This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HiJack issue

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help, my computer is running slower ever since i got hijacked, i've got popup problems too that i can't seem to prevent…it continues to popup even when i don't have IE open. Here's my hijack log…please tell me wat i need to do to get rid of these menace and if there are other problems i should get rid off tat i don't know of.

Logfile of HijackThis v1.99.1
Scan saved at 8:58:10 PM, on 23/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\WINDOWS\System32\mysvcc.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SystemInspect\SVCHAST.exe
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\wbem\smss.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - C:\PROGRA~1\SYSTEM~1\SYSTEM~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: CpapView Class - {77962960-536E-47EC-9DDB-52651519705F} - C:\WINDOWS\System32\rundll32.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll
O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll
O2 - BHO: Macromedia. Flash8 Object - {C61A70F3-505E-4B90-916F-627A8706B4BC} - c:\WINDOWS\system32\FlashPlayer8OCX.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [mysvcig38] mysvcc.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe
O4 - HKLM\..\RunServices: [winystems25] winystems.exe
O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SVCHOST (SystemInspect) - Unknown owner - C:\Program Files\SystemInspect\SVCHAST.exe
splat

Hello and welcome to Tom Coyote

It will take a couple of runs at this, so please be patient.

If you have any questions at any time feel free to ask.

First Copy and paste the following into NotePad (Not Wordpad)sc stop SystemInspect
sc delete SystemInspect

Click File ->>Save as ->>type in svc.batUnder "Save as type" Select "all files" ->>Save it to your Desktop
Close Notepad
The svc.bat file should now appear on your Desktop
Double Click that file (It will appear that nothing has happened, but that's o.k.)
Next Re Run HijackthisAt the Main window select "Open the misc tool section"
Then select "Open uninstall manager"
Then "save list" and save it to your desktop
Copy and paste that list as a reply to this thread
k this is the uninstall details : Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Reader 7.0.8 Adobe Shockwave Player Avi Fix Joiner 2.11 Azureus BitComet 0.56 CA eTrust PestPatrol Anti-Spyware Corporate Edition DefilerPak 1.22 (Remove Only) Download Accelerator Plus (DAP) FlashGet(JetCar) HijackThis 1.99.1 HP Image Zone Express HP Imaging Device Functions 5.3 HP PSC & OfficeJet 5.3.A HP Software Update HP Solution Center & Imaging Support Tools 5.3 J2SE Runtime Environment 5.0 Update 8 kuzhan LimeWire 4.12.6 LiveUpdate 1.6 (Symantec Corporation) Maxthon Browser (remove only) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft Office Professional Edition 2003 Mozilla Firefox (1.5.0.7) Nero Suite NJStar Communicator Norton AntiVirus Corporate Edition Overture 4.0 ????? QuickTime RealPlayer S3 S3Display S3 S3Gamma2 S3 S3Info2 S3 S3Overlay SnagIt 8 Spybot - Search & Destroy 1.4 UniChrome IGP Driver and Utilities Unlocker 1.8.1 VIA Audio Driver Setup Program Windows Live Messenger Windows XP Hotfix - KB822603 WinRAR archiver WordWeb
splat

Thanks for the lists.

First Go to Add/Remove programs (Click Start->>Control Panel->>Add/Remove Programs)
And uninstallDownload Accelerator Plus (DAP)
kuzhan

And as an optional uninstallLimeWire 4.12.6
Most Malware removal experts consider this program (Limewire) and other P2P programs risky at best. When the program is used it opens a doorway for other malware/spyware to be installed on the users PC without their knowledge. If you decide to keep this program, at the very least turn it off and do not use it until your PC is clean.

Then Reboot your PC

Next We need to make sure we can see hidden files and foldersClick Start.
Click My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Uncheck the Hide file extensions for known file types.
Click OK.
Next Open Taskmanager (Rt click a blank space on your lower toolbar->>Taskmanger)Locate mysvcc.exe under processes tab
Hilite and Select "End Process"
Close Taskmanager
Next Rerun Hijackthis (scan only) and place checks beside the following entriesO2 - BHO: CdnForIE Class - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O2 - BHO: CpapView Class - {77962960-536E-47EC-9DDB-52651519705F} - C:\WINDOWS\System32\rundll32.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll
O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll
O2 - BHO: WMHlprObj Class - {F5824EFB-728A-4726-A5A5-85A68B20EDC3} - C:\PROGRA~1\CNNIC\Cdn\wmhlpr.dll
O4 - HKLM\..\Run: [mysvcig38] mysvcc.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\RunServices: [winystems25] winystems.exe
O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe
O9 - Extra button: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O9 - Extra 'Tools' menuitem: Chinese Navigation - {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} - C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll
O23 - Service: SVCHOST (SystemInspect) - Unknown owner - C:\Program Files\SystemInspect\SVCHAST.exe

Close all other open windows except Hijackthis and Select "Fix checked"
If prompted to reboot Select No and close Hijackthis.

Next Using Windows Search (Click Start->>Search) (Making sure your search includes looking in hidden files and folders)
Locate and delete the following foldersC:\Program Files\CNNIC
C:\Program Files\SystemInspect

Locate and delete the following filesC:\WINDOWS\System32\xenroer.dll
C:\WINDOWS\DLP.dll
mysvcc.exe
winystems.exe

Reboot your PC->>Rerun Hijackthis and post a fresh Hijackthis log

thanks bamajim
i've done everything up til the fixing those items on hijackthis. I can't seem to delete the following : O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll it keeps coming with this msg: HJT is about to remove a BHO and the corresponding file from you system. close all IE windows and all win explorer b4 continuing for the best chance of success. I've tried wat it said and still it comes out wif that msg.
splat

Sometimes we have files that can be difficult

Rerun HijackthisAt the main window Select "Open the misc tool section"
Select "Delete a file on reboot"
Copy and paste the following in the file box
C:\WINDOWS\System32\xenroer.dll
Click O.K.
Reboot your PC Rerun Hijackthis and let me see a fresh Hijackthis log
thanks bamajim
ok here's the new log:

Logfile of HijackThis v1.99.1
Scan saved at 10:29:06 PM, on 26/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
c:\windows\system32\wbem\smss.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {707D86CC-0DE3-43D7-B874-F0A3F5E82578} - C:\WINDOWS\system32\asfersife.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

Good job

First Re run Hijackthis (scan only) ans place checks beside the following entriesO2 - BHO: (no name) - {707D86CC-0DE3-43D7-B874-F0A3F5E82578} - C:\WINDOWS\system32\asfersife.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe

Close all other open windows except Hijackthis and Select "Fix checked"

Next Using Windows Search
Locate and delete the following filesC:\WINDOWS\system32\asfersife.dll
mssvcc.exe

Reboot your PC->>Re run Hijackthis->> and post a fresh log

thanks bamajim
here's the new log :P but that:
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
is still undeletable.

Logfile of HijackThis v1.99.1
Scan saved at 12:53:15 AM, on 27/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
c:\windows\system32\wbem\smss.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe
C:\WINDOWS\explorer.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

That's o.k. we will get it.

You may want to print out these instructions for reference

1.Go here and Download Ewido Antimalware 4.0
(30 day free trial version) Save it to Your Desktop
 
Double Click Ewido-setup
(It will create its own folder)
Once the program starts You will be at the Status menuUnder "Your computers Security"
Click change status on Resident shield to inactive
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tabUnder How to act? Set default action for detected malwareTo Quarantine
Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlited
Exit Ewido(Do Not run it yet)

2. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)

Use your arrow keys and select Safe Mode and then Enter
4. Once in Safe Mode, Open Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.

5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log.

Your reply should includeyour report-scan.txt from Ewdio
a fresh Hijackthis log
here's the new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 7:27:47 PM, on 27/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
c:\windows\system32\wbem\smss.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe



_______________________________________________________________________________


And this is the report logs from ewido:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 7:23:19 PM 27/09/2006

+ Scan result:



C:\Documents and Settings\Patrick\Local Settings\Temp\5C\cdnaux.dll -> Adware.Cdn : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\62\cdnaux.dll -> Adware.Cdn : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\62\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\12\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\12\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\171\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\171\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\180\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\180\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\24\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\28\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\28\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\3C\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\3C\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\41\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\41\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\7\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\7\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\8\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\8\cdnup.exe -> Adware.Cdn : No action taken.
C:\WINDOWS\system32\cdnns.dll -> Adware.Cdn : No action taken.
HKLM\SOFTWARE\Classes\CLSID\{A64E86D2-203D-4145-AA9B-2425BAF568E9} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A64E86D2-203D-4145-AA9B-2425BAF568E9} -> Adware.Generic : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\1001hkcmd[1].txt -> Adware.IEHlpr : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\toto[1].txt -> Adware.IEHlpr : No action taken.
C:\WINDOWS\Temp\5104.exe.exe -> Adware.IEHlpr : No action taken.
C:\WINDOWS\Temp\PlugSetup0920.exe -> Adware.IEHlpr : No action taken.
C:\WINDOWS\Temp\toto.exe -> Adware.IEHlpr : No action taken.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Patrick\Desktop\Hihack this\backups\backup-20060926-114101-338.dll -> Adware.Webdir : No action taken.
C:\WINDOWS\Temp\fsprot.sys -> Adware.WSearch : No action taken.
C:\WINDOWS\system32\spreadno.exe -> Backdoor.SdBot.avw : No action taken.
C:\WINDOWS\system32\winystems.exe -> Backdoor.SdBot.avw : No action taken.
C:\WINDOWS\system32\mysvcc.exe -> Backdoor.SdBot.awk : No action taken.
C:\WINDOWS\system32\recsl.exe -> Backdoor.SdBot.awk : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\1018.exe -> Downloader.Agent.aww : No action taken.
C:\Documents and Settings\LocalService\Templates\5fbcb5c\1.dll -> Downloader.Delf.asz : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\13519[1].txt -> Downloader.Delf.axa : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\13519[1].txt -> Downloader.Delf.axa : No action taken.
C:\WINDOWS\Temp\13519.exe -> Downloader.Delf.axa : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\huacai904[1].txt -> Downloader.Delf.axl : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\setup175[1].txt -> Downloader.Delf.axl : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\setup[2].txt -> Downloader.Delf.axl : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\huacai904[1].txt -> Downloader.Delf.axl : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\setup[2].txt -> Downloader.Delf.axl : No action taken.
C:\WINDOWS\Temp\huacai904.exe -> Downloader.Delf.axl : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\18gou[1].htm -> Downloader.IstBar.ai : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\p1[1].htm -> Downloader.IstBar.ai : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\maohehe12[1].htm -> Downloader.IstBar.ai : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\tanchuang1[1].htm -> Downloader.IstBar.ai : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\17kanmmm[1].htm -> Downloader.IstBar.ai : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\maohehe95[1].htm -> Downloader.IstBar.ai : No action taken.
C:\WINDOWS\system32\Rundl132.dll -> Downloader.Zlob : No action taken.
C:\WINDOWS\Temp\001.exe -> Dropper.Agent.awp : No action taken.
C:\Documents and Settings\Patrick\Desktop\Hihack this\backups\backup-20060927-004425-991.dll -> Hijacker.BHO.f : No action taken.
C:\WINDOWS\cert.exe -> Hijacker.BHO.f : No action taken.
C:\WINDOWS\cnt.exe -> Hijacker.BHO.f : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\mm7[1].htm -> Not-A-Virus.Exploit.HTML.Mht : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\index[2].htm -> Not-A-Virus.Exploit.HTML.Mht : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\mm7[3].htm -> Not-A-Virus.Exploit.HTML.Mht : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\3[1].htm -> Not-A-Virus.Exploit.HTML.Mht : No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\mm7[2].htm -> Not-A-Virus.Exploit.HTML.Mht : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\RarSFX0\rinst.exe -> Not-A-Virus.Monitor.Win32.Perflogger.163 : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\RarSFX1\rinst.exe -> Not-A-Virus.Monitor.Win32.Perflogger.163 : No action taken.
C:\WINDOWS\system32\rinst.exe -> Not-A-Virus.Monitor.Win32.Perflogger.163 : No action taken.
:mozilla.134:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.49:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.50:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.51:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.20:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.21:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.55:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.149:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.150:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.161:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.148:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.22:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.23:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.24:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.133:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.112:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.218:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.219:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.220:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.221:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.108:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.109:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.110:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.111:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.139:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.140:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.141:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.121:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.264:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hotlog : No action taken.
:mozilla.277:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.197:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.198:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.199:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.200:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.283:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.284:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.319:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.320:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.321:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.322:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.323:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.64:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.65:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.66:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.67:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.68:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.69:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.359:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.292:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Spylog : No action taken.
:mozilla.75:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.76:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.77:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.78:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.79:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.105:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.106:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.107:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.294:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
:mozilla.37:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.177:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.178:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.179:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.180:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.181:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.182:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.29:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.30:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.31:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.32:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.174:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.175:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.176:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\WINDOWS\system32\helperymssmsgs.exe -> Trojan.Agent.an : No action taken.
C:\Documents and Settings\Patrick\Local Settings\Temp\3721.jpg -> Trojan.BCB.i : No action taken.


::Report end
Splat

We seem to have missed a step while running Ewido :(

C:\WINDOWS\Temp\12\cdnaux.dll -> Adware.Cdn : No action taken.
C:\WINDOWS\Temp\12\cdnup.exe -> Adware.Cdn : No action taken.

It should show C:\WINDOWS\Temp\12\cdnaux.dll -> Adware.Cdn : Cleaned or Quarantined

I need you to Boot into Safe mode and rerun Ewido following the instructions below again

Run EwidoClick scanner
Select Complete system scan
Once the scan finishesSelect Apply all actions (The items found will be quarantined)
Click save report as (Another window will open)
Save it to your desktop
(By default It will be saved in the Ewido folder as)
C:\Program Files\ewido anti-spyware 4.0\Reports
Exit Ewido

Then reboot your PC and repost the report_scan.txt From Ewido again please :)

thanks bamajim
ok tat was a bit noobish of me <_< 2nd time lucky: ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 10:37:12 PM 27/09/2006 + Scan result: C:\WINDOWS\system32\cdnns.dll -> Adware.Cdn : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{A64E86D2-203D-4145-AA9B-2425BAF568E9} -> Adware.Generic : Error during cleaning. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A64E86D2-203D-4145-AA9B-2425BAF568E9} -> Adware.Generic : Error during cleaning. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\1001hkcmd[1].txt -> Adware.IEHlpr : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\toto[1].txt -> Adware.IEHlpr : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Patrick\Desktop\Hihack this\backups\backup-20060926-114101-338.dll -> Adware.Webdir : Cleaned with backup (quarantined). C:\WINDOWS\system32\spreadno.exe -> Backdoor.SdBot.avw : Cleaned with backup (quarantined). C:\WINDOWS\system32\winystems.exe -> Backdoor.SdBot.avw : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Templates\5fbcb5c\1.dll -> Downloader.Delf.asz : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\13519[1].txt -> Downloader.Delf.axa : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\13519[1].txt -> Downloader.Delf.axa : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\huacai904[1].txt -> Downloader.Delf.axl : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\setup175[1].txt -> Downloader.Delf.axl : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\setup[2].txt -> Downloader.Delf.axl : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\huacai904[1].txt -> Downloader.Delf.axl : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\setup[2].txt -> Downloader.Delf.axl : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\18gou[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\p1[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\maohehe12[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\tanchuang1[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\17kanmmm[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\maohehe95[1].htm -> Downloader.IstBar.ai : Cleaned with backup (quarantined). C:\WINDOWS\system32\Rundl132.dll -> Downloader.Zlob : Cleaned with backup (quarantined). C:\Documents and Settings\Patrick\Desktop\Hihack this\backups\backup-20060927-004425-991.dll -> Hijacker.BHO.f : Cleaned with backup (quarantined). C:\WINDOWS\cert.exe -> Hijacker.BHO.f : Cleaned with backup (quarantined). C:\WINDOWS\cnt.exe -> Hijacker.BHO.f : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\mm7[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\index[2].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\mm7[3].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\3[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\mm7[2].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined). C:\WINDOWS\system32\rinst.exe -> Not-A-Virus.Monitor.Win32.Perflogger.163 : Cleaned with backup (quarantined). :mozilla.133:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.54:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.148:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined). :mozilla.149:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined). :mozilla.160:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined). :mozilla.147:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.24:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.132:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.111:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.217:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.218:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.219:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.220:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.107:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.108:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.109:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.110:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.138:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.139:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.120:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined). :mozilla.263:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined). :mozilla.276:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.196:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.197:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.198:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.199:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.282:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.283:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.318:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.319:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.320:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.321:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.322:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.63:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.64:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.65:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.66:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.67:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.68:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.358:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.291:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined). :mozilla.74:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.75:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.76:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.77:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.78:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.104:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.105:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.106:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.293:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.176:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.177:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.178:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.179:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.180:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.181:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.31:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.173:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.174:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.175:C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\WINDOWS\system32\helperymssmsgs.exe -> Trojan.Agent.an : Cleaned with backup (quarantined). ::Report end
new HJT log :)

Logfile of HijackThis v1.99.1
Scan saved at 11:16:46 PM, on 27/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\UPDATE2\Update.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\MsgSys.EXE
c:\windows\system32\wbem\smss.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\BitComet\BitComet.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI