This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PopUps, SurfSidekick and who knows what else.

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am dealing with my 13 yo's computer. I tried some of the self help, but I have some real issues here.
Spybot works and removes some stuff. Windows keeps shutting down Adaware and Ewido runs but locks up when trying to quarenteen anything. Here is the HJ Log.
Thanks
Bill


Logfile of HijackThis v1.99.1
Scan saved at 6:31:59 PM, on 9/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\crunner\cproc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - _{A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [hkmqdi] C:\WINDOWS\system32\htiydk.exe reg_run
O4 - HKLM\..\Run: [enxadcc1] RUNDLL32.EXE w0b270c9.dll,n 003adcbe000000030b270c9
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [dhtrf] C:\WINDOWS\system32\htiydk.exe reg_run
O4 - HKCU\..\Run: [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\i006lads1d06.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi,

Welcome to TC :)

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply, as well as a new HijackThis log.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Danny :)
Danny:
Here are the 2 logs you requested.
Thanks for the help.
Bill


Owner - 06-09-07 20:41:44.42
ComboFix 06.09.07 - Running from: C:\Combo

Microsoft Windows XP [Version 5.1.2600]

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{C42492CA-5BDF-416B-8F34-1BC96438FBA3}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C42492CA-5BDF-416B-8F34-1BC96438FBA3}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C42492CA-5BDF-416B-8F34-1BC96438FBA3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{C42492CA-5BDF-416B-8F34-1BC96438FBA3}\InprocServer32]
@="C:\\WINDOWS\\system32\\iksecsnp.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{2CDFC4E9-078F-4B09-BB99-30BDFDC96898}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2CDFC4E9-078F-4B09-BB99-30BDFDC96898}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2CDFC4E9-078F-4B09-BB99-30BDFDC96898}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2CDFC4E9-078F-4B09-BB99-30BDFDC96898}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{61AA437D-074D-4E78-A4B9-57572A2CD13F}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{61AA437D-074D-4E78-A4B9-57572A2CD13F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{61AA437D-074D-4E78-A4B9-57572A2CD13F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{61AA437D-074D-4E78-A4B9-57572A2CD13F}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{12A79ACC-0263-4E34-88F7-64DEF8519095}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{12A79ACC-0263-4E34-88F7-64DEF8519095}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{12A79ACC-0263-4E34-88F7-64DEF8519095}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{12A79ACC-0263-4E34-88F7-64DEF8519095}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{D68516E6-F847-437A-A2A6-0017A3CB45D9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D68516E6-F847-437A-A2A6-0017A3CB45D9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D68516E6-F847-437A-A2A6-0017A3CB45D9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D68516E6-F847-437A-A2A6-0017A3CB45D9}\InprocServer32]
@="C:\\WINDOWS\\system32\\doserial.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{4EEFBC13-FEC3-48AE-8554-47C3856D2ECA}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4EEFBC13-FEC3-48AE-8554-47C3856D2ECA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4EEFBC13-FEC3-48AE-8554-47C3856D2ECA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{4EEFBC13-FEC3-48AE-8554-47C3856D2ECA}\InprocServer32]
@="C:\\WINDOWS\\system32\\lshsvc.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{0656D260-42A3-4E67-BE66-9EE100D646DB}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0656D260-42A3-4E67-BE66-9EE100D646DB}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0656D260-42A3-4E67-BE66-9EE100D646DB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{0656D260-42A3-4E67-BE66-9EE100D646DB}\InprocServer32]
@="C:\\WINDOWS\\system32\\ptlmon.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\CLSID\{8ED3CA04-29AB-4771-A407-4E88E6B33531}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8ED3CA04-29AB-4771-A407-4E88E6B33531}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8ED3CA04-29AB-4771-A407-4E88E6B33531}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8ED3CA04-29AB-4771-A407-4E88E6B33531}\InprocServer32]
@="C:\\WINDOWS\\system32\\mpr2c.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


Granting sedebugprivilege to Administrators … successful


((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-08-28 15:14 28672 ra8pv.exe.qoo
06-09-04 19:06 277 goofu.dll.qoo
06-08-29 18:25 53 bcbwcq.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Owner\Application Data\Sskdmns.dll
C:\Documents and Settings\Owner\Application Data\Sskknwrd.dll
C:\Documents and Settings\Owner\Application Data\Sskuknwrd.dll
C:\Program Files\surfsidekick 3\Ssk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\keyboard1.dat
C:\WINDOWS\keyboard191.dat
C:\WINDOWS\keyboard201.dat
C:\WINDOWS\system32\aaa00000.dll
C:\WINDOWS\system32\aaa00000.sys
C:\WINDOWS\system32\bez6n4r21.exe
C:\WINDOWS\system32\wapisvsu.exe
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\justin.exe
C:\WINDOWS\system32bez6n4r21.exe
C:\Program Files\cmfibula
C:\Program Files\PSLister
C:\Program Files\Common Files\{78E1FBDF-0958-1033-1202-030709040001}
C:\WINDOWS\system32\crunner

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\WINDOWS\SEMBLY~1


((((((((((((((((((((((((((((((( Files Created from 2006-08-07 to 2006-09-07 ))))))))))))))))))))))))))))))))))


2006-09-06 16:48 236,838 -r–s—- C:\WINDOWS\system32\i006lads1d06.dll
2006-09-04 20:03 884,736 –a—— C:\WINDOWS\system32\msimsg.dll
2006-09-04 20:03 77,312 –a—— C:\WINDOWS\system32\msiexec.exe
2006-09-04 20:03 44,032 –a—— C:\WINDOWS\system32\msisip.dll
2006-09-04 20:03 331,264 –a—— C:\WINDOWS\system32\msihnd.dll
2006-09-04 20:03 2,804,224 –a—— C:\WINDOWS\system32\msi.dll
2006-08-29 18:25 32,768 –a—— C:\WINDOWS\unstall.exe
2006-08-29 18:25 215,308 –a—— C:\WINDOWS\Setup90.exe
2006-08-29 18:25 186,219 –a—— C:\WINDOWS\srvqwlwjsg.exe
2006-08-29 18:25 139,264 –a—— C:\WINDOWS\MirarSetup_876075.exe
2006-08-29 18:25 115,160 –a—— C:\WINDOWS\Eim03.exe
2006-08-28 15:27 186,223 –a—— C:\WINDOWS\srvzfprsjt.exe
2006-08-28 15:26 215,308 –a—— C:\WINDOWS\srveoxtouh.exe
2006-08-28 15:25 28,672 –a—— C:\WINDOWS\system32ra8pv.exe
2006-08-28 15:14 61,952 –a—— C:\WINDOWS\system32\enxadcc1.dll
2006-08-28 15:14 186,223 –a—— C:\WINDOWS\srvwklblbh.exe
2006-08-28 15:14 1,233 –a—— C:\WINDOWS\system32\enxadcc1.sys
2006-08-28 15:13 232 –a—— C:\WINDOWS\system32\jkjkj.bat
2006-08-28 15:13 215,308 –a—— C:\WINDOWS\srvpadoopr.exe
2006-08-28 15:12 32,768 –a—— C:\WINDOWS\system32\setup9x.exe
2006-08-28 15:12 137,432 –a—— C:\WINDOWS\system32\install.exe
2006-08-28 15:11 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2006-08-14 20:52 78,848 –a—— C:\WINDOWS\system32\nsj20.dll
2006-08-07 11:17 61,440 –a—— C:\WINDOWS\system32\BattyRun2.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-07 20:42 ——– d-a—— C:\Program Files\Common Files
2006-09-07 20:29 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-09-05 19:07 ——– d——– C:\Program Files\Windows NT
2006-09-02 22:01 ——– d——– C:\Program Files\Common Files\misc002
2006-09-02 21:09 ——– d—s—- C:\Documents and Settings\Owner\Application Data\Microsoft
2006-08-29 19:41 ——– d——– C:\Documents and Settings\Owner\Application Data\Aim
2006-08-29 19:40 ——– d——– C:\Program Files\Common Files\AOL
2006-08-29 19:39 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-28 21:47 ——– d——– C:\Program Files\AOL
2006-08-28 18:16 ——– d——– C:\Program Files\Common Files\kiii
2006-08-28 17:11 777472 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-08-28 17:11 4992 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2006-08-28 17:11 4288 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-08-28 17:11 27904 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-08-28 17:11 23424 –a—— C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-08-28 17:11 ——– d——– C:\Documents and Settings\Owner\Application Data\AVG7
2006-08-28 17:10 ——– d——– C:\Program Files\Grisoft
2006-08-28 16:55 ——– d——– C:\Program Files\Windows Media Player
2006-08-28 14:44 225280 –a—— C:\Program Files\Uninstall My Global Search Bar.dll
2006-08-28 14:44 ——– d——– C:\Program Files\MyGlobalSearch
2006-08-25 22:00 ——– d——– C:\Documents and Settings\Owner\Application Data\Lavasoft
2006-08-23 22:13 98304 –a—— C:\WINDOWS\system32\CmdLineExt.dll
2006-08-20 20:43 ——– d——– C:\Program Files\CCP
2006-08-20 14:26 ——– d——– C:\Program Files\Common Files\Blizzard Entertainment
2006-08-14 16:35 ——– d——– C:\Program Files\AOD
2006-07-31 12:09 24576 –a—— C:\WINDOWS\system32\ewxcksr.exe
2006-07-17 11:19 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2006-07-16 22:33 ——– d——– C:\Program Files\Common Files\Microsoft Shared
2006-07-16 22:32 ——– d——– C:\Program Files\MSN Messenger
2006-07-13 19:36 ——– d——– C:\Program Files\DiscWizard for Windows
2006-07-13 18:09 ——– d——– C:\Program Files\StepMania
2006-06-23 20:58 720896 –a—— C:\WINDOWS\iun6002ev.exe
2006-06-23 15:31 183296 –a-s—- C:\WINDOWS\NDNuninstall7_22.exe
2006-06-18 09:54 36864 –a—— C:\WINDOWS\system32\frapsvid.dll
2006-06-16 14:34 48936 –a—— C:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"BearShare"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"enxadcc1"="RUNDLL32.EXE w0b270c9.dll,n 003adcbe000000030b270c9"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"Steam"="\"f:\\program files\\steam\\steam.exe\" -silent"
"cprocsvc"="C:\\WINDOWS\\system32\\crunner\\cproc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\Program Files\\Windows NT\\qufyvuty.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="C:\\Program Files\\Common Files\\nico.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^.protected]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\.protected"
"backup"="C:\\WINDOWS\\pss\\.protectedCommon Startup"
"location"="Common Startup"
"command"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\.protected"
"item"=".protected"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk"
"backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe "
"item"="HP Digital Imaging Monitor"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Image Zone Fast Start.lnk"
"backup"="C:\\WINDOWS\\pss\\HP Image Zone Fast Start.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqthb08.exe -s"
"item"="HP Image Zone Fast Start"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^USB Manager.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\USB Manager.lnk"
"backup"="C:\\WINDOWS\\pss\\USB Manager.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Belkin\\BELKIN~1\\WLANMO~1.EXE "
"item"="USB Manager"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^.protected]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\.protected"
"backup"="C:\\WINDOWS\\pss\\.protectedStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\.protected"
"item"=".protected"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Xfire.lnk]
"path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Xfire.lnk"
"backup"="C:\\WINDOWS\\pss\\Xfire.lnkStartup"
"location"="Startup"
"command"="C:\\Program Files\\Xfire\\Xfire.exe "
"item"="Xfire"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\127cbbdd.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="127cbbdd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\127cbbdd.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Configuration Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cfg32"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\cfg32.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="defender20"
"hkey"="HKLM"
"command"="c:\\\\defender20.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Fraps]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FRAPS"
"hkey"="HKCU"
"command"="C:\\FRAPS\\FRAPS.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HotKeysCmds]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hkcmd"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\hkcmd.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd2"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\IgfxTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="igfxtray"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\igfxtray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\keyboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="keyboard20"
"hkey"="HKLM"
"command"="c:\\\\keyboard20.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msnmsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\New.net Startup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NEWDOT~2"
"hkey"="HKLM"
"command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~2.DLL,ClientStartup -s"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="newname20"
"hkey"="HKLM"
"command"="c:\\\\newname20.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PCMService]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PCMService"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_05\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ViewMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ViewMgr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ViewpointPhotosDeviceConnect]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FotomatDeviceConnect"
"hkey"="HKLM"
"command"="C:\\Program Files\\Viewpoint\\Viewpoint Toolbar V35\\FotomatDeviceConnect.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WhenUSave]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Save"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Save\\Save.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\zango]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="zango"
"hkey"="HKLM"
"command"="\"c:\\program files\\zango\\zango.exe\""
"inimapping"="0"



Completion time: Thu 09/07/2006 20:46:20.75
ComboFix.txt



Logfile of HijackThis v1.99.1
Scan saved at 8:48:44 PM, on 9/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - _{A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [enxadcc1] RUNDLL32.EXE w0b270c9.dll,n 003adcbe000000030b270c9
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi,

I recommend that you print out these diretions for use in Safe Mode.

Please boot into Safe Mode. To do this:

1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml

When in Safe Mode, open HijackThis, click the "Scan" button, and check the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - _{A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O4 - HKLM\..\Run: [enxadcc1] RUNDLL32.EXE w0b270c9.dll,n 003adcbe000000030b270c9
O4 - HKCU\..\Run: [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - (no file)


Close all windows except HijackThis, and click the "Fix Checked" button. Close HijackThis.

Next, please enable viewing of hidden files as follows:

1) Go to My Computer, and click on the "Tools" menu
2) Click "Folder options"
3) Select the "View" tab
4) Make sure "Show hidden files and folders" is selected
5) Make sure "Hide extensions for known file types" is unchecked
6) Make sure "Hide protected operating system files (recommended)" is unchecked


Next, delete the following folder:

C:\WINDOWS\system32\crunner

Then click "Start –> Search" and search and delete this file:

w0b270c9.dll

Is that computer running Bearshare LITE or just regular Bearshare.

Reboot and post a new HijackThis log.

Danny :)


Then Reboot and post a new HijackThis log.

Danny :)
Danny:
I followed your instructions and here is the new HJ log. According to my son, Bearshare has been uninstalled.
Thanks
Bill

Logfile of HijackThis v1.99.1
Scan saved at 4:27:25 PM, on 9/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
F:\program files\steam\steam.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Hijackthis\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi,

Please download the Killbox by Option^Explicit.

Note:In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select
    • "Delete on Reboot
    • then Click on the "All Files" button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

    C:\WINDOWS\system32\crunner


  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "OK" at any PendingRenameOperations prompt.
If your computer does not restart automatically, please restart it manually.

After your computer restarts, open HijackThis, click the "Scan" button, and check the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKCU\..\Run: [cprocsvc] C:\WINDOWS\system32\crunner\cproc.exe


Close all windows except HijackThis, and click the 'Fix Checked' button. Close HijackThis.

It looks like BearShare is still installed. To uninstall it:

Click "Start –> Control Panel –> Add Remove Programs". Uninstall BearShare. I recommend that your son look at the list of safe P2P programs here: http://p2p.malwareremoval.com

Next, please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post as well as a new HijackThis log.
Danny :)
Danny:
Here are the new logs.
Thanks
Bill


Logfile of HijackThis v1.99.1
Scan saved at 7:39:54 PM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Tuesday, September 12, 2006 7:39:19 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 13/09/2006
Kaspersky Anti-Virus database records: 222861
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 56659
Number of viruses found: 34
Number of infected objects: 104 / 0
Number of suspicious objects: 4
Duration of the scan process: 00:54:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos10.zip/stdrun2.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos10.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos5.zip/stdrun7.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-714945fd.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w skipped
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-714945fd.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\QooBox\ra8pv.exe.qoo Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP100\A0067880.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP100\A0067882.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067913.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067914.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067943.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067966.exe/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067966.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067989.exe Infected: Trojan-Downloader.Win32.VB.als skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067991.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067992.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067993.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP102\A0073989.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.i skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075124.exe Infected: not-a-virus:AdWare.Win32.CASClient.n skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075125.dll Infected: not-a-virus:AdWare.Win32.CASClient.n skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075128.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075129.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075130.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075131.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075132.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075133.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075134.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075136.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075143.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075150.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP105\A0075215.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP105\A0075218.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP106\A0075285.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP106\A0075288.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075353.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075356.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075370.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP108\A0075428.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP108\A0075439.dll Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075503.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075504.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075505.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe CAB: infected - 5 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075561.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075562.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075563.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075588.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075589.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075590.dll Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075592.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075605.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075606.exe Infected: Trojan.Win32.Runner.j skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075607.exe Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075608.exe Infected: Trojan.Win32.Runner.j skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075609.exe Infected: Trojan.Win32.Runner.j skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075610.exe Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075611.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075612.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075613.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075614.dll Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075626.exe Infected: not-a-virus:AdWare.Win32.Agent.ag skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075632.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075633.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075635.dll Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075640.exe Infected: not-a-virus:AdWare.Win32.Agent.y skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075641.exe Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075683.dll Infected: Trojan-Downloader.Win32.Agent.awb skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075685.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075687.dll Infected: not-a-virus:AdWare.Win32.Mirar.a skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075689.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075690.exe Infected: not-a-virus:AdWare.Win32.CASClient.m skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075725.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075729.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075731.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075732.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075738.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP111\change.log Object is locked skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP59\A0025669.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP67\A0032369.exe/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP67\A0032369.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061882.exe Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061893.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe CAB: infected - 5 skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066981.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped
C:\System Volume Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0067258.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.i skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\em.ocx Infected: Trojan-Dropper.Win32.VB.dq skipped
C:\WINDOWS\MirarSetup_876075.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\WINDOWS\NDNuninstall7_22.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\WINDOWS\qfawjyxo.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Setup90.exe/data0002 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\Setup90.exe/data0005 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\Setup90.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\Setup90.exe NSIS: infected - 3 skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3DDC9625-868E-449C-82EF-E97036683172}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{6506E006-1C56-485F-B4E4-47E0476E85E6}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\srveoxtouh.exe/data0002 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srveoxtouh.exe/data0005 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srveoxtouh.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srveoxtouh.exe NSIS: infected - 3 skipped
C:\WINDOWS\srvpadoopr.exe/data0002 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srvpadoopr.exe/data0005 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srvpadoopr.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\WINDOWS\srvpadoopr.exe NSIS: infected - 3 skipped
C:\WINDOWS\srvqwlwjsg.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped
C:\WINDOWS\srvqwlwjsg.exe NSIS: infected - 1 skipped
C:\WINDOWS\srvwklblbh.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped
C:\WINDOWS\srvwklblbh.exe NSIS: infected - 1 skipped
C:\WINDOWS\srvzfprsjt.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped
C:\WINDOWS\srvzfprsjt.exe NSIS: infected - 1 skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\BattyRun2.dll Infected: not-a-virus:AdWare.Win32.CASClient.n skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\enxadcc1.dll Infected: Trojan-Downloader.Win32.Agent.awb skipped
C:\WINDOWS\system32\ewxcksr.exe Infected: Trojan.Win32.Runner.j skipped
C:\WINDOWS\system32\i006lads1d06.dll Object is locked skipped
C:\WINDOWS\system32\install.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\WINDOWS\system32\install.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\WINDOWS\system32\install.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32ra8pv.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped
C:\WINDOWS\unstall.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.o skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
Hi,

please reboot your computer in Safe Mode by doing the following:

1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Next, delete the following files/folders (if they exist):

C:\WINDOWS\em.ocx
C:\WINDOWS\MirarSetup_876075.exe
C:\WINDOWS\NDNuninstall7_22.exe
C:\WINDOWS\qfawjyxo.exe
C:\WINDOWS\Setup90.exe
C:\WINDOWS\srveoxtouh.exe
C:\WINDOWS\srvpadoopr.exe
C:\WINDOWS\srvqwlwjsg.exe
C:\WINDOWS\srvwklblbh.exe
C:\WINDOWS\srvzfprsjt.exe
C:\WINDOWS\system32\enxadcc1.dll
C:\WINDOWS\system32\ewxcksr.exe
C:\WINDOWS\system32\i006lads1d06.dll
C:\WINDOWS\system32\install.exe


Reboot, and run Kaspersky online scan again, and post the results as well as a new HijackThis log.

Danny :)
Danny:
Here are the new scans. All the files you asked me to deleate were there and have been deleated.
Bill

Logfile of HijackThis v1.99.1
Scan saved at 5:30:15 PM, on 9/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
Thursday, September 14, 2006 5:30:02 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build
2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 14/09/2006
Kaspersky Anti-Virus database records: 223401


Scan Settings
Scan using the following antivirus databaseextended
Scan Archivestrue
Scan Mail Basestrue

Scan TargetMy Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects56699
Number of viruses found35
Number of infected objects105 / 0
Number of suspicious objects4
Duration of the scan process00:54:12

Infected Object NameVirus NameLast Action
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log
Object is locked skipped

C:\Documents and Settings\All Users\Application
Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application
Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application
Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application
Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search &
Destroy\Recovery\VcodecStarVideos10.zip/stdrun2.exe Suspicious:
Password-protected-EXE skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search &
Destroy\Recovery\VcodecStarVideos10.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search &
Destroy\Recovery\VcodecStarVideos5.zip/stdrun7.exe Suspicious:
Password-protected-EXE skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search &
Destroy\Recovery\VcodecStarVideos5.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked
skipped

C:\Documents and Settings\LocalService\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local
Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet
Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped


C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked
skipped

C:\Documents and Settings\NetworkService\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked
skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked
skipped

C:\Documents and Settings\Owner\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-714945fd.zip/javainstaller/InstallerApplet.class
Infected: Trojan-Downloader.Java.OpenStream.w skipped

C:\Documents and Settings\Owner\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-714945fd.zip
ZIP: infected - 1 skipped

C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped


C:\Documents and Settings\Owner\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Local
Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local
Settings\History\History.IE5\MSHist012006091420060915\index.dat Object is
locked skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet
Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped

C:\QooBox\ra8pv.exe.qoo Infected:
not-a-virus:AdWare.Win32.SearchAssistant.g skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc1.ocx Infected:
Trojan-Dropper.Win32.VB.dq skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc10.exe/data0002
Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc10.exe NSIS:
infected - 1 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc11.dll Infected:
Trojan-Downloader.Win32.Agent.awb skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc12.exe Infected:
Trojan.Win32.Runner.j skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc13.dll Object is
locked skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc14.exe/stream/data0005
Infected: not-a-virus:AdWare.Win32.Softomate.q skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc14.exe/stream
Infected: not-a-virus:AdWare.Win32.Softomate.q skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc14.exe NSIS:
infected - 2 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc2.exe Infected:
not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc3.exe Infected:
not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc4.exe Infected:
not-a-virus:AdWare.Win32.BookedSpace.h skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc5.exe/data0002
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc5.exe/data0005
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc5.exe/data0006
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc5.exe NSIS:
infected - 3 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc6.exe/data0002
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc6.exe/data0005
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc6.exe/data0006
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc6.exe NSIS:
infected - 3 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc7.exe/data0002
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc7.exe/data0005
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc7.exe/data0006
Infected: Trojan.Win32.VB.tg skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc7.exe NSIS:
infected - 3 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc8.exe/data0002
Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc8.exe NSIS:
infected - 1 skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc9.exe/data0002
Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped

C:\RECYCLER\S-1-5-21-1935655697-343818398-839522115-500\Dc9.exe NSIS:
infected - 1 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP100\A0067880.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP100\A0067882.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067913.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067914.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067943.dll
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067966.exe/clientax.dll
Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067966.exe
CAB: infected - 1 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067989.exe
Infected: Trojan-Downloader.Win32.VB.als skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067991.exe
Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067992.exe
Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP101\A0067993.exe
Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP102\A0073989.dll
Infected: not-a-virus:AdWare.Win32.NewDotNet.i skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075124.exe
Infected: not-a-virus:AdWare.Win32.CASClient.n skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075125.dll
Infected: not-a-virus:AdWare.Win32.CASClient.n skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075128.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075129.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075130.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075131.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075132.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075133.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075134.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075136.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075143.dll
Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP104\A0075150.dll
Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP105\A0075215.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP105\A0075218.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP106\A0075285.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP106\A0075288.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075353.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075356.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP107\A0075370.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP108\A0075428.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP108\A0075439.dll
Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075503.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075504.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075505.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/SskBho.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/SskCore.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/Ssk.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB/Ssk3RepairInstall.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe/InpB
Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075523.exe
CAB: infected - 5 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075561.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075562.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075563.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe/stream/data0004
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe/stream
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075586.exe
NSIS: infected - 2 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075588.dll
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075589.exe
Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075590.dll
Infected: not-a-virus:AdWare.Win32.Maxifiles.aa skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075592.exe
Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075605.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075606.exe
Infected: Trojan.Win32.Runner.j skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075607.exe
Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075608.exe
Infected: Trojan.Win32.Runner.j skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075609.exe
Infected: Trojan.Win32.Runner.j skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075610.exe
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075611.exe
Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075612.exe
Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075613.exe
Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075614.dll
Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075626.exe
Infected: not-a-virus:AdWare.Win32.Agent.ag skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075632.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075633.dll
Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075635.dll
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075640.exe
Infected: not-a-virus:AdWare.Win32.Agent.y skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075641.exe
Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075683.dll
Infected: Trojan-Downloader.Win32.Agent.awb skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075685.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075687.dll
Infected: not-a-virus:AdWare.Win32.Mirar.a skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075689.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075690.exe
Infected: not-a-virus:AdWare.Win32.CASClient.m skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075694.exe
Infected: Trojan-Downloader.MSIL.Agent.c skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075725.exe
Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075729.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075731.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075732.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP109\A0075738.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP112\change.log
Object is locked skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP59\A0025669.exe
Infected: not-a-virus:Client-IRC.Win32.mIRC.617 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP67\A0032369.exe/clientax.dll
Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP67\A0032369.exe
CAB: infected - 1 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061882.exe
Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe/stream/data0004
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe/stream
Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061884.exe
NSIS: infected - 2 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0061893.EXE
Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/SskBho.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/SskCore.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/Ssk.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB/Ssk3RepairInstall.exe
Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe/InpB
Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066882.exe
CAB: infected - 5 skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0066981.dll
Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped

C:\System Volume
Information\_restore{A724C7F1-83F8-46E4-BF7C-B36D4A83F686}\RP99\A0067258.DLL
Infected: not-a-virus:AdWare.Win32.MyWebSearch.i skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{3DDC9625-868E-449C-82EF-E97036683172}.bin
Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{6506E006-1C56-485F-B4E4-47E0476E85E6}.bin
Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked
skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\BattyRun2.dll Infected:
not-a-virus:AdWare.Win32.CASClient.n skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked
skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked
skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked
skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked
skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked
skipped

C:\WINDOWS\system32ra8pv.exe Infected:
not-a-virus:AdWare.Win32.SearchAssistant.g skipped

C:\WINDOWS\unstall.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.o
skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped

Scan process completed.
Hi, Locate and delete the following files: C:\WINDOWS\system32\BattyRun2.dll C:\WINDOWS\system32\ra8pv.exe C:\WINDOWS\unstall.exe Reboot, and post a new HijackThis log. Danny
Danny:
Here is the HJ log after removing the files in your last post.
Bill


Logfile of HijackThis v1.99.1
Scan saved at 10:42:25 AM, on 9/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Steam] "f:\program files\steam\steam.exe" -silent
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi,

Your computer is now clean!

We have a couple of last steps to perform and then you're all set.

First, let's reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
  • CHECK the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Next, let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer.

3. Turn ON System Restore.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.

System Restore will now be active again.

After System Restore is turned back on, create a Restore Point:

Go to: 'Start > All Programs > Accessories > System Tools', and select System Restore.
In the System Restore Wizard, select: 'Create a restore point'.
Click: Next
Give a description to the new Restore Point. (Something like: Clean PC)
Click: Create

A Firewall is an essential part of PC security and you do not appear to have one running on your system. There are a few available for free that have excellent reputations:
Zone ALarm Free Firewall
Kerio Free Firewall

**To learn more about how to protect yourself while on the internet read this article by Tony Klein: So how did I get infected in the first place?

This article includes important ways of how to keep safe, and has links to programs that you should download to keep spyware free!

Some programs that I recommend:
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows
  • CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
If you wish to submit a complaint about malware, please click on the following image:

[external image: Posted Image]

Danny :thumbup:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI