PM: Quarantining All Traces: dl cookie
8:19 PM: Quarantining All Traces: directtrack cookie
8:19 PM: Quarantining All Traces: clickbank cookie
8:19 PM: Quarantining All Traces: burstnet cookie
8:19 PM: Quarantining All Traces: bs.serving-sys cookie
8:19 PM: Quarantining All Traces: bluestreak cookie
8:19 PM: Quarantining All Traces: a cookie
8:19 PM: Quarantining All Traces: atwola cookie
8:19 PM: Quarantining All Traces: atlas dmt cookie
8:19 PM: Quarantining All Traces: ask cookie
8:19 PM: Quarantining All Traces: falkag cookie
8:19 PM: Quarantining All Traces: apmebf cookie
8:19 PM: Quarantining All Traces: adreactor cookie
8:19 PM: Quarantining All Traces: pointroll cookie
8:19 PM: Quarantining All Traces: specificclick.com cookie
8:19 PM: Quarantining All Traces: hbmediapro cookie
8:19 PM: Quarantining All Traces: yieldmanager cookie
8:19 PM: Quarantining All Traces: about cookie
8:19 PM: Quarantining All Traces: 247realmedia cookie
8:19 PM: Quarantining All Traces: 2o7.net cookie
8:19 PM: Quarantining All Traces: primaryads cookie
8:19 PM: Quarantining All Traces: java byteverify
8:19 PM: Quarantining All Traces: webdir
8:18 PM: Quarantining All Traces: marketscore
8:18 PM: Removal process initiated
8:16 PM: Traces Found: 87
8:16 PM: Full Sweep has completed. Elapsed time 00:18:01
8:16 PM: File Sweep Complete, Elapsed Time: 00:16:36
8:15 PM: Warning: Failed to access drive D:
8:15 PM: C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-7e4442f4-312d851d.class (ID = 64821)
8:15 PM: Found Adware: java byteverify
8:13 PM: Warning: Failed to open file "c:\windows\system32\spool\printers\fp00000.shd". The operation completed successfully
8:13 PM: Warning: Failed to open file "c:\windows\system32\spool\printers\fp00000.spl". The operation completed successfully
8:13 PM: Warning: Failed to open file "c:\documents and settings\chris\cookies\chris@cdcovers[2].txt". The operation completed successfully
8:13 PM: C:\Documents and Settings\Chris\Local Settings\Temp\VVSNInst.exe (ID = 127141)
8:13 PM: Found Adware: whenu savenow
8:11 PM: C:\Documents and Settings\Chris\My Documents\Unzipped\hijackthis[1]\backups\backup-20060905-213755-449.dll (ID = 238222)
8:10 PM: C:\System Volume Information\_restore{bcb15ae0-1419-440a-858f-63cae3281ba7}\RP342\A0055494.dll (ID = 298669)
8:08 PM: C:\System Volume Information\_restore{bcb15ae0-1419-440a-858f-63cae3281ba7}\RP353\A0056563.dll (ID = 238222)
8:06 PM: C:\WINDOWS\system32\rk.bin (ID = 235981)
8:05 PM: C:\Documents and Settings\Chris\Local Settings\Temp\RKEula.rtf (ID = 190350)
8:01 PM: C:\Documents and Settings\Chris\Local Settings\Temp\osi40.tmp (ID = 185507)
8:01 PM: Found Adware: marketscore
8:00 PM: C:\Program Files\Common Files\WhenU (1 subtraces) (ID = 2147486917)
8:00 PM: Found Adware: whenu
8:00 PM: Starting File Sweep
8:00 PM: Warning: Failed to access drive A:
8:00 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
8:00 PM: c:\documents and settings\chris\cookies\chris@zedo[1].txt (ID = 3762)
8:00 PM: Found Spy Cookie: zedo cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@yadro[2].txt (ID = 3743)
8:00 PM: Found Spy Cookie: yadro cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@xiti[1].txt (ID = 3717)
8:00 PM: Found Spy Cookie: xiti cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3032)
8:00 PM: Found Spy Cookie: myaffiliateprogram.com cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2417)
8:00 PM: Found Spy Cookie: clixgalore cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2337)
8:00 PM: c:\documents and settings\chris\cookies\chris@web-stat[1].txt (ID = 3648)
8:00 PM: Found Spy Cookie: web-stat cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@videodome[1].txt (ID = 3638)
8:00 PM: Found Spy Cookie: videodome cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2729)
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3627)
8:00 PM: Found Spy Cookie: valuead cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@tribalfusion[1].txt (ID = 3589)
8:00 PM: Found Spy Cookie: tribalfusion cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@tradedoubler[1].txt (ID = 3575)
8:00 PM: Found Spy Cookie: tradedoubler cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@thriftyaustralia.122.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2528)
8:00 PM: c:\documents and settings\chris\cookies\chris@tacoda[2].txt (ID = 6444)
8:00 PM: Found Spy Cookie: tacoda cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3254)
8:00 PM: Found Spy Cookie: reliablestats cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@statcounter[1].txt (ID = 3447)
8:00 PM: Found Spy Cookie: statcounter cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3098)
8:00 PM: Found Spy Cookie: onestat.com cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@spylog[1].txt (ID = 3415)
8:00 PM: Found Spy Cookie: spylog cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@serving-sys[2].txt (ID = 3343)
8:00 PM: Found Spy Cookie: serving-sys cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3341)
8:00 PM: Found Spy Cookie: server.iad.liveperson cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2528)
8:00 PM: c:\documents and settings\chris\cookies\chris@rn11[2].txt (ID = 3261)
8:00 PM: Found Spy Cookie: rn11 cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3440)
8:00 PM: Found Spy Cookie: starpulse cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@revenue[1].txt (ID = 3257)
8:00 PM: Found Spy Cookie: revenue.net cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 2528)
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3106)
8:00 PM: c:\documents and settings\chris\cookies\chris@paypal.112.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@partypoker[1].txt (ID = 3111)
8:00 PM: Found Spy Cookie: partypoker cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@partygaming.122.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@overture[2].txt (ID = 3105)
8:00 PM: Found Spy Cookie: overture cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@newsinteractive.112.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@msnportal.112.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@msnaccountservices.112.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@metacafe.122.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@maxserving[1].txt (ID = 2966)
8:00 PM: Found Spy Cookie: maxserving cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3669)
8:00 PM: Found Spy Cookie: webtrends cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2535)
8:00 PM: Found Spy Cookie: domainsponsor cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 2528)
8:00 PM: c:\documents and settings\chris\cookies\chris@hypertracker[1].txt (ID = 2817)
8:00 PM: Found Spy Cookie: hypertracker.com cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 2810)
8:00 PM: Found Spy Cookie: humanclick cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@go[1].txt (ID = 2728)
8:00 PM: Found Spy Cookie: go.com cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@fastclick[2].txt (ID = 2651)
8:00 PM: Found Spy Cookie: fastclick cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@dl[1].txt (ID = 2529)
8:00 PM: Found Spy Cookie: dl cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@directtrack[2].txt (ID = 2527)
8:00 PM: Found Spy Cookie: directtrack cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@digitalhomediscountptyltd.122.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@cnetaustralia.122.2o7[1].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@clickbank[2].txt (ID = 2398)
8:00 PM: Found Spy Cookie: clickbank cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@burstnet[1].txt (ID = 2336)
8:00 PM: Found Spy Cookie: burstnet cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed]-sys[2].txt (ID = 2330)
8:00 PM: Found Spy Cookie: bs.serving-sys cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@bluestreak[1].txt (ID = 2314)
8:00 PM: Found Spy Cookie: bluestreak cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@a[1].txt (ID = 2027)
8:00 PM: Found Spy Cookie: a cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@atwola[1].txt (ID = 2255)
8:00 PM: Found Spy Cookie: atwola cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@atdmt[2].txt (ID = 2253)
8:00 PM: Found Spy Cookie: atlas dmt cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@ask[2].txt (ID = 2245)
8:00 PM: Found Spy Cookie: ask cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2650)
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2650)
8:00 PM: Found Spy Cookie: falkag cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@apmebf[2].txt (ID = 2229)
8:00 PM: Found Spy Cookie: apmebf cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 3190)
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 2087)
8:00 PM: Found Spy Cookie: adreactor cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 3148)
8:00 PM: Found Spy Cookie: pointroll cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3400)
8:00 PM: Found Spy Cookie: specificclick.com cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 2768)
8:00 PM: Found Spy Cookie: hbmediapro cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][1].txt (ID = 3751)
8:00 PM: Found Spy Cookie: yieldmanager cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@about[1].txt (ID = 2037)
8:00 PM: Found Spy Cookie: about cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@2o7[1].txt (ID = 1957)
8:00 PM: c:\documents and settings\chris\cookies\chris@247realmedia[1].txt (ID = 1953)
8:00 PM: Found Spy Cookie: 247realmedia cookie
8:00 PM: c:\documents and settings\chris\cookies\chris@122.2o7[2].txt (ID = 1958)
8:00 PM: c:\documents and settings\chris\cookies\chris@112.2o7[2].txt (ID = 1958)
8:00 PM: Found Spy Cookie: 2o7.net cookie
8:00 PM: c:\documents and settings\chris\cookies\[removed][2].txt (ID = 3190)
8:00 PM: Found Spy Cookie: primaryads cookie
8:00 PM: Starting Cookie Sweep
8:00 PM: Registry Sweep Complete, Elapsed Time:00:00:13
8:00 PM: HKLM\software\classes\typelib\{930436bc-7707-4f77-9e82-771423a87c75}\ (ID = 1135463)
8:00 PM: HKLM\software\classes\bhobj.bhobjobj.1\ (ID = 1135435)
8:00 PM: HKLM\software\classes\bhobj.bhobjobj\ (ID = 1135429)
8:00 PM: HKCR\typelib\{930436bc-7707-4f77-9e82-771423a87c75}\ (ID = 1135419)
8:00 PM: HKCR\bhobj.bhobjobj.1\clsid\ (ID = 1135393)
8:00 PM: HKCR\bhobj.bhobjobj.1\ (ID = 1135391)
8:00 PM: HKCR\bhobj.bhobjobj\ (ID = 1135385)
8:00 PM: Found Adware: webdir
7:59 PM: Starting Registry Sweep
7:59 PM: Memory Sweep Complete, Elapsed Time: 00:01:01
7:58 PM: Starting Memory Sweep
7:58 PM: Sweep initiated using definitions version 754
7:58 PM: Spy Sweeper 5.0.5.1286 started
7:58 PM: | Start of Session, Wednesday, 6 September 2006 |
********
7:58 PM: | End of Session, Wednesday, 6 September 2006 |
7:58 PM: Your definitions are up to date.
7:57 PM: Your spyware definitions have been updated.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
7:47 PM: Shield States
7:47 PM: Spyware Definitions: 691
7:47 PM: Spy Sweeper 5.0.5.1286 started
7:47 PM: Spy Sweeper 5.0.5.1286 started
7:47 PM: | Start of Session, Wednesday, 6 September 2006 |
********

EWIDO

ewido anti-spyware - Scan Report
———————————————————

+ Created at: 9:06:35 PM 6/09/2006

+ Scan result:



C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\MessenPass\mspass.exe -> Not-A-Virus.PSWTool.Win32.Messen.104 : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\chris@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\chris@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\chris@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Directnetadvertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Chris\Cookies\chris@trafic[1].txt -> TrackingCookie.Trafic : Cleaned with backup (quarantined).


::Report end

HIJACK LOG

Logfile of HijackThis v1.99.1
Scan saved at 9:17:05 PM, on 6/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris\My Documents\Unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.iprimus.com.au
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iprimus.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.iprimus.com.au
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iprimus.com.au
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://au.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.iprimus.com.au:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.IPrimus.com.au;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.31.*;192.168.*;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EPSON Stylus Photo R310 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3F2.EXE" /P30 "EPSON Stylus Photo R310 Series" /O6 "USB001" /M "Stylus Photo R310"
O4 - HKLM\..\Run: [Easy-PrintToolBox] "C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" /logon
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131105775901
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~2\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


A little more background info: My system rebooted itself a couple of weeks ago and when it recovered Windows said it had recovered from a serious error. A couple of days ago AVG quarantined a trojan (which I have since deleted). I am sorry I didn't write down what it was called!

Once again, thanks so much for your assistance!

:D
Hi again, Thanks for replying and thanks for the links to those useful cleaning tools! :-) I know how to turn on and off system restore and it is on. I clicked the link you provided anyway to see if an error message came up. It did. "The signature of the certificate can not be verified". The second time I clicked the link it in stalled loading the page. The third time it loaded fine and I was able to download the loaded help. I tried doing a system restore again and the the computer froze during the shutdown faze and I had to reboot. Error on restart " Restoration incomplete: Your computer can not be restored to (date)….due to interruption by improper shutdown. Choose another restore point". This is the first time it has froze during the operation - before it was just saying could not restore to selected date after shutdown and restart. Maybe a reformat is the only answer? Thanks again.
Hello originalwitty,

Let's try this first,

Click Start Menu > All Programs > Accessories > System Tools > SystemRestore

Press OK. Choose 'Create a Restore Point' then Next. Name it and press 'Create' then when the confirmation screen shows the restore point has been created click 'Close'

Next go to Start Menu > Run > type

cleanmgr

click OK, when Disk Cleanup opens goto the 'More Options' tab and press 'Cleanup' on the system restore area which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.

Now after you have a restore point created and it is a good one, maybe you will be able to do a system restore?
Let me know.
Hi originalwitty,

Your logs appear to be clean. It appears that you have two antivirus applications installed
avguard.exe is part of Antivirus Service for Windows XP/2000/NT made by H+BEDV"s AntiVir and
Grisoft's AVG

The rule for antivirus applications is that you should only have one installed since they may interfere with each other. So you need to uninstall one.

If you have any questions about the above please reply. Otherwise, you can do the following and we will wrap this up:

Please update your Java.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 8.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_08-windowsi586-p.exe to install the newest version.
STEP 1.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI