This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Hijack this Logfile. Please help

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My problem is that I keep getting these pop ups even when i'm not using my browser. they just pop up with some ad for a spyware remover or a cellphone this is real annoying. Please help me. thanks, jay





Logfile of HijackThis v1.99.1
Scan saved at 5:41:52 PM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Rar$EX00.766\HijackThis.exe

O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugi…PluginNOSSO.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148091584718
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://72.240.51.211/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - AppInit_DLLs: iniwin32.dll
O20 - Winlogon Notify: Nls - C:\WINDOWS\system32\d80mlid1180.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Welcome to the forum :wavey:

Part 1

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory

MSWINSCK.OCX

After posting those two logs, proceed to Part 2.
=================================

Part 2

Go to:

Start –> Control Panel –> Add/Remove Programs

Remove New.Net or NewDotNet, then reboot.

If there is no listing for it, use the uninstaller at New.net

Use Procedure 4 to remove it. It requires that an internet connection be active while doing it.

Reboot.

Proceed to Part 3
=================================

Part 3

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll (file missing)

O15 - Trusted Zone: http://click.getmirar.com (HKLM)

O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)

O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)

O20 - AppInit_DLLs: iniwin32.dll

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column look for:

Command Service

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\twljagflbcbsawnoyxjkcw <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Ok, here is what I got for the first step. I'll move onto step 2 now. By the way thanks very much for the help. It is greatly appreciated




Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 9/12/2006 11:44:07 PM

Infected! C:\WINDOWS\system32\p48q0el5ehq.dll
Infected! C:\WINDOWS\system32\hvpertrm.dll
Infected! C:\WINDOWS\system32\mv66l9js1.dll
Infected! C:\WINDOWS\system32\p48q0el5ehq.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016022.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016065.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016075.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016088.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017095.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017102.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017190.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017197.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017204.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017786.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017793.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017812.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017813.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017814.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017815.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017820.dll
Infected! C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017824.dll

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\p48q0el5ehq.dll
C:\WINDOWS\system32\p48q0el5ehq.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\hvpertrm.dll
C:\WINDOWS\system32\hvpertrm.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\mv66l9js1.dll
C:\WINDOWS\system32\mv66l9js1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\p48q0el5ehq.dll
C:\WINDOWS\system32\p48q0el5ehq.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016022.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016022.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016065.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016065.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016075.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016075.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016088.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016088.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017095.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017095.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017102.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017102.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017190.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017190.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017197.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017197.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017204.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017204.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017786.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017786.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017793.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017793.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017812.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017812.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017813.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017813.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017814.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017814.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017815.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017815.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017820.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017820.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017824.dll
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017824.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{6E38C8AB-3035-4D48-A337-BB0FF1F6FC3B}"
HKCR\Clsid\{6E38C8AB-3035-4D48-A337-BB0FF1F6FC3B}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B312729C-85C1-4836-BF9B-88B73694780A}"
HKCR\Clsid\{B312729C-85C1-4836-BF9B-88B73694780A}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

—————————————————————————————————————————-
Logfile of HijackThis v1.99.1
Scan saved at 11:53:39 PM, on 9/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\7d20032.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\{3442DD53-04BB-1033-0114-040725030001}\Update.exe
C:\WINDOWS\DOBE~1\fast.exe
C:\Documents and Settings\Mike\Application Data\??pPatch\r?gsvr32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [7d20032.exe] C:\WINDOWS\system32\7d20032.exe
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [adi598ec] RUNDLL32.EXE w013a617.dll,n 004598e800000002013a617
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [7d20032.exe] C:\Documents and Settings\Mike\Local Settings\Application Data\7d20032.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Rhss] "C:\WINDOWS\DOBE~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Muob] C:\Documents and Settings\Mike\Application Data\??pPatch\r?gsvr32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugi…PluginNOSSO.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148091584718
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://72.240.51.211/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - AppInit_DLLs: repairs303169590.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw\command.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Regardless whether you saw my last post or not, you need to do this:

Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop.

Run it.

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.
:)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Ok here is what I got.

Mike - 06-09-13 0:10:17.31
ComboFix 06.09.11B - Running from: C:\Documents and Settings\[removed]\Desktop

Microsoft Windows XP [Version 5.1.2600]

((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\repairs303169590.dll
C:\Documents and Settings\Mike\Application Data\Sskknwrd.dll
C:\Documents and Settings\Mike\Application Data\Sskcwrd.dll
C:\Documents and Settings\Mike\Application Data\Sskuknwrd.dll
C:\Documents and Settings\Mike\Application Data\Sskdmns.dll
C:\WINDOWS\system32\bk.exe
C:\Program Files\surfsidekick 3\SskBho.dll
C:\Program Files\surfsidekick 3\SskCore.dll
C:\Program Files\surfsidekick 3\Ssk.exe
C:\WINDOWS\system32\iniwin32.dll
C:\Program Files\data19


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\dfndrff_e.exe
C:\deskbar3.exe
C:\kybrdff_18.exe
C:\nwnmff_18.exe
C:\WINDOWS\system32\adrot-uninst.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\justin.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Program Files\Inetget2
C:\WINDOWS\system32\components
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\system32\adrotate.dll
C:\Program Files\network monitor
C:\Program Files\Common Files\{3442DD53-04BB-1033-0114-040725030001}
C:\WINDOWS\TWljaGFlbCBSaWNoYXJkcw

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\WINDOWS\DOBE~1
C:\QooBox\Purity\WINDOWS\DOBE~1\?dobe
C:\QooBox\Purity\WINDOWS\DOBE~1\fast.exe
C:\QooBox\Purity\Documents and Settings\Mike\Application Data\PPATCH~1
C:\QooBox\Purity\Documents and Settings\Mike\Application Data\PPATCH~1\r?gsvr32.exe


((((((((((((((((((((((((((((((( Files Created from 2006-08-13 to 2006-09-13 ))))))))))))))))))))))))))))))))))


2006-09-12 23:36 2 –a—— C:\WINDOWS\system32\wtssvit.exe
2006-09-12 23:36 131,072 –a—— C:\WINDOWS\system32\issbjdzk.dll
2006-09-12 23:35 61,952 –a—— C:\WINDOWS\system32\adi598ec.dll
2006-09-12 23:35 32,768 –a—— C:\WINDOWS\system32\WinDmy.dll
2006-09-12 23:35 30,208 –a—— C:\WINDOWS\ss1205.exe
2006-09-12 23:35 29,696 –a—— C:\WINDOWS\system32\w013a617.dll
2006-09-12 23:35 2,560 –a—— C:\WINDOWS\ac3_0002.exe
2006-09-12 23:35 184,939 –a—— C:\WINDOWS\YazzleBundle-1119.exe
2006-09-12 23:35 139,264 –a—— C:\WINDOWS\MirarSetup_876057.exe
2006-09-12 23:35 1,233 –a—— C:\WINDOWS\system32\adi598ec.sys
2006-09-12 23:34 18,944 –a—— C:\WINDOWS\system32\cool.exe
2006-09-12 23:14 13,312 –a—— C:\WINDOWS\system32\7d20032.exe
2006-09-12 22:24 812,122 —hs—- C:\WINDOWS\system32\vvvwa.bak1
2006-09-12 22:23 577,588 —hs—- C:\WINDOWS\system32\awvvv.dll
2006-09-12 22:19 78,378 –a—— C:\WINDOWS\g4727250.dll
2006-09-12 22:18 5,120 –a—— C:\WINDOWS\system32\ismini.exe
2006-09-12 22:18 40,973 —hs—- C:\WINDOWS\system32\qommmml.dll
2006-09-12 22:18 15,872 –a—— C:\WINDOWS\system32\winwly32.dll
2006-09-12 15:49 970,752 –a—— C:\WINDOWS\system32\VchReg.dll
2006-09-07 11:01 78,848 –a—— C:\WINDOWS\system32\nsw7C.dll
2006-08-30 15:32 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-12 23:37 93634 –ahs—- C:\Program Files\Common Files\Yazzle1119OinUninstaller.exe
2006-09-12 21:09 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-09-12 19:53 ——– d——– C:\Documents and Settings\Mike\Application Data\Talkback
2006-09-12 15:49 ——– d——– C:\Program Files\MaxAntiSpyware
2006-09-12 15:06 ——– d——– C:\Program Files\WinRAR
2006-09-08 13:15 157184 —hs—- C:\Program Files\Common Files\Yazzle1119OinAdmin.exe
2006-08-30 15:49 ——– d——– C:\Program Files\Colorful Movie Editor Trial
2006-08-30 15:33 ——– d——– C:\Program Files\Mpeg2Decoder
2006-08-24 01:35 ——– d——– C:\Program Files\Google
2006-08-03 11:48 56 -r-hs—- C:\WINDOWS\system32\B34D580FE0.sys
2006-08-03 11:48 3766 –ahs—- C:\WINDOWS\system32\KGyGaAvL.sys
2006-08-03 11:47 ——– d——– C:\Documents and Settings\Mike\Application Data\Corel
2006-08-03 11:39 ——– d——– C:\Program Files\CorelPaintShopProX__
2006-08-03 11:36 ——– d——– C:\Program Files\CorelPaintShopProX_
2006-08-03 11:27 ——– d——– C:\Program Files\CorelPaintShopProX
2006-07-30 17:31 ——– d——– C:\Program Files\MSN Games
2006-07-17 20:18 329020 –a—— C:\WINDOWS\clientupgrade.exe
2006-07-15 15:09 ——– d——– C:\Program Files\Alchemy Mindworks
2006-07-15 05:16 ——– d——– C:\Program Files\IrfanView
2006-07-13 00:19 ——– d——– C:\Program Files\iPod
2006-07-10 16:27 8464 –a—— C:\WINDOWS\system32\sporder.dll
2006-07-10 11:56 73216 –a—— C:\WINDOWS\cadkasdeinst01e.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"7d20032.exe"="C:\\Documents and Settings\\Mike\\Local Settings\\Application Data\\7d20032.exe"
"Rhss"="\"C:\\WINDOWS\\DOBE~1\\fast.exe\" -vt yazb"
"Muob"="C:\\Documents and Settings\\Mike\\Application Data\\??pPatch\\r?gsvr32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"HP Software Update"="\"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\""
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_07\\bin\\jusched.exe"
"ClamWin"="\"C:\\Program Files\\ClamWin\\bin\\ClamTray.exe\" –logon"
"iTunesHelper"="\"D:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"7d20032.exe"="C:\\WINDOWS\\system32\\7d20032.exe"
"adi598ec"="RUNDLL32.EXE w013a617.dll,n 004598e800000002013a617"
"adstart"="\"iexplore.exe\" \"http://iesettingsupdate\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="http://gfx2.hotmail.com/i.p.attach.gif"
"SubscribedURL"="http://gfx2.hotmail.com/i.p.attach.gif"
"FriendlyName"=""
"Flags"=dword:00000001
"Position"=hex:2c,00,00,00,52,01,00,00,23,00,00,00,7c,00,00,00,72,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,17,01,00,00,0d,00,00,00,0c,00,\
00,00,01,00,00,40
"RestoredStateInfo"=hex:14,6d,0a,07,41,c0,b4,74,50,08,c1,02,68,de,0a,07,20,6d,\
0a,07,78,5d,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,de,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4e,00,00,00,00,00,00,00,b2,03,00,00,de,02,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
"incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvvv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwly32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: Wed 09/13/2006 0:16:41.31
ComboFix.txt
_________________________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 12:18:39 AM, on 9/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\7d20032.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\cool.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [7d20032.exe] C:\WINDOWS\system32\7d20032.exe
O4 - HKLM\..\Run: [adi598ec] RUNDLL32.EXE w013a617.dll,n 004598e800000002013a617
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [7d20032.exe] C:\Documents and Settings\Mike\Local Settings\Application Data\7d20032.exe
O4 - HKCU\..\Run: [Rhss] "C:\WINDOWS\DOBE~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Muob] C:\Documents and Settings\Mike\Application Data\??pPatch\r?gsvr32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugi…PluginNOSSO.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148091584718
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://72.240.51.211/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
When I made my first post, I hadn't counted on more "bad boys" showing up…
:oops:

Please make a PERMANANT folder for Hijack This!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. MOVE (drag-and-drop) HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O4 - HKLM\..\Run: [7d20032.exe] C:\WINDOWS\system32\7d20032.exe

O4 - HKLM\..\Run: [adi598ec] RUNDLL32.EXE w013a617.dll,n 004598e800000002013a617

O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"

O4 - HKCU\..\Run: [7d20032.exe] C:\Documents and Settings\Mike\Local Settings\Application Data\7d20032.exe

O4 - HKCU\..\Run: [Rhss] "C:\WINDOWS\DOBE~1\fast.exe" -vt yazb

O4 - HKCU\..\Run: [Muob] C:\Documents and Settings\Mike\Application Data\??pPatch\r?gsvr32.exe

O15 - Trusted Zone: *.elitemediagroup.net

O15 - Trusted Zone: *.media-motor.net

O15 - Trusted Zone: *.mmohsix.com

O15 - Trusted Zone: http://click.getmirar.com (HKLM)

O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)

O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)

O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\mike\application data\??ppatch <— FOLDER

c:\documents and settings\mike\local settings\application data\7d20032.exe <— file

c:\windows\system32\7d20032.exe <— file

c:\windows\system32\cool.exe <— file

w013a617.dll <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
Ok, I did my best here, so I hope I did everything correct.

Logfile of HijackThis v1.99.1
Scan saved at 1:38:28 AM, on 9/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugi…PluginNOSSO.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148091584718
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://72.240.51.211/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Only for Windows XP and Windows 2000

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:

c:\rapport.txt

Open that file with Notepad, and "copy/paste" the ENTIRE CONTENTS of it into this thread.
Heres wha tI got from this scan SmitFraudFix v2.87 Scan done at 10:08:56.60, Wed 09/13/2006 Run from C:\Documents and Settings\Mike\Desktop OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ismini.exe FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Mike\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MIKE\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="http://gfx2.hotmail.com/i.p.attach.gif" "SubscribedURL"="http://gfx2.hotmail.com/i.p.attach.gif" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}"="g322" [HKEY_CLASSES_ROOT\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32] @="C:\WINDOWS\g514546.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32] @="C:\WINDOWS\g514546.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{259BA022-2005-45E9-A965-10EDB9C00618}"="Windowz Updater" [HKEY_CLASSES_ROOT\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32] @="C:\WINDOWS\g18874843.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32] @="C:\WINDOWS\g18874843.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
Close Ewido and Reboot in Normal Mode.

______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
SmitFraudFix v2.87

Scan done at 11:01:03.35, Wed 09/13/2006
Run from C:\Documents and Settings\Mike\Desktop
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}"="g322"

[HKEY_CLASSES_ROOT\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32]
@="C:\WINDOWS\g514546.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32]
@="C:\WINDOWS\g514546.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{259BA022-2005-45E9-A965-10EDB9C00618}"="Windowz Updater"

[HKEY_CLASSES_ROOT\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32]
@="C:\WINDOWS\g25118187.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32]
@="C:\WINDOWS\g25118187.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\ismini.exe Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}"="g322"

[HKEY_CLASSES_ROOT\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32]
@="C:\WINDOWS\g514546.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}\InProcServer32]
@="C:\WINDOWS\g514546.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{259BA022-2005-45E9-A965-10EDB9C00618}"="Windowz Updater"

[HKEY_CLASSES_ROOT\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32]
@="C:\WINDOWS\g25118187.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{259BA022-2005-45E9-A965-10EDB9C00618}\InProcServer32]
@="C:\WINDOWS\g25118187.dll"



»»»»»»»»»»»»»»»»»»»»»»»» End

_________________________________________________________________________________________

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:52:23 AM 9/13/2006

+ Scan result:



C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017884.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017817.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017818.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017909.DLL -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017910.EXE -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016072.dll -> Adware.E2Give : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017091.dll -> Adware.E2Give : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017194.dll -> Adware.E2Give : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017899.DLL -> Adware.E2give : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015917.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017804.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017838.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\em.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017904.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0018005.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Program Files\filesubmit\ccfsuperman.zip\NNWDAC638.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015913.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015918.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0016049.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP139\A0017092.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017816.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\filesubmit\ccfsuperman.zip\SetupInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017672.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017895.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017911.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015912.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
D:\Program Files\Mozilla Firefox\plugins\npclntax.dll -> Adware.Zango : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Application Data\7d20032.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017811.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017869.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017924.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017984.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017986.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015908.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017797.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\ss1205.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP138\A0015907.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017796.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017906.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
:mozilla.332:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.7:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.87:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.17:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.8:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.18:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.19:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.20:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.21:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.22:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.23:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\g572b2ws.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.561:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.562:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.563:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.564:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.461:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.462:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.463:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.464:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.465:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.466:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.467:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.468:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.469:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.470:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.505:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.506:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.507:C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\rvwu2i8p.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\Temp\win10.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win159.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{A162EE52-5164-4FCD-8399-74EABC7C8EB3}\RP143\A0017907.exe -> Trojan.Starter.65 : Cleaned with backup (quarantined).


::Report end

_________________________________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 11:57:36 AM, on 9/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager/plugi…PluginNOSSO.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148091584718
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://72.240.51.211/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI