This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log - my girlfriend ruined my PC! :-/

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi folks!

First time poster, long time reader. This is the first time I post a HJT log anywhere, so I hope everything's correct.

Anyway, my girlfriend (although that was not what I was calling her earlier after finding out what she'd done!) was happily chatting away on MSN when she received a message from a friend that said something like "Hi! Is this you on the picture?", complete with a suspicious looking link. All I know is that she clicked the link and got a couple of DOS-files called "picture 549" or similar. She tried to open them, but without success of course.

So, after hearing about this I quickly ran both Ad-Aware and Spybot plus a few assorted programs trying to clean my poor PC. Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 00:40:46, on 2006-10-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\system32\iid.exe
C:\Program\Java\jre1.5.0_08\bin\jusched.exe
C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\Delade filer\{44C53BCC-0AE9-1053-0823-04040512002e}\Update.exe
C:\DOCUME~1\LINUST~1\APPLIC~1\SSTEM~1\svchost.exe
C:\Program\??mbols\m?dtc.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Miranda IM\miranda32.exe
C:\Program Files\PrintView\pvmodule.exe
C:\Program\foobar v0.9\foobar2000.exe
C:\Program\Last.fm\LastFM.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program\Deskbar\deskbar.dll
R3 - URLSearchHook: (no name) - {3B4D954F-2DF6-2002-D0AD-06B59CB3DDC6} - C:\WINDOWS\system32\cegzjbjb.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3B4D954F-2DF6-2002-D0AD-06B59CB3DDC6} - C:\WINDOWS\system32\cegzjbjb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program\Deskbar\deskbar.dll
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [IAAnotif] C:\Program\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Net iD] C:\WINDOWS\system32\iid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [H2O] C:\Program\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKCU\..\Run: [Oaph] "C:\DOCUME~1\LINUST~1\APPLIC~1\SSTEM~1\svchost.exe" -vt yazb
O4 - HKCU\..\Run: [Fawi] C:\Program\??mbols\m?dtc.exe
O4 - HKCU\..\Run: [shell] "C:\Program\Delade filer\Microsoft Shared\Web Folders\ibm00003.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Hello and Welcome to TomCoyote,

I do not see a firewall application. Do not rely solely on the Windows XP firewall.
I would recommend that you install another firewall application.
For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Let's find out if you have any malware disabled with selective start-up.
Go to Start >Run and type "Notepad" without the quotes
Copy/paste the following blue text into a new notepad (not wordpad) document. Make sure that wordwrap is unchecked.
Go to the menu at the top of the Notepad file and Save as:
  • Name the file mslook.bat
  • Save as Type: All files (not as a text document or it won't work)
  • Select the desktop icon on the left to save it on the desktop.
Locate mslook.bat on your Desktop and double-click it. When notepad opens, copy/paste the content in your reply. When you close Notepad the CMD window will close automatically and the text file will be deleted.

regedit /a /e %systemdrive%\regkey.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig"
notepad %systemdrive%\regkey.txt
del /q %systemdrive%\regkey.txt
Hi Susan! Thanks a lot for your help! Here's what I got after running the .bat file: REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services] "Ati HotKey Poller"=dword:00000002 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Documents and Settings^All Users^Start-meny^Program^Autostart^Microsoft Office.lnk] "path"="C:\\Documents and Settings\\All Users\\Start-meny\\Program\\Autostart\\Microsoft Office.lnk" "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\Program\\MICROS~3\\Office\\OSA9.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ATIPTA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="atiptaxx" "hkey"="HKLM" "command"="C:\\Program\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\CXMon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Hpi_Monitor" "hkey"="HKLM" "command"="\"C:\\Program\\Hewlett-Packard\\PhotoSmart\\Photo Imaging\\Hpi_Monitor.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\DAEMON Tools-1033] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program\\D-Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NeroCheck" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\NeroCheck.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\PCMService] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PCMService" "hkey"="HKLM" "command"="\"C:\\Program\\Dell\\Media Experience\\PCMService.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Share-to-Web Namespace Daemon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="hpgs2wnd" "hkey"="HKLM" "command"="C:\\Program\\Hewlett-Packard\\PhotoSmart\\HP Share-to-Web\\hpgs2wnd.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\UpdReg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="UpdReg" "hkey"="HKLM" "command"="C:\\WINDOWS\\UpdReg.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state] "system.ini"=dword:00000000 "win.ini"=dword:00000002 "bootini"=dword:00000000 "services"=dword:00000002 "startup"=dword:00000002 Any help would be most appreciated! PS. My girlfriend and I are now best friends again, in case anyone wondered… :-)
Hi humanoid boogie,

I am glad that you and your girlfriend are on good terms again.

You have some bad things on this computer. One that stands out is the following:
O4 - HKCU\..\Run: [shell] "C:\Program\Delade filer\Microsoft Shared\Web Folders\ibm00003.exe"
http://www.castlecops.com/s11220-Shell.html

It is showing the contemptible Trojan Torpig, which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs.

Please disconnect this PC from the Internet, and then go to a known clean computer and change any passwords or security information held on the infected computer. In particular, check whatever relates to online banking financial transactions, shopping, credit cards, or sensitive personal information. It is also wise to contact your financial institutions to apprise them of your situation.

We will do our best to clean the computer of any infections seen on the log. However, because of the nature of this Trojan, cannot offer a total guarantee that there are no remnants left in the system, or that the computer will be trustworthy.

Many security experts believe that once infected with this type of Trojan, the best course of action is to reformat and reinstall the Operating System. Making this decision is based on what the computer is used for, and what information can be accessed from it.

Knowing the above, let us know if you wish to proceed.

Additional information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall
Oh boy, this was even worse than I expected. I found a thread over at a Swedish site where someone had exactly the same problem (a message via MSN with a link to a dos file hidden as a jpeg). They suggested downloading a program called combofix (which I did) and it found lots of bad files (approx. 50 different viruses/trojans) that I ran through the VirusTotal website. Here are a few of them: Trojan-PSW.Win32.Sinowal.bg Win32/Anserin!generic TrojanDropper:Win32/Sinowal.gen TR/PSW.Sinowal.AY.2 BehavesLike:Trojan.Downloader TR/Dldr.Adload.FU.358 DollarRevenue unknown NewHeur_PE virus W32/Adload.FU!tr.dldr OScope.Downloader.VB W32/Mydoom.i@MM Trojan.Downloader.Tiny.BK Mal/Packer The viruses were found in the following files: 2006-10-23 21:24 157,696 –a—— C:\Documents and Settings\Linus T”rnqvist\two.exe 2006-10-22 22:23 53,835 –a—— C:\WINDOWS\SYSTEM32\image1.gif.exe 2006-10-22 22:23 50,251 –a—— C:\WINDOWS\SYSTEM32\taskdir~.exe 2006-10-22 22:23 50,251 –a—— C:\WINDOWS\SYSTEM32\adirss.exe 2006-10-22 22:12 131,072 –a—— C:\WINDOWS\SYSTEM32\cegzjbjb.dll 2006-10-22 21:52 76,800 –a—— C:\qvfgx.exe 2006-10-22 21:52 75,776 –a—— C:\pglln.exe 2006-10-22 21:52 20,480 –a—— C:\mc44a34.exe 2006-10-22 21:52 1,465 –a—— C:\glnp.exe I'll take your advice and disconnect this PC from the Internet, change all my passwords on a clean computer and check my credit cards, bank accounts, etc. Once again, thanks for all you help!
Hi (again)!

Pardon me, but I would like to get to the bottom with this (but will of course check my bank accounts, change passwords, and so on). Any chance you could guide me on what to do next? Here's a fresh HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 00:03:20, on 2006-10-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\system32\iid.exe
C:\Program\Java\jre1.5.0_08\bin\jusched.exe
C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [IAAnotif] C:\Program\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Net iD] C:\WINDOWS\system32\iid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Oaph] "C:\DOCUME~1\LINUST~1\APPLIC~1\SSTEM~1\svchost.exe" -vt yazb
O4 - HKCU\..\Run: [Fawi] C:\Program\??mbols\m?dtc.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
Hi humanoidboogie,

Do you have the information from the Combofix? I would like to see it if you do.

I was not sure what you wanted to do- whether to format and reinstall or try to clean this one.

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with HijackThis. Place a check against each of the following:
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKCU\..\Run: [Oaph] "C:\DOCUME~1\LINUST~1\APPLIC~1\SSTEM~1\svchost.exe" -vt yazb
O4 - HKCU\..\Run: [Fawi] C:\Program\??mbols\m?dtc.exe

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
If you have any questions please ask before deletion.
C:\DOCUME~1\LINUST~1\APPLIC~1\SSTEM~1\svchost.exe<=(Be sure folder starts with svchost.exe is in the folder starting SSTEM)
C:\Program\??mbols\m?dtc.exe<=file The ? can be any character

Did you delete this already? If not then do it.
C:\Documents and Settings\Linus T”rnqvist\two.exe<=file
C:\WINDOWS\SYSTEM32\image1.gif.exe <=file
C:\WINDOWS\SYSTEM32\taskdir~.exe <=file
C:\WINDOWS\SYSTEM32\adirss.exe <=file
C:\WINDOWS\SYSTEM32\cegzjbjb.dll <=file
C:\qvfgx.exe<=file
C:\pglln.exe<=file
C:\mc44a34.exe<=file
C:\ glnp.exe<=file

Exit Explorer, and reboot as normal afterwards.

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

If you are taken to the internet page, just close the page.

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Results from Spy Sweeper file, and Kapersky into this thread.
Hi again Susan!

Here are the logs you asked for. I forgot to save the one generated by Spy Sweeper, but it found and put the following viruses in quarantine:

trojan-backdoor-rustock
adperform
command

I can run it again if you need the complete log.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 24, 2006 4:51:31 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 24/10/2006
Kaspersky Anti-Virus database records: 220989
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
F:\

Scan Statistics:
Total number of scanned objects: 129316
Number of viruses found: 8
Number of infected objects: 17 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:17:44

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Dokument\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – 4 and 5 star rated.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Have not heard recently.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to late at night.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to on Weekdays.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to on Weekends.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – One Audio CD worth.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – One Data CD-R worth.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks – yet to be played.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks – yet to be rated.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\High bitrate media in my library.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Low bitrate media in my library.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks I dislike.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks I have not rated.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks with content protection.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Large.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Small.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\DMX_TempList.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{08115859-E625-4BCD-83A8-57E01873B42F}_Large.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{08115859-E625-4BCD-83A8-57E01873B42F}_Small.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Large.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Small.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\Beethovens nionde symfoni (Scherzo).wma Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\Folder.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\New Stories (Highway Blues).wma Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Folder.jpg Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.ASX Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.BMP Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.WMA Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sample Playlists\desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\01_Music_auto_rated_at_5_stars.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\02_Music_added_in_the_last_month.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\03_Music_rated_at_4_or_5_stars.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\04_Music_played_in_the_last_month.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\05_Pictures_taken_in_the_last_month.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\06_Pictures_rated_4_or_5_stars.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\07_TV_recorded_in_the_last_week.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\08_Video_rated_at_4_or_5_stars.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\09_Music_played_the_most.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\10_All_Music.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\11_All_Pictures.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\12_All_Video.wpl Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Mina bilder\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Dokument\Mina videoklipp\Desktop.ini Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Application Data\Webroot\Spy Sweeper\Logs\061024132512.ses Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Tidigare\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Tidigare\History.IE5\MSHist012006102420061025\index.dat Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\ntuser.dat Object is locked skipped
C:\Documents and Settings\Linus Törnqvist\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS00C91F50-E43F-4898-BD78-420EC731D41E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS00DECCED-EB31-4E0C-B42E-B918F3962E07.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS02C85A77-6B5D-413D-B361-524B9517B710.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS03FC35E5-9F79-4A74-8272-C0E32A849AB4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS08042991-42F2-4E86-AA23-FF2D535B7FC3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0F0FA5B5-4AD5-4B63-981B-8B5BBC151206.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0FE9C2C3-A709-4B3F-962B-8DFC1BF9BFBC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1271626C-C439-4A24-B310-E36DB1688B54.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1282814A-59C8-47AA-A255-A7C83AB57BB8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS128F6497-FCFF-4BF9-AB5B-BA9AE63C61B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS138CD367-16C9-41FB-AB84-2B82B3C3469E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS15B40224-15B7-4E59-B11A-A72875629E8F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS19582C1A-8255-431E-A470-EDCF47C6E2B7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS19741477-FB79-4027-ACDD-2B33C31D391F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS19E5A61E-A2D3-46D8-8162-D1A774A7E7B6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1C56D1A3-99E6-4368-A88F-8D49F15FAF1E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1DBE65AA-40AC-4FC9-9B28-EC9798C62CA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1FA45CDF-886A-4AB8-876A-21D2C1848802.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS245F8A5B-08F0-4F11-B3F7-D9B680B3EDDC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24784E53-FF1A-4DA4-9321-BD7B2C3AD2C3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS282A6539-A3DC-4D5E-A3A2-9F18A872443A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS286C73BE-75B3-47EF-9BAB-59A35EA8BFC0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A06B912-4C0F-417A-AE10-948975CBA71B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A6B8ECC-ADF1-4B7C-B071-0858597E11E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2E48AC02-8637-4779-9E93-45F3E57DB89D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3080EFA3-C06D-4F53-AB78-A2C641CA4647.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3193EC6F-151D-46E4-B7E3-17B5612A708F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3197A723-2FEF-4B02-9C76-6C77B28AD157.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS31FF95CB-C1F1-467B-94A2-9D5F8BE19DF1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS351C60E5-CC4E-49ED-AE04-96681F4AF0AA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3EDCF01F-A5E9-407D-819D-C173EDF5A49B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS45FD08D7-0FFE-42D7-AC5A-0BA120B18C06.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4746352D-0F59-4BCB-9EF7-AC7F13A64DF3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS47BDFBF1-F684-4246-BD7B-89EDD53EE998.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A595246-298B-40F0-93F5-75BE54CFD922.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A5F694C-D033-4ED7-99BB-996DA4BF00F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4BD9DEC0-E341-4F31-8077-4C1AA0879588.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D8DCE2F-49E1-4429-832F-591477CBE1B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4EF04F46-B356-4D91-B02A-7381B5578384.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS511AC54F-7C0E-4ECE-A39F-5FBC86A9E29C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS516074EF-FD9B-4F17-B265-F6B557242B68.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS520870AB-AF64-42BE-97EF-7A3C76AC777F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS57379055-6AB0-4D20-989C-5076A22FAC9D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS589A0932-C8BB-4521-84A3-07971989FC2E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5F3FB5DC-3A8C-41BB-96C4-DAB016938466.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5FD90C11-F787-4A2D-885B-06C99481190E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67F10693-12E2-4136-8901-CC69262DD704.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS695724AE-326C-44DE-AF86-358268ABE051.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6AAAD09F-8731-4C0A-BA1F-C20DA6D7CEC1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS729AA7D9-3F9C-4B6D-AFE4-49F5B5612FDD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS73FB03AA-9CF1-4F0F-ADB6-379B12EEF851.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7C1885EC-3866-4ED7-9294-C51A4E4C7427.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7D6B91F7-82D1-4EAD-8544-4DDF986D062E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E79D8DC-7068-43DB-B60E-16C201553D33.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80D0A76F-F2A8-4F46-84D8-B62A9F80E703.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS86C92721-8BBC-4907-A5CC-44DFA5F7414C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8A6A8E4A-87C7-40BF-9B24-48E4A4FA9138.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C080FF6-E396-43D7-8262-C6A6F25989DA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8D364DDB-171C-4FEB-9149-B2BCADFD2EC5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8DC926E3-C029-4EE4-8EE9-EE81526F1BD8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8ED77475-2C12-4056-A634-7BEB86DAFAA3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9250716C-433A-4F8B-8B64-FEF62E342EC1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS92699EF5-9281-4E39-AA58-C6ED4AC9424B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS973D03BF-D350-44AF-83E1-699302F355A9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS99C3AC26-179A-4EC1-A648-2C9BB4559E9E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA2F9DA1E-4A98-45A4-BBAC-739D7D3E16F0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA51D2978-2BD1-4030-ABD4-BC2696FEE1AE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA58EC3A5-E763-47DE-923B-9544667F107F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAA269389-2640-485F-8A19-00EE0940CC95.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAA5AE685-4A81-46D5-86BC-9981D58AB9EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAC6CBC39-149E-4D68-B0A9-45EAA19C5DBE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB01F19A3-46EB-4C8E-BFD7-BC705706C42C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB2D133B2-A8F0-4BFE-A91C-56DB6801619E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB6D40D24-3EE7-45ED-9FAE-D8A805E18D83.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB7C9467A-D15C-4CFB-8502-F0F462EA8FFD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBB31A099-1B97-4933-BE1D-D99D295B8343.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBBD56B64-51F1-42C3-9E3F-61BFD875F407.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBC212E2B-C4AC-40D5-A1C7-1263922564E8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBD8174F5-0156-42F3-8E8B-3A0C0F56A20A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC044AA9E-ED7C-4C63-922A-F3398ABC9F36.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC2235BBF-763C-438E-84CF-925BEB68A5FD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC271072C-FDB0-4A04-AF9D-2000C35FDF9F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC423BB21-1DEC-45DC-90AC-166FCF926493.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5EAB538-BBB9-4E0C-88FA-7EC13DEA9271.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC926C4D0-40E8-4649-A29A-E18DA4201E55.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC9979CD4-0745-40E6-B16A-5D654FA71358.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB73E5F2-B194-4006-B4A0-A67C63206726.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD0436B37-D0E1-41F1-8ED9-B480DE7C87BC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD18ED27A-FC72-47EF-8B14-B7DD2C8C0D6B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD64E9969-36DE-4A5D-80A7-01DFCBE2148B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD98FC8F7-8E68-4F4D-827C-5AE39C06ABB6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD9AA1AAA-9F23-467E-AA4E-C8E51703BE4C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDB1EAA14-5A87-43C9-9092-00967680E0B3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDB4B84AD-B117-415B-9FC1-E2A2D69D6659.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDBEA5249-4617-4EA4-A940-3339F040FC2A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDCDFD1C7-FC98-40F5-9FFA-D1347DEF0DBC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDE06CE1B-43DF-43F5-8115-45485335A5F8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE14B9557-07BE-4B37-986D-38F4AB1DAC59.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE28CB236-DFFE-40FE-8C57-A959E1B6A147.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE6D752D0-2CCE-4E99-A329-62B4BD49A5EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE9719EAC-C134-4CA6-AC52-AF9191CD1FD1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEE0707A9-64E0-4435-B40C-9E8E8D354C8C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEF054D80-820D-4C17-947C-8F3F732FFFE8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEF3CA7A4-FEA7-4B8E-89BD-DB41D72802B3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF0C8CB67-5C8C-4511-B6EC-9246778C2C70.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF124FEFC-72F8-4798-84A9-05F09B8D7103.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF7296DD1-038E-406C-82A3-4CD85A981BA9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD79EFAA-B506-4BAA-8288-60D539C14B0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFEAADA6B-0AC6-4F0A-A09E-9727736525BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Lokala inställningar\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokala inställningar\Tidigare\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program\Mozilla Firefox\drv.exe Infected: Trojan-Downloader.Win32.Adload.hd skipped
C:\Program\Mozilla Firefox\loadadv455.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\debug.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\debug.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\error.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\error.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\hips.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\hips.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\ids.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\ids.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\network.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\network.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\system.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\system.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\warning.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\warning.log.idx Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\web.log Object is locked skipped
C:\Program\Sunbelt Software\Personal Firewall 4\logs\web.log.idx Object is locked skipped
C:\Program\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP559\A0129666.exe Infected: Trojan-Downloader.Win32.VB.afl skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP559\A0129667.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0129727.exe Infected: Trojan-PSW.Win32.Sinowal.bg skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130719.exe Infected: Trojan-Downloader.Win32.Adload.hd skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130752.exe Infected: Trojan-PSW.Win32.Sinowal.bg skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130756.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130757.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130758.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130764.exe Infected: Trojan-Dropper.Win32.PurityScan.ah skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130765.dll Infected: Trojan-PSW.Win32.Sinowal.bg skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130768.exe Infected: Backdoor.Win32.MSNMaker.w skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130769.exe Infected: Trojan-Downloader.Win32.PurityScan.dr skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130770.exe/data0002 Infected: Trojan-Downloader.Win32.IstBar.er skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130770.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP561\A0130848.dll Infected: Trojan-PSW.Win32.Sinowal.bg skipped
C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP561\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{5968758E-28F0-4815-B1F5-30358C29AB9B}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000004-00000000-00000001-00001102-00000004-10031102}.CDF Object is locked skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 16:58:49, on 2006-10-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\iid.exe
C:\Program\Java\jre1.5.0_08\bin\jusched.exe
C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/se/sve/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] "C:\Program\Intel\Intel Application Accelerator\iaanotif.exe"
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Net iD] C:\WINDOWS\system32\iid.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] "C:\Program\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe"
O4 - HKLM\..\Run: [CTDVDDet] C:\Program\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] "REGSVR32.EXE" /S CTASIO.DLL
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "C:\Program\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program\Delade filer\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.5.0_08\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program\Delade filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program\Webroot\Spy Sweeper\SpySweeper.exe
Hi humanoid,

It is looking much better. You have a couple of file that we need to fix. We do not fix infected _restore files until other infected files deleted/cleaned in case the rare catastrophe occurs and we need to restore the system to a previous restore point (infected then is better than none). So let's get rid of those two first.
C:\Program\Mozilla Firefox\drv.exe Infected: Trojan-Downloader.Win32.Adload.hd skipped
C:\Program\Mozilla Firefox\loadadv455.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped

Uninstall Firefox using the Add/Remove Programs
Delete the C:\Program\Mozilla Firefox<=folder
Empty your recycle bin,
Reboot and then download and install Firefox again.

Then go ahead and run Kapersky again to double-check that the infected Mozilla Firefox files are gone. Please post the results.
Hi again Susan! Here's a fresh Kaspersky log, generated after removing Firefox and the infected files you told me to throw away: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Wednesday, October 25, 2006 9:10:36 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 25/10/2006 Kaspersky Anti-Virus database records: 221210 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ F:\ Scan Statistics: Total number of scanned objects: 130771 Number of viruses found: 6 Number of infected objects: 12 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:17:59 Infected Object Name / Virus Name / Last Action C:\bt\Wings - 1973-05-17 - Manchester\wings09.flac Object is locked skipped C:\bt\Wings - 1973-05-17 - Manchester\wings10.flac Object is locked skipped C:\Documents and Settings\All Users\Dokument\DESKTOP.INI Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – 4 and 5 star rated.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Have not heard recently.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to late at night.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to on Weekdays.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – Listen to on Weekends.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – One Audio CD worth.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Favorites – One Data CD-R worth.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks – yet to be played.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks – yet to be rated.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Fresh tracks.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\High bitrate media in my library.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Low bitrate media in my library.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks I dislike.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks I have not rated.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\001DFB3B\Music tracks with content protection.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\DMX_TempList.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArtSmall.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{08115859-E625-4BCD-83A8-57E01873B42F}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{08115859-E625-4BCD-83A8-57E01873B42F}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Large.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\AlbumArt_{EFFDEB51-C913-4EE1-8B2A-C80112057955}_Small.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\Beethovens nionde symfoni (Scherzo).wma Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\DESKTOP.INI Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Exempelmusik\New Stories (Highway Blues).wma Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Folder.jpg Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.ASX Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.BMP Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\MUSIC.WMA Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sample Playlists\desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\01_Music_auto_rated_at_5_stars.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\02_Music_added_in_the_last_month.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\03_Music_rated_at_4_or_5_stars.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\04_Music_played_in_the_last_month.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\05_Pictures_taken_in_the_last_month.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\06_Pictures_rated_4_or_5_stars.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\07_TV_recorded_in_the_last_week.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\08_Video_rated_at_4_or_5_stars.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\09_Music_played_the_most.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\10_All_Music.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\11_All_Pictures.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\03F42D5E\12_All_Video.wpl Object is locked skipped C:\Documents and Settings\All Users\Dokument\Min musik\Sync Playlists\desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Dokument\Mina bilder\Desktop.ini Object is locked skipped C:\Documents and Settings\All Users\Dokument\Mina videoklipp\Desktop.ini Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\container.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\httpinput.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\metadata.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\playback.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\transcode.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Last.fm\Client\webservice.log Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Tidigare\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\Linus Törnqvist\Lokala inställningar\Tidigare\History.IE5\MSHist012006102520061026\index.dat Object is locked skipped C:\Documents and Settings\Linus Törnqvist\ntuser.dat Object is locked skipped C:\Documents and Settings\Linus Törnqvist\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Linus Törnqvist\UserData\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Lokala inställningar\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Lokala inställningar\Tidigare\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Lokala inställningar\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped C:\Program\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program\Alwil Software\Avast4\DATA\report\Resident skydd.txt Object is locked skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP559\A0129666.exe Infected: Trojan-Downloader.Win32.VB.afl skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP559\A0129667.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130716.exe Infected: IM-Worm.Win32.Licat.e skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130719.exe Infected: Trojan-Downloader.Win32.Adload.hd skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130756.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130757.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130758.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130764.exe Infected: Trojan-Dropper.Win32.PurityScan.ah skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130770.exe/data0002 Infected: Trojan-Downloader.Win32.IstBar.er skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP560\A0130770.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP562\A0131099.exe Infected: Trojan-Downloader.Win32.Adload.hd skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP562\A0131101.exe Infected: Trojan-Downloader.Win32.Tibs.ir skipped C:\System Volume Information\_restore{B19406CB-15FE-4643-899E-BE44508A1787}\RP562\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\LINUS.ldb Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{02C30802-C547-4994-8520-5C1661227FF4}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\Antiviru.evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_6bc.dat Object is locked skipped C:\WINDOWS\Temp\ZLT027f4.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT027fb.TMP Object is locked skipped C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\WINDOWS\{00000004-00000000-00000001-00001102-00000004-10031102}.CDF Object is locked skipped Scan process completed. PS. Can a FLAC file really be infected? :scratch:

Can a FLAC file really be infected?


I had to look up FLAC. I am not music savvy. But I would not want to say no it cannot. You would need to ask someone with more expertise. But the Kapersky scan did scan those files, so evidently the designers of Kapersky intended that.

Your system appears to be clean, however I cannot give guarantees. Bad thing with some infections is that system is changed and after infections are removed, the system still may be compromised.

Be sure and have an anti-virus application. The AVG is a complement to an anti-virus applications. There is a tutorial listed below. You did install a firewall which was very important.


This will clear those infected _restore files.
System Restore for Windows XP
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.

STEP 1.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.


    See this link for a listing of some online & their stand-alone antivirus programs:
    Virus, Spyware, and Malware Protection and Removal Resources

  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware


    Updating Java
    • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
    • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement".
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Hi again Susan! I can't thank you enough for helping me out (and completely for FREE as well - amazing!). If you ever visit Scandinavia, consider yourself my guest of honour. Massive thanks once again! :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI