This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Web browser redirected

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Can anyone help me get my computer back. Everytime I go online and go to a web site, it is redirected to a generic gateway search page with a bunch of ad junk. At the top it says sorry could not find ad.doubleclick.net.

I have tryed running avg-antivirus, spysweeper, spy doctor, adaware, spy bot, and registry mechanic, and I still have the same problem. A freind told me about hijackthis, so here I am. Here is a copy of my hijackthis log. I hope someone can tell me what to do.

Thank you

Logfile of HijackThis v1.99.1
Scan saved at 10:18:54 AM, on 1/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT4016
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.roadrunner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" /P24 "EPSON Stylus Photo R1800" /O12 "EP1394D3_001" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hello electric158 and Welcome to TomCoyote,

Your hijackthis log appears to be clean so I did not obtain clues from it. Let's try the following and see if there is improvement.

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


======
Hoster

Please download hoster.
  • Unzip Hoster.zip
  • Open Hoster.exe.
  • Then click on "Restore Original Hosts"
  • Close program when complete.
  • Empty Recycle Bin
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

======
DelDomains

Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As": or if you are using Firefox "Save Page As"
http://www.mvps.org/winhelp2002/DelDomains.inf
Save the file to the desktop. Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal.

========
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

======
Uninstall Manager
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your post
Let me know if there is any improvement and post the list.
Hi Susan528,

Thank you for your help. I ran ATF Cleaner and Hoster. There seemed to be trouble with running Hoster though. I closed it because it kept freezing up and then said not-responding. Whwn I tried to reopen it it said there was an error and wouldn't let me run it. I rebooted the computer and went on line and the same thing happened. I ran hijackthis, and here is the log. Now I'm going to try deldomains and spyware blaster.

Thank you again for your help.

Logfile of HijackThis v1.99.1
Scan saved at 7:12:27 PM, on 1/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT4016
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.roadrunner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE" /P24 "EPSON Stylus Photo R1800" /O12 "EP1394D3_001" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hi again, I installed deldomains, and spyware blaster, and turned on all the protections. I 'm still having the same problems. Here's my uninstall list. Sansa Media Converter Ad-Aware SE Personal Adobe Bridge 1.0 Adobe Flash Player 9 ActiveX Adobe Reader 8 Adobe Stock Photos 1.0 Ahead InCD Ahead InCD EasyWrite Reader Ahead Nero Burning ROM Ahead NeroMIX Ahead NeroVision Express America's Army Backyard Football BigFix Browser Address Error Redirector Canon EOS 20D WIA Driver Canon EOS-1D Mark II WIA Driver Canon EOS-1Ds Mark II WIA Driver Canon Utilities Digital Photo Professional 1.6.1 Canon Utilities EOS Capture 1.2 Canon Utilities EOS Viewer Utility 1.2 Canon Utilities PhotoStitch 3.1 Digital Media Converter 2.71 Digital Media Reader DVD Decrypter (Remove Only) DVD Shrink 3.2 DVD Solution EPSON 1394.3 Printer Devices EPSON Easy Photo Print EPSON EPIC EPSON PhotoCenter EPSON Print CD EPSON Printer Software EPSON RAW Print EPSON SPR1800 Reference Guide Google Toolbar for Internet Explorer Google Updater Hauppauge English Help Files and Resources Hauppauge WinTV Infrared Remote Hauppauge WinTV IR Blaster Hauppauge WinTV Radio Hauppauge WinTV Scheduler Hauppauge WinTV2000 Hauppauge WinTV-PVR 150 Drivers Hauppauge WinTV-PVR PCI II Drivers High Definition Audio Driver Package - KB888111 Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 10 (KB910393) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB912024) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB928388) Hotfix for Windows XP (KB929120) InterActual Player InterVideo FilterSDK for Hauppauge J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 2 JumpStart Explorers JumpStart Math JumpStart Toddlers 2001 Kid Pix Deluxe 3 Lernout & Hauspie TruVoice American English TTS Engine LimeWire 4.12.6 MapCreate U.S.A Hunting w/ Topo 6.3 MediaFACE 4.0 Image Library MediaFACE 4.2 Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Digital Image Starter Edition 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Office Standard Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Windows XP Video Decoder Checkup Utility Microsoft Works MonacoEZcolor Demo Mpeg2Decoder 1.3 MSXML 4.0 SP2 (KB927978) Multimedia Keyboard Driver nanoPEG-Editor 2.3 Hauppauge Edition Napster Burn Engine nik Color Efex Pro 2.0 Promo NVIDIA Drivers OLYMPUS CAMEDIA Master 4.0 Online Manuals for WinTV (English) P.I.M. II Plug-In Power2Go 4.0 PowerDVD Premium ICC Color Profiles QuickTime RealPlayer Basic Realtek High Definition Audio Driver Registry Mechanic 6.0 Rhapsody Player Engine Security Update for Microsoft .NET Framework 2.0 (KB917283) Security Update for Microsoft .NET Framework 2.0 (KB922770) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB926255) Sibelius Scorch Soft Data Fax Modem with SmartCP Sonic Encoders Spy Sweeper Spybot - Search & Destroy 1.4 Spyware Doctor 4.0 SpywareBlaster v3.5.1 TONKA Search & Rescue 2 Ulead DVD MovieFactory 3 SE Update for Windows Media Player 10 (KB913800) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB900930) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920342) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925876) Update Rollup 2 for Windows XP Media Center Edition 2005 USB 2.0 MMC/SD Card Reader Viewpoint Media Player VTPlus32 for WinTV (English) Windows Backup Utility Windows Defender Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live Messenger Windows Live Sign-in Assistant Windows Media Connect Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows Registry Repair SE Windows Rights Management Client Backwards Compatibility SP2 Windows Rights Management Client with Service Pack 2 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887742 Windows XP Media Center Edition 2005 KB925766 YAMAHA Digital Music Notebook YAMAHA Musicsoft Downloader 5
Okay let's just rename the host file.
Please set your system to show all files; please see here if you're unsure how to do this.

Using Windows Explorer, locate the following files/folders
C:\WINDOWS\system32\drivers\etc
Now locate the hosts file and rename it to hostsx (right click and use rename option)
Exit Explorer.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

Combofix
  • Download this file - combofix.exe
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Save that log for your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Please rename the GMER file
    Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
    Run the Gmer.exe renamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your next reply.

Please post (reply) with the results from Kapaersky, the log from ComboFix, the GMER scan, and a fresh hijackthis log.

Let me know if the problem still exists or if renaming the host file helped.
Hi Susan528, Thank you for all your help. When I changed the host file name, that seemed to do it. I ran all the other things that you wanted me to. I still don't know what it was that was doing this, but thank you very much. Here are all the logs that you asked for. Do I need to do anymore, and should I remove any of the software I installed? What should I keep and get rid of? What things should I normally run to keep my computer clean? Have a wonderful day. Tuesday, January 30, 2007 6:16:03 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 31/01/2007 Kaspersky Anti-Virus database records: 248861 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan Statistics Total number of scanned objects 92586 Number of viruses found 0 Number of infected objects 0 / 0 Number of suspicious objects 0 Duration of the scan process 01:15:23 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01272007-210153.log Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_2893198108_1179648_20119 Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE10.tmp Object is locked skipped C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{2FF298D3-142D-4A45-864A-C866C15F322A}.TmpSBE Object is locked skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0260DF19-D435-45CB-9F5F-88494C4249BF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS047B17D1-8050-490C-99A5-810F88DC2BDD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS07DB0065-6F88-4294-906A-7FFB84643CE8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS07E3757C-BF80-49A1-92C8-262BBD33F653.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS090A79B8-FBEA-430E-B1E9-5C5AD8571AF6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS09EF5276-FC8B-4B9D-825A-F11790A4B901.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0D9F9DE6-35FB-4FF3-A19E-292FF6EF4E5D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1D0A6F4D-6B73-426B-BC1B-D0383B1F78ED.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1FB66AC8-4B1E-4FF3-9977-DEFA3BEF5C0C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20256481-7FCF-4F76-A0C5-E53D07C16D3C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS210D0951-E050-43D8-9111-0BF75ED3D58B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS230B8FBA-CA4D-41F9-9A81-A5BAB7C4A95D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24EFAACF-F8E0-4398-B10B-FB10B45849ED.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS262512B4-D5D7-4AC4-8DAA-765AFF1CFE06.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS273DF790-1FB4-41E0-8BCC-015F788F531B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2BE2FA56-EF2C-4D4D-8995-F1A084959713.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2EAFDCEB-609E-46F9-9202-68CB1EDC9BE9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS322DF8B9-7A6D-45F8-B85E-52CA791BDF8A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS32BB590C-C0B5-4A33-96FB-9240BC7BF89D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DCBFA39-1F32-4DD6-B16F-00F077513F77.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DF62356-6AE2-436F-87BC-6E7AA0C4E564.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS43E1861F-F6B7-4F3D-9BFD-31C66163D9B9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS45776729-B8AB-4F5F-A530-3B6A70165FD2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS472ACCDD-39C6-4C86-8D95-E0425C4D84A5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4A9C852B-3CCB-463F-9DAF-366D51DB27AD.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D326A87-68D6-419E-B657-DC44810742C6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS53C74D9A-FC2C-4B4D-AC2F-70CEEDF33E1A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS54596271-966F-4314-85FD-69005C3D164A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5512A3C7-B87D-44E5-9D3F-0DC4A5F50D2D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS57938C2D-C31D-46A7-AEB9-856846540568.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6188E77B-7690-40A0-998F-A343F7507F02.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS61969FD7-9B05-40BE-808B-A6DF69C5F9C2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS61D43BE7-4392-4348-90E9-46066F0EEF83.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS662A974E-0132-4BD8-8162-27D326E3A891.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6C39A946-AC05-4468-B405-765370335662.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6E62E690-F4DB-4021-9528-8F965212A692.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7025BA0B-C5AC-40F7-AD30-21BB97881335.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS706A6F7E-A10F-47FB-87F8-BDE468F990C7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS785D8D1E-5268-40BB-82B2-5CCAFC4CD969.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E5A3C6C-7E43-4B40-9113-C29B00A647AC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7F69E81D-F868-4132-8477-FED2EB8761B9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS957408EA-DD76-4C35-AF87-4AD89158AE12.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9BD4D065-5CC6-430E-85E9-4BDCFDAA3C82.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9C888289-4D3C-4026-BC11-621FFD169FE1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9CA374A2-7094-4142-8776-5568E297D42D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA7306E71-D819-4800-A17F-E33895825D69.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAB916270-97D2-4190-962E-007EBD9F2B2D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAC575AEB-B763-4262-9769-9E4085BE29CB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAE0A7140-2075-4506-8469-9A41DBF7B777.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5782941-E7C7-49FC-8F94-FBC9D46D25C4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB7020594-BE81-496F-A8C0-EDE0B8A0F5D2.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBA20A789-D5B6-41C0-AF82-5FC85F1576FA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBC401451-927E-4941-B702-5B22B0D84AB5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBE406C1C-9B31-40E5-B5B1-EA640C8CE451.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC06B2DD5-62C6-40C6-8B02-63B5924AB46F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC456EDEE-F7DC-4C70-970D-556A0E83E99B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5B0E915-4B4B-44D8-B483-7DA48617F167.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD1E0C563-5598-4309-99DC-663F2371F53B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD4647596-AB2D-4CC1-8303-77E65F38DAF9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD4745FA2-6A47-4DA4-8B62-D37F10ED9CEA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD72F1E5C-4C31-44AF-B0D0-299CCD463076.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD7A157F0-FE20-4225-8919-232EF4DDB5F8.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD84483EC-13FA-4A19-8DF0-181AF8391961.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF650E16-9025-4A31-B825-986347EC5FF5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE6507DFC-D755-4DD6-A61C-A1B5706274DB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSECCA6DC2-6001-4F1C-A21A-5DE2BD6DD692.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF4065B05-3B58-4C87-86A1-A0F257B731FC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF672A403-12B8-4D28-A164-806D8B9AA965.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFC5B2611-EFE6-473A-8614-0867650E3639.tmp Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Logs\Dfsr.log Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\pending.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D8AC_72DA_AC72_B31C\dfsr.db Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D8AC_72DA_AC72_B31C\fsr.log Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D8AC_72DA_AC72_B31C\fsrtmp.log Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Messenger\[removed]\SharingMetadata\Working\database_D8AC_72DA_AC72_B31C\tmp.edb Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{091107A7-F29C-48F4-99F9-75E1A170DA7A} Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\real\members.stg Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Live Contacts\[removed]\shadow\members.stg Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007013020070131\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_fe8.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DF2CE6.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DF3D89.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DF8BE0.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DF8CA7.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DFB4BE.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\~DFB531.tmp Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{593F298F-B7D6-4A3D-A260-6D7E68E3F587}\RP276\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_PCI Soft Data Fax Modem with SmartCP.txt Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{977752B0-A240-4B22-B137-DC5DA7D0F0EE}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. "Owner" - 07-01-30 18:29:14 Service Pack 2 ComboFix 07.01.30 - Running from: "C:\Documents and Settings\Owner\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-12-30 to 2007-01-30 )))))))))))))))))))))))))))))))))) 2007-01-30 16:43 d——– C:\WINDOWS\system32\Kaspersky Lab 2007-01-30 16:43 d——– C:\WINDOWS\LastGood 2007-01-29 19:26 d——– C:\Program Files\SpywareBlaster 2007-01-29 18:23 12,800 –a—— C:\WINDOWS\system\WING32.DLL 2007-01-27 21:01 d——– C:\Program Files\Windows Defender 2007-01-27 20:07 d——– C:\Program Files\Registry Mechanic 2007-01-27 17:26 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Avg7 2007-01-26 21:34 d——– C:\Program Files\Enigma Software Group 2007-01-26 21:14 78,488 –a—— C:\WINDOWS\system32\XMD5.dll 2007-01-26 21:14 101,888 –a—— C:\WINDOWS\system32\vb6stkit.dll 2007-01-26 07:16 51,072 –a—— C:\WINDOWS\system32\drivers\ikhlayer.sys 2007-01-26 07:16 30,592 –a—— C:\WINDOWS\system32\drivers\ikhfile.sys 2007-01-26 07:16 d-a—— C:\DOCUME~1\ALLUSE~1\Application Data\TEMP 2007-01-26 07:16 d——– C:\Program Files\Spyware Doctor 2007-01-26 07:16 d——– C:\DOCUME~1\Owner\Application Data\PC Tools 2007-01-25 22:55 d——– C:\DOCUME~1\ADMINI~1\Application Data\Lavasoft 2007-01-25 22:40 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy 2007-01-25 19:45 d——– C:\Program Files\3B Software 2007-01-25 19:29 63 –a—— C:\WINDOWS\system\SYSRegC.dll 2007-01-25 19:29 143,360 –a—— C:\WINDOWS\system32\GetHardDiskNo.dll 2007-01-25 19:29 1,126,400 –a—— C:\WINDOWS\system32\VchReg.dll 2007-01-25 19:29 d——– C:\Program Files\Max Registry Cleaner 2007-01-25 19:07 d——– C:\DOCUME~1\Owner\Application Data\Registry Cleaner 2007-01-25 18:30 d——– C:\Program Files\Lavasoft 2007-01-25 18:30 d——– C:\DOCUME~1\Owner\Application Data\Lavasoft 2007-01-23 17:28 d——– C:\DOCUME~1\ADMINI~1\Application Data\Webroot 2007-01-23 16:42 d——– C:\DOCUME~1\ADMINI~1\Application Data\AVG7 2007-01-22 19:29 d——– C:\DOCUME~1\NETWOR~1\Application Data\Webroot 2007-01-21 17:54 d——– C:\material_girls_DVD 2007-01-15 09:16 d——– C:\DOCUME~1\Owner\Application Data\Sun 2007-01-14 13:58 d——– C:\crank_DVD 2007-01-13 20:28 d——– C:\DOCUME~1\Denver\Application Data\Adobe 2007-01-11 03:00 d——– C:\WINDOWS\ie7updates 2007-01-08 20:09 d——– C:\Shark_Tale_DVD (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-26 21:15 ——– d——– C:\Program Files\google 2007-01-15 09:18 ——– d——– C:\Program Files\java 2007-01-13 20:23 ——– d——– C:\DOCUME~1\Owner\Application Data\ripit4me 2007-01-10 17:58 ——– d——– C:\Program Files\epson print cd 2007-01-05 17:31 ——– d—s—- C:\DOCUME~1\Owner\Application Data\microsoft 2006-12-26 20:37 ——– d——– C:\Program Files\best buy rhapsody 2006-12-25 11:58 ——– d——– C:\Program Files\Common Files\adobe 2006-12-25 11:58 ——– d——– C:\DOCUME~1\Owner\Application Data\adobe 2006-12-25 10:39 ——– d——– C:\Program Files\quicktime 2006-12-25 10:39 ——– d——– C:\DOCUME~1\Owner\Application Data\real 2006-12-25 10:38 ——– d——– C:\Program Files\Common Files\swf studio 2006-12-25 09:34 8413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys 2006-12-25 09:14 ——– d——– C:\Program Files\real 2006-12-25 09:04 ——– d——– C:\Program Files\Common Files\installshield 2006-12-25 09:03 ——– d–h—– C:\Program Files\installshield installation information 2006-12-25 09:03 ——– d——– C:\Program Files\sandisk 2006-12-24 11:48 ——– d——– C:\Program Files\Common Files\knowledge adventure 2006-12-23 16:20 ——– d——– C:\Program Files\yamaha 2006-12-23 16:10 ——– d——– C:\Program Files\managed directx (0901) 2006-12-23 12:31 ——– d——– C:\Program Files\windows installer clean up 2006-12-22 17:34 ——– d——– C:\DOCUME~1\Owner\Application Data\officeupdate12 2006-12-21 21:16 ——– d——– C:\Program Files\microsoft.net 2006-12-21 21:16 ——– d——– C:\Program Files\microsoft activesync 2006-12-15 18:24 ——– d——– C:\DOCUME~1\Owner\Application Data\adobeum 2006-12-10 10:52 ——– d——– C:\Program Files\windows media connect 2 2006-12-07 20:46 120 –a—— C:\DOCUME~1\Owner\Application Data\fixvts.ini 2006-12-07 18:27 692 –a—— C:\DOCUME~1\Owner\Application Data\wklnhst.dat 2006-11-27 02:45 60416 ——— C:\WINDOWS\system32\tzchange.exe 2006-11-18 09:38 356352 –a—— C:\WINDOWS\esellerateengine.dll 2006-11-16 19:47 524288 –a—— C:\WINDOWS\opuc.dll 2006-11-13 00:02 36352 ——— C:\WINDOWS\system32\tsgqec.dll 2006-11-13 00:02 288768 ——— C:\WINDOWS\system32\rhttpaa.dll 2006-11-13 00:02 1866240 ——— C:\WINDOWS\system32\mstscax.dll 2006-11-13 00:02 116736 ——— C:\WINDOWS\system32\aaclient.dll 2006-11-07 23:06 679424 ——— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-11-07 21:03 413696 ——— C:\WINDOWS\system32\vbscript.dll 2006-11-07 21:03 231424 ——— C:\WINDOWS\system32\webcheck.dll 2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-11-07 21:03 156160 ——— C:\WINDOWS\system32\msls31.dll 2006-11-07 03:27 382976 ——— C:\WINDOWS\system32\iedkcs32.dll 2006-11-07 03:27 229376 ——— C:\WINDOWS\system32\ieaksie.dll 2006-11-07 03:26 71680 ——— C:\WINDOWS\system32\admparse.dll 2006-11-07 03:26 55296 ——— C:\WINDOWS\system32\iesetup.dll 2006-11-07 03:26 54784 ——— C:\WINDOWS\system32\ie4uinit.exe 2006-11-07 03:26 43008 ——— C:\WINDOWS\system32\iernonce.dll 2006-11-07 03:26 152064 ——— C:\WINDOWS\system32\ieakeng.dll 2006-11-07 03:26 13312 ——— C:\WINDOWS\system32\ieudinit.exe 2006-11-07 03:26 123904 ——— C:\WINDOWS\system32\advpack.dll 2006-11-07 03:25 161792 ——— C:\WINDOWS\system32\ieakui.dll 2006-11-07 02:06 600576 ——— C:\WINDOWS\system32\mstsc.exe 2006-11-06 11:35 531568 ——— C:\WINDOWS\system32\rmactivate_isv.exe 2006-11-06 11:35 523376 ——— C:\WINDOWS\system32\rmactivate.exe 2006-11-06 11:35 519280 ——— C:\WINDOWS\system32\secproc_isv.dll 2006-11-06 11:35 518768 ——— C:\WINDOWS\system32\secproc.dll 2006-11-06 11:35 358000 ——— C:\WINDOWS\system32\rmactivate_ssp.exe 2006-11-06 11:35 354416 ——— C:\WINDOWS\system32\rmactivate_ssp_isv.exe 2006-11-06 11:35 323696 ——— C:\WINDOWS\system32\msdrm.dll 2006-11-06 11:35 192624 ——— C:\WINDOWS\system32\secproc_ssp_isv.dll 2006-11-06 11:35 192624 ——— C:\WINDOWS\system32\secproc_ssp.dll 2006-11-05 10:41 43520 ——— C:\WINDOWS\system32\cmdlineext03.dll 2006-11-04 14:14 1245696 ——— C:\WINDOWS\system32\msxml4.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "WMPNSCFG"="\"C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe\"" "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "RTHDCPL"="RTHDCPL.EXE" "Alcmtr"="ALCMTR.EXE" "NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray" "EPSON Stylus Photo R1800"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9LA.EXE\" /P24 \"EPSON Stylus Photo R1800\" /O12 \"EP1394D3_001\" /M \"Stylus Photo R1800\"" "RegistryMechanic"="" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\BigFix\\BigFix.lnk" "backup"="C:\\WINDOWS\\pss\\BigFix.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\BigFix\\bigfix.exe /atstartup" "item"="BigFix" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AOLSP Scheduler" "hkey"="HKLM" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="zHotkey" "hkey"="HKLM" "command"="zHotkey.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ehtray" "hkey"="HKLM" "command"="C:\\WINDOWS\\ehome\\ehtray.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HDAShCut" "hkey"="HKLM" "command"="HDAShCut.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AOLHostManager" "hkey"="HKLM" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvCpl" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvMcTray" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="readericon45G" "hkey"="HKLM" "command"="C:\\Program Files\\Digital Media Reader\\readericon45G.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RECGUARD" "hkey"="HKLM" "command"="%WINDIR%\\SMINST\\RECGUARD.EXE" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Remind_XP" "hkey"="HKLM" "command"="%WINDIR%\\Creator\\Remind_XP.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\ 63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\ 6d,73,73,74,79,6c,65,73,00 "InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\ 73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 Usnsvc REG_MULTI_SZ usnsvc\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8b244b51-00af-11db-a46e-806d6172696f}] Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480 Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\MP Scheduled Scan.job C:\WINDOWS\tasks\wrSpySweeper_3C8AA5269E58474CADAF0FC422005D4C.job Completion time: 07-01-30 18:32:35 "Owner" - 07-01-30 18:29:14 Service Pack 2 ComboFix 07.01.30 - Running from: "C:\Documents and Settings\Owner\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-12-30 to 2007-01-30 )))))))))))))))))))))))))))))))))) 2007-01-30 16:43 d——– C:\WINDOWS\system32\Kaspersky Lab 2007-01-30 16:43 d——– C:\WINDOWS\LastGood 2007-01-29 19:26 d——– C:\Program Files\SpywareBlaster 2007-01-29 18:23 12,800 –a—— C:\WINDOWS\system\WING32.DLL 2007-01-27 21:01 d——– C:\Program Files\Windows Defender 2007-01-27 20:07 d——– C:\Program Files\Registry Mechanic 2007-01-27 17:26 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Avg7 2007-01-26 21:34 d——– C:\Program Files\Enigma Software Group 2007-01-26 21:14 78,488 –a—— C:\WINDOWS\system32\XMD5.dll 2007-01-26 21:14 101,888 –a—— C:\WINDOWS\system32\vb6stkit.dll 2007-01-26 07:16 51,072 –a—— C:\WINDOWS\system32\drivers\ikhlayer.sys 2007-01-26 07:16 30,592 –a—— C:\WINDOWS\system32\drivers\ikhfile.sys 2007-01-26 07:16 d-a—— C:\DOCUME~1\ALLUSE~1\Application Data\TEMP 2007-01-26 07:16 d——– C:\Program Files\Spyware Doctor 2007-01-26 07:16 d——– C:\DOCUME~1\Owner\Application Data\PC Tools 2007-01-25 22:55 d——– C:\DOCUME~1\ADMINI~1\Application Data\Lavasoft 2007-01-25 22:40 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy 2007-01-25 19:45 d——– C:\Program Files\3B Software 2007-01-25 19:29 63 –a—— C:\WINDOWS\system\SYSRegC.dll 2007-01-25 19:29 143,360 –a—— C:\WINDOWS\system32\GetHardDiskNo.dll 2007-01-25 19:29 1,126,400 –a—— C:\WINDOWS\system32\VchReg.dll 2007-01-25 19:29 d——– C:\Program Files\Max Registry Cleaner 2007-01-25 19:07 d——– C:\DOCUME~1\Owner\Application Data\Registry Cleaner 2007-01-25 18:30 d——– C:\Program Files\Lavasoft 2007-01-25 18:30 d——– C:\DOCUME~1\Owner\Application Data\Lavasoft 2007-01-23 17:28 d——– C:\DOCUME~1\ADMINI~1\Application Data\Webroot 2007-01-23 16:42 d——– C:\DOCUME~1\ADMINI~1\Application Data\AVG7 2007-01-22 19:29 d——– C:\DOCUME~1\NETWOR~1\Application Data\Webroot 2007-01-21 17:54 d——– C:\material_girls_DVD 2007-01-15 09:16 d——– C:\DOCUME~1\Owner\Application Data\Sun 2007-01-14 13:58 d——– C:\crank_DVD 2007-01-13 20:28 d——– C:\DOCUME~1\Denver\Application Data\Adobe 2007-01-11 03:00 d——– C:\WINDOWS\ie7updates 2007-01-08 20:09 d——– C:\Shark_Tale_DVD (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-26 21:15 ——– d——– C:\Program Files\google 2007-01-15 09:18 ——– d——– C:\Program Files\java 2007-01-13 20:23 ——– d——– C:\DOCUME~1\Owner\Application Data\ripit4me 2007-01-10 17:58 ——– d——– C:\Program Files\epson print cd 2007-01-05 17:31 ——– d—s—- C:\DOCUME~1\Owner\Application Data\microsoft 2006-12-26 20:37 ——– d——– C:\Program Files\best buy rhapsody 2006-12-25 11:58 ——– d——– C:\Program Files\Common Files\adobe 2006-12-25 11:58 ——– d——– C:\DOCUME~1\Owner\Application Data\adobe 2006-12-25 10:39 ——– d——– C:\Program Files\quicktime 2006-12-25 10:39 ——– d——– C:\DOCUME~1\Owner\Application Data\real 2006-12-25 10:38 ——– d——– C:\Program Files\Common Files\swf studio 2006-12-25 09:34 8413 –a—— C:\WINDOWS\system32\drivers\mcstrm.sys 2006-12-25 09:14 ——– d——– C:\Program Files\real 2006-12-25 09:04 ——– d——– C:\Program Files\Common Files\installshield 2006-12-25 09:03 ——– d–h—– C:\Program Files\installshield installation information 2006-12-25 09:03 ——– d——– C:\Program Files\sandisk 2006-12-24 11:48 ——– d——– C:\Program Files\Common Files\knowledge adventure 2006-12-23 16:20 ——– d——– C:\Program Files\yamaha 2006-12-23 16:10 ——– d——– C:\Program Files\managed directx (0901) 2006-12-23 12:31 ——– d——– C:\Program Files\windows installer clean up 2006-12-22 17:34 ——– d——– C:\DOCUME~1\Owner\Application Data\officeupdate12 2006-12-21 21:16 ——– d——– C:\Program Files\microsoft.net 2006-12-21 21:16 ——– d——– C:\Program Files\microsoft activesync 2006-12-15 18:24 ——– d——– C:\DOCUME~1\Owner\Application Data\adobeum 2006-12-10 10:52 ——– d——– C:\Program Files\windows media connect 2 2006-12-07 20:46 120 –a—— C:\DOCUME~1\Owner\Application Data\fixvts.ini 2006-12-07 18:27 692 –a—— C:\DOCUME~1\Owner\Application Data\wklnhst.dat 2006-11-27 02:45 60416 ——— C:\WINDOWS\system32\tzchange.exe 2006-11-18 09:38 356352 –a—— C:\WINDOWS\esellerateengine.dll 2006-11-16 19:47 524288 –a—— C:\WINDOWS\opuc.dll 2006-11-13 00:02 36352 ——— C:\WINDOWS\system32\tsgqec.dll 2006-11-13 00:02 288768 ——— C:\WINDOWS\system32\rhttpaa.dll 2006-11-13 00:02 1866240 ——— C:\WINDOWS\system32\mstscax.dll 2006-11-13 00:02 116736 ——— C:\WINDOWS\system32\aaclient.dll 2006-11-07 23:06 679424 ——— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-11-07 21:03 413696 ——— C:\WINDOWS\system32\vbscript.dll 2006-11-07 21:03 231424 ——— C:\WINDOWS\system32\webcheck.dll 2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-11-07 21:03 156160 ——— C:\WINDOWS\system32\msls31.dll 2006-11-07 03:27 382976 ——— C:\WINDOWS\system32\iedkcs32.dll 2006-11-07 03:27 229376 ——— C:\WINDOWS\system32\ieaksie.dll 2006-11-07 03:26 71680 ——— C:\WINDOWS\system32\admparse.dll 2006-11-07 03:26 55296 ——— C:\WINDOWS\system32\iesetup.dll 2006-11-07 03:26 54784 ——— C:\WINDOWS\system32\ie4uinit.exe 2006-11-07 03:26 43008 ——— C:\WINDOWS\system32\iernonce.dll 2006-11-07 03:26 152064 ——— C:\WINDOWS\system32\ieakeng.dll 2006-11-07 03:26 13312 ——— C:\WINDOWS\system32\ieudinit.exe 2006-11-07 03:26 123904 ——— C:\WINDOWS\system32\advpack.dll 2006-11-07 03:25 161792 ——— C:\WINDOWS\system32\ieakui.dll 2006-11-07 02:06 600576 ——— C:\WINDOWS\system32\mstsc.exe 2006-11-06 11:35 531568 ——— C:\WINDOWS\system32\rmactivate_isv.exe 2006-11-06 11:35 523376 ——— C:\WINDOWS\system32\rmactivate.exe 2006-11-06 11:35 519280 ——— C:\WINDOWS\system32\secproc_isv.dll 2006-11-06 11:35 518768 ——— C:\WINDOWS\system32\secproc.dll 2006-11-06 11:35 358000 ——— C:\WINDOWS\system32\rmactivate_ssp.exe 2006-11-06 11:35 354416 ——— C:\WINDOWS\system32\rmactivate_ssp_isv.exe 2006-11-06 11:35 323696 ——— C:\WINDOWS\system32\msdrm.dll 2006-11-06 11:35 192624 ——— C:\WINDOWS\system32\secproc_ssp_isv.dll 2006-11-06 11:35 192624 ——— C:\WINDOWS\system32\secproc_ssp.dll 2006-11-05 10:41 43520 ——— C:\WINDOWS\system32\cmdlineext03.dll 2006-11-04 14:14 1245696 ——— C:\WINDOWS\system32\msxml4.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "WMPNSCFG"="\"C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe\"" "Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "RTHDCPL"="RTHDCPL.EXE" "Alcmtr"="ALCMTR.EXE" "NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray" "EPSON Stylus Photo R1800"="\"C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9LA.EXE\" /P24 \"EPSON Stylus Photo R1800\" /O12 \"EP1394D3_001\" /M \"Stylus Photo R1800\"" "RegistryMechanic"="" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\BigFix\\BigFix.lnk" "backup"="C:\\WINDOWS\\pss\\BigFix.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\BigFix\\bigfix.exe /atstartup" "item"="BigFix" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AOLSP Scheduler" "hkey"="HKLM" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="zHotkey" "hkey"="HKLM" "command"="zHotkey.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ehtray" "hkey"="HKLM" "command"="C:\\WINDOWS\\ehome\\ehtray.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HDAShCut" "hkey"="HKLM" "command"="HDAShCut.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="AOLHostManager" "hkey"="HKLM" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvCpl" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NvMcTray" "hkey"="HKLM" "command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="readericon45G" &quo
Hello electric158,

Your logs were cut off but we know the culprit is a bad host file. I would like you to try to run the Hoster again but disable these Anti-spyware programs first. I believe that SpySweeper does have protection to keep the host file from being modified.

SpySweeper may be blocking Hoster so try the following:

Disable Hosts File Shield.Open Spy Sweeper and click Options. Click Shields and click Hosts File. Uncheck Hosts File Shield
Disable SpySweeper:
You have SpySweeper installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
Right click on the SpySweeper icon in your System Tray (near the clock).
From the pop up menu, left click on Shields, this will open the program at the same time.
Click the "Internet Explorer" tab and uncheck the following:
  • IE Favorites Shield
  • IE Security Shield
  • Broswer Helper Object (BHO) Shield
  • IE Hijack Shield
Click the "Windows System Shields" and uncheck the following:
  • Memory Shield
  • Spy Installation Shield
Click the "Startup Programs" tab and uncheck the Startup Items Shield

Disable Spyware Doctor:
Please disable Spyware Doctor, as it may interfere with the fix. To disable Spyware Doctor:
  • Click the Spyware Doctor icon in the System Tray.
  • Click Settings.
  • Click Startup Settings under Pick a Category.
  • Uncheck Run at Windows startup.
  • Click Apply and Exit Spyware Doctor
Once your log is clean you can re-enable Spyware Doctor.

======
Hoster

Please download hoster.
  • Unzip Hoster.zip
  • Open Hoster.exe.
  • Then click on "Restore Original Hosts"
  • Close program when complete.
  • Empty Recycle Bin
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

If you still receive the error with trying to install Hoster like you did before then you will need to create the file yourself. Let me know. We need to get rid of that hostx file and get you a good host file.

http://www.mvps.org/winhelp2002/hosts.htm
Hi Susan528,

I shut down the software yyou told me. I opened hoster, and it told me there was no hosts file. It asked me if I wanted to create one with microsofts original hosts file. I then clicked on restore microsfts original. It only took a second. I'll copy and paste below what it showed. I then went in to the windows file where hostx is. I changed the name of the new hosts file to something different and changed hostx back to hosts, and tried to run Hoster again , but got that error that said somthing about an index grid. I went back in and changed the file names back. Do I delete the hostx file now that I have a new hosts file?

# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a "#" symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
#
127.0.0.1 localhost


Is this all that it's supose to be? ( 127.0.0.1 localhost.) What system tools would be good to run on a regular basis to keep my system running fast and clean? Looking forward to your reply. Here is the new Log.

Logfile of HijackThis v1.99.1
Scan saved at 4:09:34 PM, on 1/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GT4016
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.roadrunner.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Hi , It's doing it again. I didn't make any changes. I got home today and went on-line to check e-mail, and I just went back to check e-mail and its doing it again. What do I do?
Hi susan528, I just ran hoster and rest the hosts file again and now its working. Am I going to have to do that everyday, What could causeing this…do I need to delete that other hostx file?
No it did not work? What? So you are renaming that host file to hostx and then run hoster again. The problem seems to be fixed but start up again. So you tried to delete the bad file but that did not help? Where are you now?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI