This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very slow and popups highjackthis log

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here is the log.. please help

Logfile of HijackThis v1.99.1
Scan saved at 4:45:45 PM, on 9/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\WINDOWS\QmlnIFRvZQ\command.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE
C:\Updater.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE
C:\WINDOWS\thiselt.exe
C:\windows\system32\ojdsregm.exe
C:\Program Files\Common Files\{585C1D41-07D2-3076-1027-040404160001}\Update.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\MINORG~1\APPLIC~1\ΑPPAT~1\userinit.exe
C:\Documents and Settings\Minorgliche\My Documents\?dobe\dνdplay.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\WINDOWS\system32\twinkpes.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Applications\HJT\jth.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ugqbw.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fbxeidk.exe
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\system32\nsp43.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll
O2 - BHO: (no name) - {A89AF847-1BD4-6F20-F7AF-611344DC30E6} - C:\WINDOWS\system32\sgiynfcn.dll
O2 - BHO: Banner Rotator - {D117A61F-92C3-4450-A0C8-F425B14D4127} - C:\WINDOWS\system32\adrotate.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O6 "USB002" /M "Stylus C84"
O4 - HKLM\..\Run: [Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P45 "Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ" /O24 "\\BIGGIE-SMALLZ\Printer3" /M "Stylus C84"
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [{C1-1D-D4-41-ZN}] C:\windows\system32\ojdsregm.exe ELT001
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Hinhueyr] C:\DOCUME~1\MINORG~1\APPLIC~1\YMANTE~1\POOLSV~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Asrc] "C:\DOCUME~1\MINORG~1\APPLIC~1\£DPPAT~1\userinit.exe" -vt yazr
O4 - HKCU\..\Run: [Clqpnqu] C:\Documents and Settings\Minorgliche\My Documents\?dobe\d£hdplay.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: http://free.aol.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O20 - AppInit_DLLs: repairs303169590.dll,csrss.dll
O20 - Winlogon Notify: WebCheck - C:\WINDOWS\system32\gp04l3dq1.dll (file missing)
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - C:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "C:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QmlnIFRvZQ\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


additional info: I couldnt defrag the drives for some reason and adaware can't get rid of all the popups. Thanks in advance
Hi I'm Angelfire777 and it'll be my pleasure to assist you in your problem. Reasearching Hijackthis logs could take sometime so please, be patient while I research a fix for you. Also, I have to let experts check my fixes first before bringing them to you. Please observe these while we work: 1.) Please stick with this thread until we are finished, do not start a new topic here or start a new thread at other forums. Do not worry, We were trained to help and never give up until we get you all fixed up. 2.) Stop if you have questions!! Never proceed if something is unclear to you. We don't want to start all over again. 3.) Avoid downloading other applications or other anti-spyware programs unless you really need to. 4.) Lastly, please be patient and never lose hope. Sometimes, it will take us several tries and posts to get something done. Sit back tight, I'll be back for you!
http://forums.tomcoyote.org/index.php?show…mp;#entry319447

I noticed that you are not running any AntiVirus application. You could get infected immediately after we clean you up. Please download and install ONE of these:

» Avast!
» AVG AntiVirus
» AntiVir
==========================
Look in your control panels add/remove programs for

1. PuritySCAN By OIN, OuterInfo, OIN or similar
2. SurfSideKick 3

If OIN is not listed, download and run this uninstaller:
Uninstaller

Tutorial for the uninstaller if needed

Reboot when done and delete these folders if found:
C:\Program Files\PurityScan
C:\Program Files\SurfSideKick 3
==========================
Please download Brute Force Uninstaller.
Unzip it to it’s own folder (c:\BFU)

RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra Remover.

Save it in the folder you made earlier (c:\BFU).
Open My Computer and navigate to the c:\BFU folder.

Start the Brute Force Uninstaller by doubleclicking BFU.exe
In the 'Scriptline to execute' field, copy and paste:

c:\bfu\alcanshorty.bfu
Press execute and let it do it’s job.
Wait for the complete script execution box to pop up and press OK.
Press exit to terminate the BFU program.

Reboot
==========================
Download combofix.exe

1. Double click combofix.exe & follow the prompts.
2. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

==========================
On your next reply, please include:
  • A Fresh Hijackthis log
  • combofix log
  • A detailed description on how your computer is behaving
Thanks a lot angel fire. You've been of great help

here is a fresh highjackthis log

Logfile of HijackThis v1.99.1
Scan saved at 12:18:52 AM, on 9/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Applications\HJT\jth.exe

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O6 "USB002" /M "Stylus C84"
O4 - HKLM\..\Run: [Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P45 "Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ" /O24 "\\BIGGIE-SMALLZ\Printer3" /M "Stylus C84"
O4 - HKLM\..\Run: [{C1-1D-D4-41-ZN}] C:\windows\system32\ojdsregm.exe ELT001
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Hinhueyr] C:\DOCUME~1\MINORG~1\APPLIC~1\YMANTE~1\POOLSV~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinkpes.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: http://free.aol.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - C:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "C:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)




And here is the combofix log…

Minorgliche - 06-09-26 0:07:59.95 Service Pack 2
ComboFix 06.09.25 - Running from: "C:\Documents and Settings\Minorgliche\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\CLSID\{138660A6-4FD9-4210-B268-71BA39186CBA}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{138660A6-4FD9-4210-B268-71BA39186CBA}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{138660A6-4FD9-4210-B268-71BA39186CBA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{138660A6-4FD9-4210-B268-71BA39186CBA}\InprocServer32]
@="C:\\WINDOWS\\system32\\wqspdmod.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *




((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))


* * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * *


F2 -REG:system.ini: UserInit C:\WINDOWS\system32\fbxeidk.exe


* * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * *


06-09-06 08:42 127488 jtoaj.dat.qoo
06-09-06 08:42 53 vpwbpn.dat.qoo

DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Minorgliche\Application Data\Sskcwrd.dll
C:\Documents and Settings\Minorgliche\Application Data\Sskknwrd.dll
C:\Documents and Settings\Minorgliche\Application Data\Sskuknwrd.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\TClock\tclock_install.exe
C:\WINDOWS\system32\aaa00000.dll
C:\WINDOWS\system32\aaa00000.sys
C:\WINDOWS\system32\adrot-uninst.exe
C:\WINDOWS\system32\dwdsregt.exe
C:\WINDOWS\system32\WinNB58.dll
C:\WINDOWS\justin.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Program Files\Inetget2
C:\Program Files\Common Files\{585C1D41-07D2-3076-1027-040404160001}
C:\Program Files\network monitor
C:\WINDOWS\QmlnIFRvZQ

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\YMANTE~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\詴PAT~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\蔍KS~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\YMANTE~1\bak
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\詴PAT~1\bak
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\詴PAT~1\userinit.exe
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\詴PAT~1\詴PAT~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\詴PAT~1\bak\userinit.exe
C:\QooBox\Purity\Documents and Settings\Minorgliche\My Documents\CURITY~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\My Documents\DOBE~1
C:\QooBox\Purity\Documents and Settings\Minorgliche\My Documents\ICROSO~1.NET
C:\QooBox\Purity\Program Files\APPATC~1
C:\QooBox\Purity\Program Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\ASEMBL~1
C:\QooBox\Purity\WINDOWS\DOBE~1
C:\QooBox\Purity\WINDOWS\STEM32~1
C:\QooBox\Purity\WINDOWS\system32\PPPATC~1


((((((((((((((((((((((((((((((( Files Created from 2006-08-26 to 2006-09-26 ))))))))))))))))))))))))))))))))))


2006-09-25 08:54 17,787 –a—— C:\WINDOWS\system32\ieuiphr.dll
2006-09-24 16:21 918 –a—— C:\WINDOWS\system32\winpfg32.sys
2006-09-21 17:28 21,504 –a—— C:\WINDOWS\system32\twinkpes.exe
2006-09-21 07:51 21,504 –a—— C:\WINDOWS\system32\ojdsregm.exe
2006-09-20 23:54 45,065 –a—— C:\WINDOWS\TIELT001.exe
2006-09-20 23:54 32,768 –a—— C:\WINDOWS\system32\WinDmy.dll
2006-09-20 23:54 30,208 –a—— C:\WINDOWS\ss1205.exe
2006-09-20 23:54 29,696 –a—— C:\WINDOWS\system32\w037ce12.dll
2006-09-20 23:54 25,105 –a—— C:\WINDOWS\idlemg.exe
2006-09-20 23:54 2,560 –a—— C:\WINDOWS\ac3_0002.exe
2006-09-20 23:54 168,041 –a—— C:\WINDOWS\system32\twinkpex.exe
2006-09-20 23:54 139,264 –a—— C:\WINDOWS\MirarSetup_876057.exe
2006-09-06 08:42 529 –a—— C:\WINDOWS\crgdo.dll
2006-09-01 20:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-26 00:10 ——– d——– C:\Program Files\Common Files
2006-09-26 00:09 ——– d——– C:\Program Files\TClock
2006-09-26 00:06 ——– d——– C:\Program Files\Mozilla Firefox
2006-09-25 23:09 777472 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-09-25 23:09 4992 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys
2006-09-25 23:09 4288 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-09-25 23:09 27904 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-09-25 23:09 23424 –a—— C:\WINDOWS\system32\drivers\avgmfrs.sys
2006-09-25 23:09 ——– d—s—- C:\Documents and Settings\Minorgliche\Application Data\Microsoft
2006-09-25 23:09 ——– d——– C:\Program Files\Grisoft
2006-09-25 23:09 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\AVG7
2006-09-25 09:25 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\AdobeUM
2006-09-24 21:35 ——– d——– C:\Program Files\QuickTime
2006-09-24 21:34 21504 –a—— C:\WINDOWS\system32\NeroCheck.exe
2006-09-24 21:34 21504 –a—— C:\Updater.exe
2006-09-22 23:05 ——– d——– C:\Program Files\Trillian Pro
2006-09-11 11:58 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\Adobe
2006-09-07 14:19 ——– d——– C:\Program Files\Autodesk
2006-09-05 12:17 ——– d——– C:\Program Files\Common Files\Autodesk Shared
2006-08-25 13:30 ——– d——– C:\Program Files\Autodesk Revit 7.0
2006-08-12 17:47 ——– d——– C:\Program Files\NoAdware4
2006-08-11 11:36 ——– d——– C:\Program Files\tlc
2006-08-11 11:31 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\Mozilla
2006-08-07 21:29 ——– d——– C:\Program Files\Common Files\Adobe
2006-08-07 11:42 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\Aim
2006-08-05 10:35 205 –a—— C:\WINDOWS\system32\lsprst7.dll
2006-08-05 10:33 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-05 10:33 ——– d——– C:\Program Files\Computers and Structures
2006-08-02 16:08 ——– d——– C:\Documents and Settings\Minorgliche\Application Data\PC Tools
2006-08-02 15:45 ——– d——– C:\Program Files\Yahoo!
2006-08-02 15:45 ——– d——– C:\Program Files\Common Files\Scanner
2006-08-02 12:54 ——– d——– C:\Program Files\Common Files\Companion Wizard
2006-07-30 23:41 1064 –a—— C:\WINDOWS\system32\hof5755d.sys
2006-07-30 22:38 39424 –a—— C:\WINDOWS\mtuninst.exe
2006-07-30 22:36 14617 –a—— C:\WINDOWS\xload.exe
2006-07-30 22:26 61440 –a—— C:\WINDOWS\system32\hof5755d.dll
2006-07-10 00:55 0 –a–c— C:\WINDOWS\system32\ssprs.dll
2006-07-01 12:42 797477 –a—— C:\Program Files\PowerISO32.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
@=""
"ATI Remote Control"="C:\\Program Files\\ATI Multimedia\\RemCtrl\\ATIRW.exe"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"Hinhueyr"="C:\\DOCUME~1\\MINORG~1\\APPLIC~1\\YMANTE~1\\POOLSV~1.EXE"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"ASUS Probe"="C:\\Program Files\\ASUS\\Probe\\AsusProb.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PtiuPbmd"="Rundll32.exe ptipbm.dll,SetWriteBack"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Logitech Utility"="Logi_MwX.Exe"
"MMTray"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe"
"zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
"EPSON Stylus C64 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2C1.EXE /P23 \"EPSON Stylus C64 Series\" /O6 \"USB001\" /M \"Stylus C64\""
"iRiver Updater"="\\Updater.exe"
"SoundMan"="SOUNDMAN.EXE"
"EPSON Stylus C84 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2D1.EXE /P23 \"EPSON Stylus C84 Series\" /O6 \"USB002\" /M \"Stylus C84\""
"Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2D1.EXE /P45 \"Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ\" /O24 \"\\\\BIGGIE-SMALLZ\\Printer3\" /M \"Stylus C84\""
"WMC_AutoUpdate"=""
"{C1-1D-D4-41-ZN}"="C:\\windows\\system32\\ojdsregm.exe ELT001"
"adstart"="\"iexplore.exe\" \"http://iesettingsupdate\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoRecentDocsHistory"=hex:01,00,00,00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Tue 09/26/2006 0:15:49.37
ComboFix.txt


The computer seems faster than before but not as fast as it was 2 years back probably because i have too much junk in it. i will try to defrag later and clean up stuff. But the speed seems to be almost back to 100%. not too much lag. but everytime i reboot the computer ie starts automatically with some address w/o a .com and gives me a cannot load this page.
1.) click start > run > type in taskmgr.exe

Go to the process tab then end these processes if you see them:

conime.exe


2.) Please download Ewido to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install Ewido by double clicking the installer.
  • Follow the prompts. Make sure that Launch Ewido is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.


3.) Download ATF Cleaner by Atribune

This program is for XP and Windows 2000 only
DO NOT USE IT YET!!


4.) Open Hijackthis > choose Scan Only > Place a checkmark against the boxes beside these entries in bold.

O4 - HKLM\..\Run: [{C1-1D-D4-41-ZN}] C:\windows\system32\ojdsregm.exe ELT001
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [Hinhueyr] C:\DOCUME~1\MINORG~1\APPLIC~1\YMANTE~1\POOLSV~1.EXE
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinkpes.exe
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: http://free.aol.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)


Close your browsers and all open windows, then click "Fix Checked."


5.) You may want to print these instructions here or save them in notepad since you'll work offline.

Reboot into Safe Mode.

To enter Safe Mode..

Click Start > Turn Off Computer > Restart > Tap F8 key just before Windows starts to load, > This will bring up a Menu > Use your keyboard to scroll to Safe Mode> Hit enter.


6.) You may need to see your hidden files first

Windows XP
  • Click Start.
  • Open My Computer
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the "Hidden files and folders" heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK
7.) Open Windows Explorer by hitting your windows key + E at the same time.
*If you do not have a windows key, double click My computer > click the folders icon

Then navigate to these files and delete them:

C:\WINDOWS\System32\conime.exe
C:\WINDOWS\System32\dwdsregt.exe
C:\WINDOWS\System32\twinkpes.exe
C:\WINDOWS\System32\ojdsregm.exe
C:\WINDOWS\system32\twinkpes.exe
C:\WINDOWS\system32\ojdsregm.exe
C:\WINDOWS\TIELT001.exe
C:\WINDOWS\system32\WinDmy.dll
C:\WINDOWS\ss1205.exe
C:\WINDOWS\system32\w037ce12.dll
C:\WINDOWS\idlemg.exe
C:\WINDOWS\ac3_0002.exe
C:\WINDOWS\system32\twinkpex.exe
C:\WINDOWS\MirarSetup_876057.exe
C:\WINDOWS\mtuninst.exe
C:\WINDOWS\system32\hof5755d.sys
C:\WINDOWS\xload.exe
C:\WINDOWS\system32\hof5755d.dll
C:\WINDOWS\system32\ssprs.dll


Next, navigate to this folder here: C:\DOCUMEnts and settings\MINORGliche\APPLICation data

Inside that folder, delete another folder that starts with this name: YMANTE

Empty your recycle bin


8.)
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


9.) Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
  • Click on Scanner
  • Click on the Settings tab.
    • Under How to act?
      Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      All checkboxes should be ticked.
    • Under Possibly unwanted software:
      All checkboxes should be ticked.
    • Under Reports:
      Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished:
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
  • When done, click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.


10.) I would like you to scan a few files for me.

Please go HERE. Click browse then, navigate to this file:

C:\WINDOWS\system32\ieuiphr.dll

Then click submit.

Do the same for this file: C:\WINDOWS\crgdo.dll

Please post the results to your next reply

If Jotti is too busy, toy can go HERE and do the same as above.

On your next reply, please include:
  • A Fresh Hijackthis log
  • ewido log
  • results of jotti scan
  • A detailed description on how your computer is behaving
sorry for the late update. i've been out of town.
update: i was unable to get into regular safe mode. computer would freeze while loading. but i got into safemode w/ networking and did everything there as adminstrator.
here is the ewido log
In safe mode, the screen was big and i was unable to see the check marks for the system scan. i believe the one for zip and rar files was not checked along with another one. But i am not sure. here is what i got

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 5:54:01 PM 10/1/2006

+ Scan result:



C:\WINDOWS\bak\thiselt.exe -> Adware.Agent : No action taken.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : No action taken.
C:\WINDOWS\amm06.ocx -> Adware.MediaMotor : No action taken.
C:\WINDOWS\em.ocx -> Adware.MediaMotor : No action taken.
C:\WINDOWS\webhdll.dll_tobedeleted -> Adware.WebHancer : No action taken.
C:\WINDOWS\system32\bak\ojdsregm.exe -> Adware.ZenoSearch : No action taken.
C:\WINDOWS\system32\bak\twinkpes.exe -> Adware.ZenoSearch : No action taken.
C:\Updater.exe -> Downloader.Agent.awf : No action taken.
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\αPPAT~1\userinit.exe -> Downloader.PurityScan.co : No action taken.
C:\QooBox\Purity\Documents and Settings\Minorgliche\Application Data\αPPAT~1\bak\userinit.exe -> Downloader.PurityScan.da : No action taken.
C:\QooBox\jtoaj.dat.qoo -> Downloader.Qoologic.bj : No action taken.
C:\WINDOWS\system32\bak\ewawxx.exe -> Downloader.Qoologic.bj : No action taken.
C:\WINDOWS\xload.exe -> Downloader.VB.wz : No action taken.
C:\WINDOWS\system32\mdrpdev.exe -> Hijacker.VB.ip : No action taken.
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
:mozilla.370:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.418:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.442:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.294:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.295:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.434:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Addcontrol : No action taken.
:mozilla.274:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.275:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.276:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.277:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.278:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.700:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.701:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.204:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.205:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.206:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.207:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.208:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.209:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.94:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.95:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.96:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.97:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.98:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.27:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.414:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.293:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.290:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.291:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.292:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.164:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.288:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.289:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.138:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.139:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.140:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.495:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.376:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.134:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.135:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.136:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.137:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.21:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.454:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.145:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.146:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.147:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.148:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.114:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.115:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.116:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.179:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.180:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.181:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.182:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.183:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.184:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.185:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.29:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.30:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.31:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.32:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.168:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Findwhat : No action taken.
:mozilla.420:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.421:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.424:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.425:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.426:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.427:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.475:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.477:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.485:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.109:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Linksynergy : No action taken.
:mozilla.110:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Linksynergy : No action taken.
:mozilla.379:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.382:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.151:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.152:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.279:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.224:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Planetactive : No action taken.
:mozilla.262:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.263:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.264:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.265:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.266:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.481:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Popularix : No action taken.
:mozilla.90:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.92:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.54:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.55:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.172:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.173:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.174:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.175:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.154:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.155:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.156:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.157:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.158:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.159:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.127:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.128:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.129:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.130:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.131:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.132:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.428:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.429:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.51:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.52:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.53:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.160:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.161:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.162:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.163:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.351:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.352:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.353:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.354:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.355:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.356:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.357:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.141:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.142:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.143:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.144:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.734:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Valueclick : No action taken.
:mozilla.64:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.45:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.46:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.432:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.433:C:\Documents and Settings\Minorgliche\Application Data\Mozilla\Firefox\Profiles\alwm0y3s.default\cookies.txt -> TrackingCookie.Zedo : No action taken.


::Report end


here is a new HJT report

Logfile of HijackThis v1.99.1
Scan saved at 6:13:15 PM, on 10/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\bak\twinkpes.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Applications\HJT\jth.exe

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O6 "USB002" /M "Stylus C84"
O4 - HKLM\..\Run: [Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P45 "Auto EPSON Stylus C84 Series on BIGGIE-SMALLZ" /O24 "\\BIGGIE-SMALLZ\Printer3" /M "Stylus C84"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\bak\twinkpes.exe ELT001
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - C:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "C:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


I am still trying the Jotti. i will update as soon as i get that.
so far the computer is running well. still some popups but i think its the website that i go to. i'm pretty satisfied with the performance as of this moment. but i still cannot defrag the computer for some reason.

Thanks for all the help.

udate:
for ieuiphr.dll ….. i get this
The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

but AVG popup said it was a virus clone or something so i moved it to the vault

for crgdo.dll ….. Jotti found nothing
Ok. Remember to NEVER EVER go online while you are in Safe Mode with networking. Your computer will attract more malware if that happens.

1.) Please re-run Ewido in Safe Mode again and this time please Hit the "Apply all actions" button before hitting the "Save Report" button. After scanning, please Reboot back to normal mode.


2.) Open Hijackthis > choose Scan Only > Place a checkmark against the boxes beside these entries in bold.

O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\bak\twinkpes.exe ELT001
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)


Close your browsers and all open windows except for Hijackthis, then click "Fix Checked."


3.) Open Windows Explorer by hitting your Windows Key + E at the same time.
*If you do not have a Windows Key, double click My Computer > Click the folders icon

Then navigate to these folders and delete them:

C:\Program Files\AWS
C:\WINDOWS\system32\bak\twinkpes.exe

Empty Your Recycle Bin


4.) Reboot


5.) Some of your important windows files may be corrupt, please run the Window's System File checker. You will need your Windows XP CD.
  • go to start > run > type in: sfc /scannow (note that there is a space between "c" and "/")
If you need some more info or should you encounter any troubles, go HERE and read through the process.

Then see if you can defrag your drive after that.

On your next reply, please include:
  • A Fresh Hijackthis log
  • Ewido log
  • A detailed description on how your computer is behaving
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI