This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tried to fix it myself

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I posted like a month ago requesting help and then was shunned because i was getting free advice while working on a clients computer. I signed up for the classroom with no success…. with that said…….This time its my computer. I got a file from a friend that supposedly was safe….i got slamed……hes a JERK!!!! anyways, ive ran spybot, adaware, antivirus, in normal and safe mode, no success. Then searched the forums and ran atf cleaner and avg anti spyware in safe mode……i still have winantivirus or what ever popping up….i also renamed HJT to seekyou and NOW i can save a log :)…….another symptom i get is ill get kicked to desktop playing my games (minimizes counter-strike)…..also while typeing this it kicks my curser out so i cant type……heres my HJT log and AVG antispyware log….THANKS IN ADVANCE FOR ANY HELP!!! :-D

PS. i also just reformated so i hope i didnt waste all that time reinstalling everything!!! :(

Logfile of HijackThis v1.99.0
Scan saved at 12:03:22 AM, on 10/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Razer\razertra.exe
C:\Program Files\Razer\razerofa.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan\Desktop\hijackthis\seekyou.exe

O2 - BHO: (no name) - {379CD67B-2C04-4E38-8559-98D66E669A62} - C:\WINDOWS\system32\ddcyx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:32:31 AM 10/9/2006

+ Scan result:



C:\Program Files\Safety Bar -> Adware.Generic : Cleaned.
C:\Program Files\Safety Bar\SafetyBar.dll -> Adware.Generic : Cleaned.
C:\Program Files\Safety Bar\Uninstall.bat -> Adware.Generic : Cleaned.
:mozilla.218:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.219:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.221:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.222:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.223:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.224:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.225:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.227:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.228:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.230:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.231:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.232:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.337:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.351:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.119:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.120:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.121:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.133:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.243:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.193:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.194:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.195:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.34:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.35:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.45:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.46:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.47:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.48:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.481:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.482:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.244:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.245:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.40:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.41:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.42:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.43:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.44:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.78:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.527:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.175:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.176:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.70:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.72:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.74:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.272:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.273:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.267:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.94:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.150:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.151:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.152:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.153:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.154:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.155:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.156:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.100:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.101:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.102:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.98:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.99:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.147:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.148:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.149:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.161:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.501:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.502:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.503:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.496:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.158:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.506:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.507:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.508:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.509:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.366:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.367:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.93:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.95:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.96:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.97:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.375:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.376:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.377:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.378:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.379:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.18:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.19:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.20:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.21:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.22:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.23:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.24:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.25:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.118:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.51:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.52:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.53:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.410:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.411:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.412:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.413:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.414:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.239:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.240:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.241:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.242:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.300:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.301:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.302:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.511:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.435:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.439:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.440:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.442:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.443:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.444:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.445:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.446:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.447:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.448:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.449:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.450:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.177:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.178:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.179:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.180:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.401:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.402:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.403:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.404:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.405:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.473:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.474:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.62:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.63:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.64:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.65:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.66:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.67:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.164:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.165:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.166:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.167:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.168:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Thanks, heres what i got after 2 reboots, this was also the first time in a while during a reboot that my antivirus didnt find iSearch and torjan…..


VundoFix V6.2.1

Checking Java version…

Sun Java not detected
Scan started at 1:34:36 PM 10/11/2006

Listing files found while scanning….

C:\WINDOWS\system32\gzrvwej.dll
C:\WINDOWS\system32\ilvumgd.dll
C:\WINDOWS\system32\ddcyx.dll
C:\WINDOWS\system32\xycdd.ini
C:\WINDOWS\system32\xycdd.bak1
C:\WINDOWS\system32\xycdd.ini2
C:\WINDOWS\system32\xycdd.tmp

Beginning removal…

Attempting to delete C:\WINDOWS\system32\gzrvwej.dll
C:\WINDOWS\system32\gzrvwej.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ilvumgd.dll
C:\WINDOWS\system32\ilvumgd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddcyx.dll
C:\WINDOWS\system32\ddcyx.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xycdd.ini
C:\WINDOWS\system32\xycdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xycdd.bak1
C:\WINDOWS\system32\xycdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\xycdd.ini2
C:\WINDOWS\system32\xycdd.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\xycdd.tmp
C:\WINDOWS\system32\xycdd.tmp Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcyx.dll
C:\WINDOWS\system32\ddcyx.dll Has been deleted!

Performing Repairs to the registry.
Done!



Logfile of HijackThis v1.99.0
Scan saved at 1:42:35 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Razer\razertra.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ryan\Desktop\hijackthis\seekyou.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll (file missing)
O2 - BHO: (no name) - {76ADA441-870A-4874-82D6-E0B7ADDA6256} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Logfile of HijackThis v1.99.1
Scan saved at 1:50:45 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Razer\razertra.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\IceChat5\IceChat5.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis(2).exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll (file missing)
O2 - BHO: (no name) - {76ADA441-870A-4874-82D6-E0B7ADDA6256} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
SmitFraudFix v2.109 Scan done at 14:00:15.28, Wed 10/11/2006 Run from C:\Documents and Settings\Ryan\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ot.ico FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ryan »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Ryan\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Ryan\FAVORI~1 C:\DOCUME~1\Ryan\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.
SmitFraudFix v2.109 Scan done at 14:06:45.37, Wed 10/11/2006 Run from C:\Documents and Settings\Ryan\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\ot.ico Deleted C:\DOCUME~1\Ryan\FAVORI~1\Antivirus Test Online.url Deleted C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
Logfile of HijackThis v1.99.1
Scan saved at 2:12:38 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Razer\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\IceChat5\IceChat5.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis(2).exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll (file missing)
O2 - BHO: (no name) - {76ADA441-870A-4874-82D6-E0B7ADDA6256} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Incident Status Location

Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.com.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[www.winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[www.winantivirus.com/pages/scanner/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.advertising.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.drivecleaner.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[.tucows.com/]
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\hipv9zsa.default\cookies.txt[drivecleaner.com/.freeware/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Ryan\Desktop\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Ryan\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Possible Virus. Not disinfected C:\WINDOWS\system32\gebyvss.dll
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\ixt0.dll_tobedeleted


Logfile of HijackThis v1.99.1
Scan saved at 2:58:34 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Razer\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\IceChat5\IceChat5.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis(2).exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll (file missing)
O2 - BHO: (no name) - {76ADA441-870A-4874-82D6-E0B7ADDA6256} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Open Hijackthis and click scan. Then check mark the following entries

O2 - BHO: (no name) - {56843EA2-6312-4D25-49E5-0AD192198A28} - C:\WINDOWS\system32\gzrvwej.dll (file missing)
O2 - BHO: (no name) - {76ADA441-870A-4874-82D6-E0B7ADDA6256} - C:\WINDOWS\system32\ddcyx.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)

Now close all open windows except Hijackthis and click fix checked

Delete the files.

C:\WINDOWS\system32\gebyvss.dll
C:\WINDOWS\system32\ixt0.dll_tobedeleted

Then post a new Hijackthis log here in a reply.
couldnt find the file C:\WINDOWS\system32\gebyvss.dll the other was there and deleted

Logfile of HijackThis v1.99.1
Scan saved at 3:09:27 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Razer\razerhid.exe
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Razer\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Razer\razerofa.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ryan\Desktop\HijackThis(2).exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159403433656
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Your log is clean.

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
    I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definatley a must have. Three good free versions are Kerio, Sygate and ZoneLabs.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI