This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected computer!

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to clean a friends computer and need some help. Here is the HJT log.
Thanks
Ed Varner

Logfile of HijackThis v1.99.1
Scan saved at 6:59:52 PM, on 10/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\QW50aG9ueSBDbGFyaw\command.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SPAMBL~1\Bin\471~1.0\SBInst.exe
C:\Program Files\SpamBlockerUtility\Bin\4.7.1.0\SbOEAddOn.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\v1201.exe
C:\WINDOWS\sys01404107721.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\oobljttA.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\system32\czuehf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\zqskw.exe
C:\Program Files\PSLister\PSLister.exe
C:\WINDOWS\system32\ha3f.exe
C:\WINDOWS\system32\fufudc.exe
C:\Program Files\CMFibula\CMFibula.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\ghynf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\reter.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cabhckl.exe
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: SearchHelper - {B6A5B638-6025-4C2C-A899-867B416453D2} - C:\Program Files\SearchHelper\SearchHelper.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\471~1.0\SBInst.exe
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.7.1.0\SbOEAddOn.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [ong27871] RUNDLL32.EXE w07bf372.dll,n 0032786e0000000307bf372
O4 - HKLM\..\Run: [sys01404107721] C:\WINDOWS\sys01404107721.exe
O4 - HKLM\..\Run: [oobljttA] C:\WINDOWS\oobljttA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [RreN4HW] C:\WINDOWS\system32\czuehf.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O8 - Extra context menu item: Allow Popups - C:\Program Files\Meaya\Popup Ad Filter\WhiteGetUrl.js
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.adsextend.net
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.adsextend.net (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\p4p60e7seh.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QW50aG9ueSBDbGFyaw\command.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Hi,

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Danny :)
Thanks for your reply. Here is the combofix log. Thanks again Ed Varner Anthony - 06-10-07 8:45:51.05 Service Pack 2 ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Anthony\Desktop" ((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log )))))))))))))))))))))))))))))))))))))))))))))))))) REGISTRY ENTRIES REMOVED: [HKEY_CLASSES_ROOT\CLSID\{E1EFCDDD-F7D5-4EBC-A8BA-BA2025835CDD}] @="" [HKEY_CLASSES_ROOT\CLSID\{E1EFCDDD-F7D5-4EBC-A8BA-BA2025835CDD}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{E1EFCDDD-F7D5-4EBC-A8BA-BA2025835CDD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{E1EFCDDD-F7D5-4EBC-A8BA-BA2025835CDD}\InprocServer32] @="C:\\WINDOWS\\system32\\sjdpsrv.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{74F4211A-6BE5-4D17-BC39-EB8307409516}] @="" [HKEY_CLASSES_ROOT\CLSID\{74F4211A-6BE5-4D17-BC39-EB8307409516}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{74F4211A-6BE5-4D17-BC39-EB8307409516}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{74F4211A-6BE5-4D17-BC39-EB8307409516}\InprocServer32] @="C:\\WINDOWS\\system32\\ntdenb32.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{2FEE583F-C140-49E0-BF5F-EB04E3242F09}] @="" [HKEY_CLASSES_ROOT\CLSID\{2FEE583F-C140-49E0-BF5F-EB04E3242F09}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{2FEE583F-C140-49E0-BF5F-EB04E3242F09}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{2FEE583F-C140-49E0-BF5F-EB04E3242F09}\InprocServer32] @="C:\\WINDOWS\\system32\\mdstkprp.dll" "ThreadingModel"="Apartment" [HKEY_CLASSES_ROOT\CLSID\{D7E902F9-6CDE-4557-A323-568DE65CC857}] @="" [HKEY_CLASSES_ROOT\CLSID\{D7E902F9-6CDE-4557-A323-568DE65CC857}\Implemented Categories] @="" [HKEY_CLASSES_ROOT\CLSID\{D7E902F9-6CDE-4557-A323-568DE65CC857}\Implemented Categories\{00021492-0000-0000-C000-000000000046}] @="" [HKEY_CLASSES_ROOT\CLSID\{D7E902F9-6CDE-4557-A323-568DE65CC857}\InprocServer32] @="C:\\WINDOWS\\system32\\dLnim.dll" "ThreadingModel"="Apartment" * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * FILES REMOVED: C:\WINDOWS\system32\en40l1hm1.dll C:\WINDOWS\system32\en80l1lm1.dll C:\WINDOWS\system32\g040lahm1d4a.dll C:\WINDOWS\system32\g0jola131d.dll C:\WINDOWS\system32\hiink.dll C:\WINDOWS\system32\k0lq0a35ed.dll C:\WINDOWS\system32\l0r00a9med.dll C:\WINDOWS\system32\m0pola731d.dll C:\WINDOWS\system32\m8ju0i19e8.dll C:\WINDOWS\system32\mdstkprp.dll C:\WINDOWS\system32\mirt.dll C:\WINDOWS\system32\mv06l9ds1.dll C:\WINDOWS\system32\nemsmgr.dll C:\WINDOWS\system32\rYsadhlp.dll C:\WINDOWS\system32\sjdpsrv.dll C:\WINDOWS\system32\slclient.dll C:\WINDOWS\system32\wjaueng1.dll C:\WINDOWS\system32\wP5inf32.dll C:\WINDOWS\system32\wubcheck.dll Granting sedebugprivilege to Administrators … successful ((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))) * * * PRE-RUN - Filepaths extracted from the Registry * * * * * * * * * * * * * * * * * * * * * * O4 - HKCU\…\Run C:\WINDOWS\system32\budarf.exe O4 - HKLM\…\Run C:\WINDOWS\system32\budarf.exe F2 -REG:system.ini: Shell C:\WINDOWS\system32\reter.exe F2 -REG:system.ini: UserInit C:\WINDOWS\system32\cabhckl.exe * * * PRE-RUN - Filepaths extracted by Memory Dump * * * * * * * * * * * * * * * * * * * * * * C:\WINDOWS\system32\budarf.exe C:\WINDOWS\system32\hcdajnw.dll C:\WINDOWS\system32\cabhckl.exe C:\Documents and Settings\All Users\Start Menu\Programs\Startup\tdobx.exe C:\WINDOWS\aqjgj.dll C:\WINDOWS\system32\gsrde.dat C:\WINDOWS\system32\reter.exe * * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * * 06-08-17 18:38 127488 budarf.exe.qoo 06-10-05 18:33 127488 gsrde.dat.qoo 06-08-17 18:38 127488 tdobx.exe.qoo 06-08-17 18:38 51712 hcdajnw.dll.qoo 06-08-17 18:38 28672 reter.exe.qoo 06-08-17 18:38 23552 cabhckl.exe.qoo 06-08-29 20:08 361 aqjgj.dll.qoo 06-08-17 18:38 53 vpcpvc.dat.qoo DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\Duce6.exe C:\dfndrff_11.exe C:\dfndrff_11a.exe C:\dfndrff_12.exe C:\dfndrff_14.exe C:\deskbar.exe C:\kybrdff_11.exe C:\kybrdff_11a.exe C:\kybrdff_12.exe C:\kybrdff_14.exe C:\nwnmff_11.exe C:\nwnmff_12.exe C:\nwnmff_14.exe C:\WINDOWS\system32\bez6n4r21.exe C:\WINDOWS\system32\cvn0.exe C:\WINDOWS\system32\ghynf.exe C:\WINDOWS\system32\n9nyb.exe C:\WINDOWS\system32\wfxqhv.exe C:\WINDOWS\system32\xeymi.dll C:\WINDOWS\system32\zqskw.exe C:\RDFX4.exe C:\WINDOWS\offun.exe C:\WINDOWS\system32bez6n4r21.exe C:\WINDOWS\system32ghynf.exe C:\WINDOWS\system32n9nyb.exe C:\WINDOWS\thiselt.exe C:\WINDOWS\uninst104.exe C:\WINDOWS\wallpap.exe C:\WINDOWS\RDFX4.exe C:\WINDOWS\MirarSetup_876075.exe C:\WINDOWS\whCC-GIANT.exe C:\WINDOWS\Eim03.exe C:\WINDOWS\uni_ehhhh.exe C:\Documents and Settings\LocalService\Application Data\NetMon C:\Program Files\batty2 C:\Program Files\cmfibula C:\Program Files\Deskbar C:\Program Files\network monitor C:\Program Files\PSLister C:\Program Files\TheSearchAccelerator C:\WINDOWS\QW50aG9ueSBDbGFyaw ((((((((((((((((((((((((((((((( Files Created from 2006-09-07 to 2006-10-07 )))))))))))))))))))))))))))))))))) 2006-10-05 17:23 26,496 –a—— C:\WINDOWS\system32\drivers\USBSTOR.SYS (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-07 08:40 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-10-05 20:01 ——– d——– C:\Program Files\Windows Startup Inspector 2006-10-05 20:01 ——– d——– C:\Program Files\Lavasoft 2006-10-05 20:01 ——– d——– C:\Documents and Settings\Anthony\Application Data\Lavasoft 2006-10-05 19:59 ——– d——– C:\Program Files\Microsoft AntiSpyware 2006-10-05 19:57 ——– d-a—— C:\Program Files\Common Files 2006-10-05 19:57 ——– d——– C:\Program Files\EndItAll 2006-10-05 19:53 ——– d——– C:\Program Files\Yahoo! 2006-10-05 19:52 ——– d——– C:\Program Files\WxEx 2006-08-29 20:09 53248 –a—— C:\topaff.exe 2006-08-29 20:09 1233 –a—— C:\WINDOWS\system32\ong27871.sys 2006-08-24 19:39 45056 –a—— C:\WINDOWS\system32fufudc.exe 2006-08-24 19:39 28672 –a—— C:\WINDOWS\system32ra8pv.exe 2006-08-24 19:39 24576 –a—— C:\WINDOWS\system32ha3f.exe 2006-08-24 18:29 45056 –a—— C:\WINDOWS\system32\fufudc.exe 2006-08-24 18:29 28672 –a—— C:\WINDOWS\system32\ra8pv.exe 2006-08-24 18:29 24576 –a—— C:\WINDOWS\system32\ha3f.exe 2006-08-23 22:00 53120 –a—— C:\WINDOWS\srvdhwghnt.exe 2006-08-23 22:00 507904 –a—— C:\814.exe 2006-08-23 22:00 214749 –a—— C:\WINDOWS\srvmfnedhw.exe 2006-08-20 18:02 52224 –a—— C:\WINDOWS\ms050772140412006.exe 2006-08-17 18:46 353280 –a—— C:\803_104.exe 2006-08-17 18:46 186223 –a—— C:\WINDOWS\srvzprdepi.exe 2006-08-17 18:45 214752 –a—— C:\Setup100.exe 2006-08-17 18:39 2560 –a—— C:\ac3_0003.exe 2006-08-17 18:38 290816 –a—— C:\installerwnusnewer.exe 2006-08-17 18:27 110592 –a—— C:\WINDOWS\v1201.exe 2006-08-17 18:26 28672 –a—— C:\WINDOWS\system32\iqqr.exe 2006-08-17 18:20 57344 –a—— C:\fym9bvo.exe 2006-08-14 20:52 78848 –a—— C:\WINDOWS\system32\nse6.dll 2006-08-11 12:05 155648 –a—— C:\WINDOWS\vSg21-d.exe 2006-08-11 12:05 155648 –a—— C:\WINDOWS\sys01404107721.exe 2006-08-11 12:05 155648 –a—— C:\WINDOWS\ms05077214041.exe 2006-08-07 11:17 61440 –a—— C:\WINDOWS\system32\BattyRun2.dll 2006-07-31 12:10 1142784 –a—— C:\WINDOWS\system32\kcnzrop6.exe 2006-07-31 12:09 24576 –a—— C:\WINDOWS\system32\ewxcksr.exe 2006-07-31 12:08 135168 –a—— C:\WINDOWS\system32\czuehf.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\"" "QD FastAndSafe"="" "RreN4HW"="C:\\WINDOWS\\system32\\czuehf.exe" "k6mmN5IOU"="\"C:\\WINDOWS\\system32\\wfxqhv.exe\"" "ad8rIU3s"="C:\\WINDOWS\\system32\\cvn0.exe" "sys01404107721"="C:\\WINDOWS\\sys01404107721.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e4,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,cb,00,00,00,00,00,00,00,2f,03,00,00,00,03,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,cb,00,00,00,00,00,00,00,2f,03,00,00,00,03,\ 00,00,01,00,00,00 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe" [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^tdobx.exe] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\tdobx.exe" "backup"="C:\\WINDOWS\\pss\\tdobx.exeCommon Startup" "location"="Common Startup" "command"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\tdobx.exe" "item"="tdobx" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ACTX1] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="v1201" "hkey"="HKLM" "command"="C:\\WINDOWS\\v1201.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ad8rIU3s] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cvn0" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\cvn0.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\amhqrd] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="budarf" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\budarf.exe reg_run" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\k6mmN5IOU] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="wfxqhv" "hkey"="HKLM" "command"="\"C:\\WINDOWS\\system32\\wfxqhv.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ong27871] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RUNDLL32" "hkey"="HKLM" "command"="RUNDLL32.EXE w07bf372.dll,n 0032786e0000000307bf372" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\oobljttA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="oobljttA" "hkey"="HKLM" "command"="C:\\WINDOWS\\oobljttA.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\RreN4HW] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="czuehf" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\czuehf.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\sys01404107721] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="sys01404107721" "hkey"="HKLM" "command"="C:\\WINDOWS\\sys01404107721.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TheMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Duce6" "hkey"="HKLM" "command"="C:\\WINDOWS\\Duce6.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\wjoss] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="budarf" "hkey"="HKCU" "command"="C:\\WINDOWS\\system32\\budarf.exe reg_run" "inimapping"="0" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: Sat 10/07/2006 8:56:30.22 ComboFix.txt
Sorry I forgot the new HJT log. Here it is.
Thanks
Ed Varner

Logfile of HijackThis v1.99.1
Scan saved at 6:58:55 PM, on 10/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\czuehf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ha3f.exe
C:\WINDOWS\system32\fufudc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RreN4HW] C:\WINDOWS\system32\czuehf.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [sys01404107721] C:\WINDOWS\sys01404107721.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.adsextend.net
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.adsextend.net (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - (no file)
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Hi,

You have an About:Blank infection. Please follow these steps carefully:

Step#1:Getting Ready


Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.

After downloading the tools, you must disconnect from the internet totally, because staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection.

To replace Internet Explorer to use during this fix, please use Internet Explorer once to download and install FireFox, to be used as your alternate browser throughout this fix.

Close Outlook Express and Internet Explorer for the duration of this fix

Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Please start by downloading the tools you will need to clean this infection, using FireFox. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you finally reply.


Step#2:Show All Hidden Files Very Important

Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
http://www.davehigham.zen.co.uk/downloads/xphidden.zip


Step#3:Download CWShredder Do Not Use Yet

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates but please Do NOT use it yet



Step#4:Download About Buster Do Not Use Yet

1. Please download About:Buster from here.

2. Once it is downloaded extract it to c:\aboutbuster.

3. Check to make sure it is up-to-date. Please Do NOT use it yet

Step#5:Download Registrar Registry Manager Do Not Use Yet

Another program to download is Registrar Registry Manager for use later: Please download Registrar Registry Manager and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use. Caution should be exercised when editing the registry as it is very easy to render a Computer unbootable by deleting the wrong key

Step#6:Download Ewido Anti Malware Do Not Use Yet
  • Download and install Ewido anti malware
  • Right Click on the “E” icon in your taskbar and open Ewido Anti Mlaware then click “update” to get the most recent definitions for it to use.
  • When it prompts you to update, click the OK button.
  • download the updates and when they are finished installing, close the window
  • Please Do Not Use It Yet
Step#7:Download A Registry File to Remove Registry Entries Do Not Use Yet
  • Please download the following zip file to your desktop:
    HSfix
  • Double Click on HSfix.zip and it will unzip to a new folder it makes on your desktop, called HSfix
  • Do Not Use It Yet
Please disconnect from the Internet





Step#8:Stop The Running Processes


Press control-alt-delete to get into the task manager and end the following processes if they exist:

czuehf.exe
wfxqhv.exe
cvn0.exe
sys01404107721.exe

Step#9:Delete About Blank Bad Files

I now need you to delete the following files:

C:\WINDOWS\system32\czuehf.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\sys01404107721.exe


If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#10:Cleaning With HijackThis

Now, Open HijackThis, click the "Scan" button, and put a checkmark next to each of these entries:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O4 - HKLM\..\Run: [RreN4HW] C:\WINDOWS\system32\czuehf.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [sys01404107721] C:\WINDOWS\sys01404107721.exe
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.adsextend.net
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.adsextend.net (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - (no file)





Close all open windows and click 'fix checked' button when ready.




Step#11: Backup The Registry


1. Open Registrar Registry Manager and run it.

2. Copy and paste the bold text below into the address bar of Registrar Registry Manager:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Registry Manager (Reglite) folder):
1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)






Step#12: Use the HSfix.reg file
  • Navigate to the HSfix folder on your Desktop
  • Then double-click on the HSfix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
  • if you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it
Step#13:Fixing With CWShredder
  • CLOSE ALL WINDOWS except CWShredder
  • Run the program by clicking 'fix' and letting it fix all CWS remnants.
Step#14:Fixing With About Buster

This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory
  • double-click on aboutbuster.exe
  • When the tool opens press the OK button, then Start button, then the OK button
  • then finally the Yes button. It will start scanning your computer for files.
  • If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply
Step#15:Scan With Ewido Anti Malware
  • Launch Ewido again
  • Click on Scanner>Complete System Scan.
  • Let the program scan your PC.
  • When the scan asks to clean files click OK.
  • When scan is completed, click Save report. to your desktop.
  • Post the report in your next reply.
Reboot your computer back to normal mode and

Reconnect To The Internet



Step#16:Scan and Post a New HJT log with other logs
  • Scan again with HijackThis.
  • Post your logs from HijackThis, About Buster, and Ewido Anti Malware here in this thread with any questions or problems that you have run into.
  • There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.
Good Luck!

Danny :)
Here are the log files you requested. Thanks Ed Varner Aboutbuster log: AboutBuster 6.05 Scan started on [10/8/2006] at [4:49:48 PM] ————————————————————- Internet Explorer Instances Terminated! HomeSearch Service stopped if present ————————————————————- No Ads Found! ————————————————————- No Files Found! ————————————————————- Scan was COMPLETED SUCCESSFULLY at 4:52:20 PM Ewido log: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 6:38:37 PM 10/8/2006 + Scan result: C:\WINDOWS\system32\BattyRun2.dll -> Adware.CASClient : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\drsmartload180a[1].exe -> Adware.DollarRevenue : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\kybrdff_11[1].exe -> Adware.DollarRevenue : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\18B67A3C-802A-472B-B537-49B736\52990647-A3F6-4948-8A29-262D74 -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\18B67A3C-802A-472B-B537-49B736\D2138335-EFCF-4F12-AAB2-07E2EC -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\1DA6C7D3-4A73-4B84-BF9D-5D5FAD\556B1B8A-975B-43B8-8042-586E98 -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\879EEE63-962B-462B-BF07-44BCDF\99414580-712D-4DFC-8FBE-CD677E -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\C35BAD50-0A6D-43EE-86F9-B7BDDC\3BF26E16-67AD-4D7C-9F11-482E94 -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\C35BAD50-0A6D-43EE-86F9-B7BDDC\A39AFD32-307A-47C9-BCAC-B3A82B -> Adware.HotBar : Cleaned. C:\Program Files\Microsoft AntiSpyware\Quarantine\C35BAD50-0A6D-43EE-86F9-B7BDDC\B341F6BF-974A-4B2A-8A84-5EBA74 -> Adware.HotBar : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\Installer[1].exe -> Adware.Look2Me : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\mediaview[1].cab/amm06.ocx -> Adware.MediaMotor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\unstall[1].exe -> Adware.MediaMotor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\mmxsnet[1].exe -> Adware.MediaMotor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\pop06ap2[1].exe -> Adware.MediaMotor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\amm06[1].ocx -> Adware.MediaMotor : Cleaned. C:\WINDOWS\SET19.tmp -> Adware.MediaMotor : Cleaned. C:\WINDOWS\amm06.ocx -> Adware.MediaMotor : Cleaned. C:\WINDOWS\em.ocx -> Adware.MediaMotor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\MirarSetup_876075[1].exe -> Adware.SaveNow : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\bbqa[1].cab/cvn0.exe -> Adware.SearchAssistant : Cleaned. C:\WINDOWS\system32\fufudc.exe -> Adware.SearchAssistant : Cleaned. C:\WINDOWS\system32\ra8pv.exe -> Adware.SearchAssistant : Cleaned. C:\WINDOWS\system32fufudc.exe -> Adware.SearchAssistant : Cleaned. C:\WINDOWS\system32ra8pv.exe -> Adware.SearchAssistant : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\bbqa[1].cab/wfxqhv.exe -> Adware.Suggestor : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\bbqa[1].cab/zqskw.exe -> Adware.Suggestor : Cleaned. C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Cleaned. C:\WINDOWS\system32\kcnzrop6.exe -> Adware.Suggestor : Cleaned. HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned. HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned. HKU\S-1-5-21-1957994488-492894223-1202660629-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned. HKU\S-1-5-21-1957994488-492894223-1202660629-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008307.exe -> Adware.WebSearch : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008308.exe -> Adware.WebSearch : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008309.exe -> Adware.WebSearch : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008311.dll -> Adware.WebSearch : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008302.exe -> Adware.WinAD : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008304.dll -> Adware.WinAD : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008305.dll -> Adware.WinAD : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\drsmartload849a[1].exe -> Downloader.Adload.ee : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\drsmartload45a[1].exe -> Downloader.Adload.ee : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\drsmartload46a[1].exe -> Downloader.Adload.ee : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\drsmartload[1].exe -> Downloader.Adload.ef : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\loader[1].exe -> Downloader.Adload.ef : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\3138302D2D2D[1].exe -> Downloader.Adload.ej : Cleaned. C:\WINDOWS\system32\dmonwv.dll_tobedeleted -> Downloader.Agent.agw : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\fym9bvo[1].exe -> Downloader.Agent.ala : Cleaned. C:\fym9bvo.exe -> Downloader.Agent.ala : Cleaned. C:\topaff.exe -> Downloader.Agent.aqx : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008296.exe -> Downloader.Dyfuca.dp : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008298.exe -> Downloader.Dyfuca.dp : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008300.dll -> Downloader.Dyfuca.dt : Cleaned. C:\System Volume Information\_restore{EBE9A8D0-C42A-4D6C-AD7B-A6FF55B33730}\RP22\A0008297.exe -> Downloader.Dyfuca.dx : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\optimize[1].exe -> Downloader.Dyfuca.ey : Cleaned. C:\WINDOWS\srvdhwghnt.exe -> Downloader.Dyfuca.ey : Cleaned. C:\814.exe -> Downloader.Dyfuca.fb : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\drsmartload_js[1].htm -> Downloader.IstBar.j : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\installerwnus[1].exe -> Downloader.Qoologic.at : Cleaned. C:\installerwnusnewer.exe -> Downloader.Qoologic.at : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\GZ2CCKNV\rcverlib[1].exe -> Downloader.Qoologic.ax : Cleaned. C:\QooBox\budarf.exe.qoo -> Downloader.Qoologic.bj : Cleaned. C:\QooBox\cabhckl.exe.qoo -> Downloader.Qoologic.bj : Cleaned. C:\QooBox\gsrde.dat.qoo -> Downloader.Qoologic.bj : Cleaned. C:\QooBox\hcdajnw.dll.qoo -> Downloader.Qoologic.bj : Cleaned. C:\QooBox\reter.exe.qoo -> Downloader.Qoologic.bj : Cleaned. C:\QooBox\tdobx.exe.qoo -> Downloader.Qoologic.bj : Cleaned. C:\WINDOWS\pss\tdobx.exeCommon Startup -> Downloader.Qoologic.bj : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\ac3[1].txt -> Downloader.Small : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\al3[1].txt -> Downloader.Small : Cleaned. C:\WINDOWS\system32\w07bf372.dll_tobedeleted -> Downloader.Small : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\mtrslib2[1].js -> Downloader.Small.ag : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Cleaned. C:\VSL.dl_ -> Downloader.Small.ctp : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\ac3_0003[1].exe -> Downloader.Small.cyh : Cleaned. C:\ac3_0003.exe -> Downloader.Small.cyh : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\stub_113_4_0_4_0[1].exe -> Downloader.TSUpdate.o : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\nwnmff_11[1].exe -> Downloader.VB.aiy : Cleaned. C:\WINDOWS\oobljttA.exe -> Downloader.VB.alu : Cleaned. C:\WINDOWS\ms05077214041.exe -> Downloader.VB.tw : Cleaned. C:\WINDOWS\vSg21-d.exe -> Downloader.VB.tw : Cleaned. C:\803_104.exe -> Dropper.Mudrop.bq : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\803_104[1].exe -> Dropper.Mudrop.bq : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\SS1001[1].exe -> Dropper.Small.qn : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\popup[4].htm -> Hijacker.Agent.a : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\FVU42FMT\popup[1].htm -> Hijacker.Agent.a : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\IQQ519CY\popup[1].htm -> Hijacker.Agent.a : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\W3IBAUWS\popup[1].htm -> Hijacker.Agent.a : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\Z5KKXKLK\popup[1].htm -> Hijacker.Agent.a : Cleaned. C:\Documents and Settings\Anthony\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\pre[1].exe -> Hijacker.Small : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\v1201[1].exe -> Hijacker.Small : Cleaned. C:\WINDOWS\v1201.exe -> Hijacker.Small : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\wallpap[1].exe -> Hijacker.Small.jf : Cleaned. C:\Program Files\html1.htm -> Hijacker.Small.jf : Cleaned. C:\Program Files\html2.htm -> Hijacker.Small.jf : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\dfndrff_11[1].exe -> Hijacker.VB.ov : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\SystemDoctor2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned. C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@anheuserbusch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@mkt10.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@msnclassifieds.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@redcats.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@snagajob.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Adserver : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@bfast[1].txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@bluemountain[2].txt -> TrackingCookie.Bluemountain : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\NetworkService\Cookies\system@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@centrport[2].txt -> TrackingCookie.Centrport : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\LocalService\Cookies\system@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\NetworkService\Cookies\system@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned. C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned. C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned. C:\Documents and Settings\NetworkService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Hitslink : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Hitslink : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Realtracker : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@revenue[2].txt -> TrackingCookie.Revenue : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@spylog[1].txt -> TrackingCookie.Spylog : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\LocalService\Cookies\system@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Valueclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@valueclick[3].txt -> TrackingCookie.Valueclick : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][2].txt -> TrackingCookie.Wegcash : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@yadro[1].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Anthony\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Anthony\Cookies\anthony@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\system32\ewxcksr.exe -> Trojan.Runner.j : Cleaned. C:\WINDOWS\system32\ha3f.exe -> Trojan.Runner.j : Cleaned. C:\WINDOWS\system32ha3f.exe -> Trojan.Runner.j : Cleaned. ::Report end HJT log: Logfile of HijackThis v1.99.1 Scan saved at 6:53:10 PM, on 10/8/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\Hijackthis\HijackThis.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
Hi,


Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Danny
Thanks for all your help. Here is the scan log you requested. ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, October 08, 2006 10:57:50 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 9/10/2006 Kaspersky Anti-Virus database records: 230008 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ Scan Statistics: Total number of scanned objects: 51345 Number of viruses found: 31 Number of infected objects: 148 / 0 Number of suspicious objects: 65 Duration of the scan process: 01:33:46 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip/drsmartload46a9999a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC10.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip/drsmartload46a46g.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC11.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip/drsmartload46a46e.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC12.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip/drsmartload46a46c.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC13.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/drsmartload46a46b.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip/drsmartload46a3344a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip/drsmartload46a2002.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip/drsmartload45a9999a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC17.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip/drsmartload45a45g.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC18.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip/drsmartload45a45e.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC19.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/MTE3NDI6ODoxNg.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip/drsmartload45a45c.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC20.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip/drsmartload45a45b.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC21.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip/drsmartload45a3344a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC23.zip/drsmartload45a2002.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC23.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/drsmartload849a9999a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/drsmartload849a849g.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/drsmartload849a849e.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip/drsmartload849a849c.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC6.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/drsmartload849a849b.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip/drsmartload849a3344a.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC8.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/drsmartload849a2002.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver1.zip/MTE3NDI6ODoxNgnew.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver1.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos4.zip/stdrun2.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VcodecStarVideos4.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\Anthony\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Anthony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Anthony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Anthony\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\deskbar[1].exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\deskbar[1].exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\deskbar[1].exe NSIS: infected - 2 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\installer[1].exe/Stream/data0001 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\installer[1].exe/Stream/data0002 Infected: Trojan-Clicker.Win32.VB.fo skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\installer[1].exe/Stream Infected: Trojan-Clicker.Win32.VB.fo skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\installer[1].exe Inno: infected - 3 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\mta[1].htm Infected: Trojan-Clicker.JS.Linker.j skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\RDFX4[1].exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\RDFX4[1].exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\RDFX4[1].exe NSIS: infected - 2 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\tsinstall_4_0_4_0_b4[1].exe/WISE0009.BIN Infected: Trojan-Downloader.Win32.TSUpdate.n skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\tsinstall_4_0_4_0_b4[1].exe/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\tsinstall_4_0_4_0_b4[1].exe/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\tsinstall_4_0_4_0_b4[1].exe/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.f skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\tsinstall_4_0_4_0_b4[1].exe WiseSFX: infected - 4 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\2FHN820W\whCC-GIANT[1].exe RarSFX: infected - 5 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\Setup100[1].exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\Setup100[1].exe/data0005 Infected: Trojan.Win32.VB.tg skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\Setup100[1].exe/data0006 Infected: Trojan.Win32.VB.tg skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\E62M027Q\Setup100[1].exe NSIS: infected - 3 skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\EF976HEW\mma[1].htm Infected: Trojan-Clicker.JS.Linker.n skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\Eim03[1].exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.cc skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\Eim03[1].exe/stream Infected: not-a-virus:AdWare.Win32.EZula.cc skipped C:\Documents and Settings\Anthony\Local Settings\Temporary Internet Files\Content.IE5\NCDPFL0L\Eim03[1].exe NSIS: infected - 2 skipped C:\Documents and Settings\Anthony\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Anthony\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Norton AntiVirus\Quarantine\003A7960 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\00651B31/[From [removed]][Date Wed, 1 Sep 2004 10:25:29 -0400]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\00651B31/[From [removed]][Date Wed, 1 Sep 2004 10:25:29 -0400]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\00651B31 Mail: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\00651B31 CryptFF: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\02995618 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\02A00C07 Infected: Exploit.HTML.Mht skipped C:\Program Files\Norton AntiVirus\Quarantine\03AB1CEA Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\03DF3CB1/[From [removed]][Date Wed, 9 Feb 2005 12:54:29 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\03DF3CB1/[From [removed]][Date Wed, 9 Feb 2005 12:54:29 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\03DF3CB1 Mail: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\03DF3CB1 CryptFF: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\05511B3F Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\05C358C1 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\07B01CA2 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\07F50E57 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\08EC283E Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\08F7033B Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\09F64E23 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0A163033/message.html .com Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\0A163033 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\0A163033 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\0A4D5EB9 Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\0A982467 Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\0B0A61E9/letter.zip/letter.htm .scr Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\0B0A61E9/letter.zip Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\0B0A61E9 ZIP: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\0B0A61E9 CryptFF: infected - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\0B94225A Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0BAA6B39 Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\0EAE7CF1 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0ED24ACA Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0EF36EA6 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0F1D1077 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0F37605A Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0F757E16 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\0F9621F2 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\10BD6651.htm Infected: Trojan.JS.Seeker skipped C:\Program Files\Norton AntiVirus\Quarantine\11457FF9/document.txt .exe Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\11457FF9 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\11457FF9 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\11803BD7 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\11B45B9D Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\11FC774E Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\12164732 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\12A61EBE Infected: Email-Worm.Win32.Bagle.gen skipped C:\Program Files\Norton AntiVirus\Quarantine\130E3E20 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\14C045D1/details.txt .pif Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\14C045D1 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\14C045D1 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\169B181C Infected: Email-Worm.Win32.NetSky.d skipped C:\Program Files\Norton AntiVirus\Quarantine\18E26945 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\192430FD/[From [removed]][Date Fri, 11 Feb 2005 11:19:19 -0500]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\192430FD/[From [removed]][Date Fri, 11 Feb 2005 11:19:19 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\192430FD Mail: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\192430FD CryptFF: suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\19B458B0 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\19DB48D0 Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\1A301428 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\1D3963F4 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\1D9B4586 Infected: Trojan-Dropper.VBS.Zerolin skipped C:\Program Files\Norton AntiVirus\Quarantine\2AEC5323 Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\2B330EC0 Infected: Email-Worm.Win32.Bagle.i skipped C:\Program Files\Norton AntiVirus\Quarantine\39191004 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\3C0B4CDF Infected: Email-Worm.Win32.Bagle.ai skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F/[From nci244-00-50-ba-57-d4-d8.theedge.ca [207.189.244.123]][Date Sun, 9 May 2004 23:22:00 -0400 (EDT)]/UNNAMED/[From [removed]][Date Sun, 9 May 2004 21:18:57 -0600]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F/[From nci244-00-50-ba-57-d4-d8.theedge.ca [207.189.244.123]][Date Sun, 9 May 2004 23:22:00 -0400 (EDT)]/UNNAMED/[From [removed]][Date Sun, 9 May 2004 21:18:57 -0600]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F/[From nci244-00-50-ba-57-d4-d8.theedge.ca [207.189.244.123]][Date Sun, 9 May 2004 23:22:00 -0400 (EDT)]/UNNAMED/[From [removed]][Date Sun, 9 May 2004 21:18:57 -0600]/message.scr Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F/[From nci244-00-50-ba-57-d4-d8.theedge.ca [207.189.244.123]][Date Sun, 9 May 2004 23:22:00 -0400 (EDT)]/UNNAMED Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F Mail: infected - 2, suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\3E173F1F CryptFF: infected - 2, suspicious - 2 skipped C:\Program Files\Norton AntiVirus\Quarantine\401B28E7/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\401B28E7 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\401B28E7 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\455D1D16 Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\49060B9D Infected: Email-Worm.Win32.Zafi.b skipped C:\Program Files\Norton AntiVirus\Quarantine\4A85103A Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\4B226F8E Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\4B7A5D2D Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\4BA15502 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\4C2B537E Infected: Email-Worm.Win32.Bagle.ah skipped C:\Program Files\Norton AntiVirus\Quarantine\4C62022E Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\4E6C3921/[From "Taylor May" <[removed]>][Date Sat, 02 Oct 2004 06:02:04 -0400]/html Infected: Exploit.HTML.Iframe.FileDownload skipped C:\Program Files\Norton AntiVirus\Quarantine\4E6C3921 Mail: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\4E6C3921 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\50320BFB Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\510A5840 Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\51AA6190/TEXT.SCR Infected: Email-Worm.Win32.Mydoom.m skipped C:\Program Files\Norton AntiVirus\Quarantine\51AA6190 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\51AA6190 CryptFF: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\51EB3016 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\539E0038 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5B733399 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5B935776 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5BFF40FF Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5C230ED7 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5CD36A15 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5CED39F9 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\5EDA7DDA Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\618C18E4 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\61E7307F Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\620B7E58 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\6232762C Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\624C4610 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\629137C4 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\62B15BA0 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\64D0154C Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\64EA652F Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\652B2CE7 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\654F7AC0 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\667F3B71 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\66BA15EA/lxiepbuc.scr Suspicious: Password-protected-EXE skipped C:\Program Files\Norton AntiVirus\Quarantine\66BA15EA ZIP: suspicious - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\66BA15EA CryptFF: suspicious - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\68A67312 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\68BD18F9 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\6B8F57DF Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\6BFB4168 Infected: Email-Worm.Win32.Mimail.j skipped C:\Program Files\Norton AntiVirus\Quarantine\70306854 Infected: Email-Worm.Win32.NetSky.d skipped C:\Program Files\Norton AntiVirus\Quarantine\781B4D06 Infected: Email-Worm.Win32.NetSky.d skipped C:\Program Files\Norton AntiVirus\Quarantine\78A613DF Infected: Exploit.HTML.Mht skipped C:\Program Files\Norton AntiVirus\Quarantine\7FEC09B6/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q skipped C:\Program Files\Norton AntiVirus\Quarantine\7FEC09B6 ZIP: infected - 1 skipped C:\Program Files\Norton AntiVirus\Quarantine\7FEC09B6 CryptFF: infected - 1 skipped C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Setup100.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped C:\Setup100.exe/data0005 Infected: Trojan.Win32.VB.tg skipped C:\Setup100.exe/data0006 Infected: Trojan.Win32.VB.tg skipped C:\Setup100.exe NSIS: infected - 3 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\srvmfnedhw.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped C:\WINDOWS\srvmfnedhw.exe/data0005 Infected: Trojan.Win32.VB.tg skipped C:\WINDOWS\srvmfnedhw.exe/data0006 Infected: Trojan.Win32.VB.tg skipped C:\WINDOWS\srvmfnedhw.exe NSIS: infected - 3 skipped C:\WINDOWS\srvzprdepi.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped C:\WINDOWS\srvzprdepi.exe NSIS: infected - 1 skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\nse6.dll Infected: not-a-virus:AdWare.Win32.EZula.cc skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Hi,

First, locate and delete the following file:

C:\Setup100.exe
C:\WINDOWS\srvmfnedhw.exe
C:\WINDOWS\srvzprdepi.exe

Then please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Reboot, and post a new HijackThis log.

Danny
Here is the new HJT log.
Thanks
Ed Varner

Logfile of HijackThis v1.99.1
Scan saved at 4:28:56 PM, on 10/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
Hi,

How is your computer doing?

Your computer is now clean!

We have a couple of last steps to perform and then you're all set.

First, let's reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
  • CHECK the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Next, let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer.

3. Turn ON System Restore.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.

System Restore will now be active again.

After System Restore is turned back on, create a Restore Point:

Go to: 'Start > All Programs > Accessories > System Tools', and select System Restore.
In the System Restore Wizard, select: 'Create a restore point'.
Click: Next
Give a description to the new Restore Point. (Something like: Clean PC)
Click: Create

**To learn more about how to protect yourself while on the internet read this article by Tony Klein: So how did I get infected in the first place?

This article includes important ways of how to keep safe, and has links to programs that you should download to keep spyware free!

Some programs that I recommend:
  • Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows
  • CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
If you wish to submit a complaint about malware, please click on the following image:

[external image: Posted Image]

Danny :thumbup:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI