This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cydoor & eZula.Earn Remover

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Windows Defender detected Cydoor and eZula.Earn and cannot remove them. I ran Spybot, Ad-Aware, Spywareblaster and SpywareGuard. Please review my hijack log, any help would be most appreciated. Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 6:24:52 PM, on 11/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\SYSTEM32\IoctlSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\hphmon03.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Icons\SetIcon.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\ATRACK.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\My Documents\My Download Files\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cox.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Cox High Speed Internet
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ADATA_PLUtil] C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\system32\HotfixQ0306270.exe
O4 - HKLM\..\Run: [SetIcon] C:\Program Files\Icons\SetIcon.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\hpis\bin\matcli.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1102938931529
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/sj/…/qdiagh.cab?326
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec Client Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
O23 - Service: Symantec Client Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\SYSTEM32\IoctlSvc.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Client Firewall Proxy Service (SymPxSvc) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0. Taken from the Ewido website:

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to know how to boot into Safe Mode.
Instructions can be found here.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.

2) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

3) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

4) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

5) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

6) Boot into Normal Mode.

Post a new HJT log (run in Normal Mode), the AVG A-S log AND a description of how your PC is running.

Also, run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Windows Defender still detects and cannot remove the Cydoor and eZula.Earn. Here are my logs:

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 5:17:25 PM 11/24/2006

+ Scan result:



C:\WINDOWS\SYSTEM\SBUtils\SBWebCtl.dll -> Adware.WindowEnhancer : Cleaned with backup (quarantined).
C:\Documents and Settings\Shalise\Local Settings\Temporary Internet Files\Content.IE5\FPPW8ZI3\zpopup[2].cgi -> Not-A-Virus.Exploit.HTML.UrlSpoof.a : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.176:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Shannon Ray\Application Data\Mozilla\Firefox\Profiles\gl23ske6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.50:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu ray@americanexpress.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu ray@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu ray@iqtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu ray@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@anheuserbusch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@wpni.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shannon Ray\Cookies\shannon ray@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@66.220.17[1].txt -> TrackingCookie.66.220.17.154 : Cleaned.
:mozilla.90:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.91:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.495:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.358:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.163:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.164:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.165:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.166:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.89:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.180:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.181:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Shannon Ray\Cookies\shannon_ray@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.702:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.449:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.450:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu [removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@paycounter[1].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.58:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.59:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.60:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.61:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.530:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.531:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.532:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.533:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Shannon Ray\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.488:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.489:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.513:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.514:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.515:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.516:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.517:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.327:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.274:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.275:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.563:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
:mozilla.539:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.540:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu ray@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.555:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficcenter : Cleaned.
:mozilla.556:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficcenter : Cleaned.
:mozilla.557:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficcenter : Cleaned.
:mozilla.558:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficcenter : Cleaned.
:mozilla.559:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficcenter : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@trafficcenter[1].txt -> TrackingCookie.Trafficcenter : Cleaned.
:mozilla.560:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.561:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.479:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.480:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.481:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.482:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.483:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][2].txt -> TrackingCookie.Wegcash : Cleaned.
:mozilla.767:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.771:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.82:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.83:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.84:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.85:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.86:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.87:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Lu Ray\Cookies\lu [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shalise\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.776:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.777:C:\Documents and Settings\Shalise\Application Data\Mozilla\Firefox\Profiles\9rm0p4xv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Shalise\Cookies\shalise@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 8:22:33 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\SYSTEM32\IoctlSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\hphmon03.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Icons\SetIcon.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\ATRACK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Shannon Ray\My Documents\My Download Files\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cox.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Cox High Speed Internet
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ADATA_PLUtil] C:\Program Files\A-DATA\USB Flash Disk Utility\PLBkMon.exe
O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\system32\HotfixQ0306270.exe
O4 - HKLM\..\Run: [SetIcon] C:\Program Files\Icons\SetIcon.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [iamapp] C:\PROGRA~1\SYMANT~1\SYMANT~2\IAMAPP.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [StrgSync.exe] C:\Program Files\StorageSync\StrgSync.exe -w
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp instant support.lnk = C:\Program Files\Hewlett-Packard\hpis\bin\matcli.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1102938931529
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/sj/…/qdiagh.cab?326
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec Client Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISSERV.EXE
O23 - Service: Symantec Client Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\NISUM.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\SYSTEM32\IoctlSvc.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Client Firewall Proxy Service (SymPxSvc) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec Client Firewall\SymPxSvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe


Adaptec UDF Reader
Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0.7
Amazing Windows XP Screen Saver 1.2
Anark Client 1.0
Apple Software Update
ArcSoft Panorama Maker 3
AVG Anti-Spyware 7.5
Belkin F5U248 Driver and Icon
Broadcom 802.11 Control Panel
Broadcom 802.11 Driver
BroadJump Client Foundation
ClueFinders Math Adventures
ClueFinders Mystery Mansion Arcade
Diablo
Disney's Toontown Online
DivX
DivX 5.0.2 Pro Bundle
DivX Player
Easy CD Creator 5 Platinum
eHelp
Ezonics Greeting Cam Deluxe
EZPhoto Browser
EZPhoto Tools
EZShowtime MMS
EZSuite For EZCam III
EZVideo Mail 2.0
FA Multiplication Division
Family Tree Maker 8.0
Final Fantasy XI Theme Installer
Frogger v3.0e
Gizmos and Gadgets!™
Greeting Card Creator 32
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
Hotfix for Windows XP (KB915865)
Hoyle Board Games 3
Hoyle Casino 4
Hoyle Word Games
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
hp instant support
HP Internet Center
HP Memories Disc
HP Photo and Imaging 2.3 - Scanjet 4600 Series
HP Photo Imaging Software
HP Photo Printing Software
HP Photosmart Premier Software 6.5
hp photosmart printer series (Remove only)
HP Scanjet 4800 series 7.0
HP Share-to-Web
HP Software Update
HP Solution Center 7.0
HP_WildTangent_Games
HyperLoad
ICM532
ICS Viewer 6.0
InterVideo WinDVD
iTunes
Java 2 Runtime Environment Standard Edition v1.3.1
JumpStart Spanish v1.0
K@zoo USB Setup
Kazoo USB
LiveUpdate 1.80 (Symantec Corporation)
LogViewer
Macromedia Flash Player 8
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft Office Professional Edition 2003
Monopoly Tycoon v1.3 Patch
Mozilla Firefox (1.5)
MSN Messenger 7.5
MSN Money Investment Toolbox
MSN Money Investment Toolbox Beta
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MUSICMATCH Jukebox
My Photo Center
OCR Software by I.R.I.S 7.0
OLYMPUS CAMEDIA Master 2.5
One-touch Multimedia Keyboard
PC-Doctor for Windows
Personalized Learning Center
PhotoSmart Printer Software
QuickLink III
QuickTime
QuickTime for Windows (32-bit)
Readiris Pro 8
Rio Internet Update
Rio Internet Update
Rio Music Manager
Rio Music Manager
Rio Taxi
Roxio VideoPack 5.0
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Shockwave
Spybot - Search & Destroy 1.4
SpywareBlaster v3.5.1
SpywareGuard v2.2
StorageSync Backup Software
Symantec AntiVirus Client
Symantec Client Firewall
Talk to Me
The ClueFinders® Reading Adventures Ages 9-12
The Game Of Life
Timbuktu Pro
TWAIN Data Source for hp Scanjet Scanner
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
USB Flash Disk Utility
Wacky Races
Windows Defender
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Connect
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows Media Tools 4.1
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Windows XP Uninstall
WinPatrol
Yahoo! Messenger
ZiO SmartMedia Adapter Ver 3.17

Windows Defender still detects and cannot remove the Cydoor and eZula.Earn.

Can you let me have a list of the files, including filepaths, that are being detected.
Cydoor C:\undo\backup.cab->\Device\Harddisk0\Partition1\WINDOWS\Installer\506e17.msi->(MSI Stream 6) eZula.Earn C:\undo\backup.cab->\Device\Harddisk0\Partition1\WINDOWS\Installer\506e17.msi->(MSI Stream 28)
Please go to Jotti's and click on the Browse… button at the top and navigate to the following file and then click on Submit:

C:\undo\backup.cab

When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button at the top, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*

Have you upgraded the Operating System or has it always been XP?
I've tried the Jotti Scan and the VirusTotal scans and they will not run/complete. My symantec firewall say that I am being attacked. It does not run when I disable the firewall either. I'm not sure what to do next. Thanks.
The file that is being flagged is one that enables you to go back to Windows ME - hence undo in the filepath. Your OS was probably infected when you upgraded and that's why it comes up as being nasty. The file doesn't pose any risk to your PC, so you can leave it where it is and instruct your scanners to ignore it, or you can delete it - it depends on whether you want to go back to ME or not.

As it's probably a hidden file, you will need to unhide it to play with it:

If you go to Start > Run, enter cmd and click OK, this will open a Command Window.
Copy and paste the following into it and hit :

attrib -r -s -h C:\undo\backup.cab

This should make the file visible if you want to remove it. That's all you want the Command Window for, so you can close it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI