This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

what do I need to fix

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer is running slower than usual. Can u help?

Here are my hijackthis logs:

Logfile of HijackThis v1.99.1
Scan saved at 21:11, on 07-03-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\keyhook.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\DOCUME~1\LYDIAG~1\LOCALS~1\Temp\Temporary Directory 3 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
lydmich2 :D

Welcome to Tom Coyote .


You need to enable windows to show all files and folders, instructions Here


Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis



Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.




Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.popcap.com/games/popcaploader_v6.cab

O20 - Winlogon Notify: euuqmjpr - C:\WINDOWS\SYSTEM32\euuqmjpr.dll
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll






Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5


Still in Safemode, look for and delete these files.

C:\WINDOWS\SYSTEM32\euuqmjpr.dll
C:\WINDOWS\system32\inetsvc.dll



Reboot normally and run this system cleaner


Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up



I need to see the AVG Report and a New HJT log please
I am so so sorry that it took me so long to reply. I have had a lot of reports and papers to write for college and weddings to attend. I hope that I did everything you told me to, if not please let me know. Here are the reports you asked for. I ran several scans with that new program so I just included all reports. Thanks for your help and if you have any more suggestions, just let me know.

+ Created at: 04:46 07-03-26

+ Scan result:



C:\HJT\backups\backup-20060815-000940-123.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-220.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-231.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-293.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-297.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-357.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-395.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-404.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-476.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-488.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-513.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-681.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-715.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-829.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-881.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000940-917.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-136.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-198.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-304.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-320.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-333.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-393.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-481.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-495.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-556.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-735.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-874.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-952.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\HJT\backups\backup-20060815-000941-956.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Program Files\y4uzj29l\y4uzj29l.dll -> Adware.ClearSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Lydia Griggs\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine\D6127F96-9A85-4524-8F1A-521A56\2BB9B150-66D7-49E5-BF83-E5C32E -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\filesubmit\endworldknow.zip\NNWDAC638.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-541998944-2676829564-3386067161-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\inetsvc.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKU\S-1-5-21-541998944-2676829564-3386067161-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-4A68-A602-5812EB50A834} -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS52DPT.0DC -> Adware.WinAD : Cleaned with backup (quarantined).
C:\temp\WinCtlAdInstPack.exe -> Adware.WinAD : Cleaned with backup (quarantined).
HKU\S-1-5-21-541998944-2676829564-3386067161-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -> Downloader.ConHook.l : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS41UK5.2QQ -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4HTMF.00G -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4HUVL.2QC -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4I9CD.004 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4IIKT.01C -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4IJDV.00D -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4IJDV.00H -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4U9VL.0NK -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4U9VL.0OC -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4UBVL.0NK -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4UBVL.2R6 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS50KVL.0NK -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS51CUT.001 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS52EUT.00D -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS52QVL.2QS -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS530UT.007 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS54MKT.00I -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5CGHD.008 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5CHVL.01G -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5CIHD.003 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5CLVL.2QG -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5CNVL.2Q7 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5DF3T.005 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS5DHKT.007 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS7JQ05.003 -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Program Files\PopCap Games\PopCap ActiveX Control\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175837.dll -> Proxy.Agent.jj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175860.dll -> Proxy.Agent.jj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175869.dll -> Proxy.Agent.jj : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\euuqmjpr.dll -> Proxy.Agent.jj : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\1.tmp -> Proxy.Agent.jj : Cleaned with backup (quarantined).
[236] C:\WINDOWS\system32\euuqmjpr.dll -> Proxy.Agent.jj : Cleaned with backup (quarantined).
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@spiketv.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\LocalService\Cookies\lydia [removed][2].txt -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia griggs@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\SYSTEM32\qdfxoiic.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tdfqwavc.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tukijuec.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\uvlpsfcb.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\vdcerrgi.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\vnjrbpya.exe -> Trojan.Agent.ny : Cleaned with backup (quarantined).
C:\VundoFix Backups\vga.dll -> Trojan.Crypt.o : Cleaned with backup (quarantined).
C:\Program Files\Trend Micro\Internet Security 2005\VSS4IKCV.00E -> Trojan.Kolweb.a : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hw067.exe -> Trojan.Kolweb.a : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\odef.sys -> Trojan.Kolweb.a : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\w0kcj78.dll -> Trojan.Kolweb.a : Cleaned with backup (quarantined).
C:\WINDOWS\odef.sys -> Trojan.Kolweb.a : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mukt.exe -> Trojan.Kolweb.d : Cleaned with backup (quarantined).


::Report end

+ Created at: 13:11 07-04-04

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175888.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175889.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175890.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175891.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175892.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175893.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175894.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175895.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175896.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175897.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175898.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175899.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175900.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175901.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175902.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175903.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175904.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175905.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175906.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175907.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175908.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175909.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175910.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175911.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175912.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175913.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175914.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175915.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175916.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175917.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175887.EXE -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175920.dll -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175918.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned.
C:\WINDOWS\SYSTEM32\__delete_on_reboot__e_u_u_q_m_j_p_r_._d_l_l_ -> Proxy.Agent.jj : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@realnetworks.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@spiketv.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Gemius : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@pocitadlo[1].txt -> TrackingCookie.Pocitadlo : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@toplist[2].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175881.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175882.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175883.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175884.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175885.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175886.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175879.dll -> Trojan.Crypt.o : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175875.exe -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175876.sys -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175877.dll -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175878.sys -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175880.exe -> Trojan.Kolweb.d : Cleaned.


::Report end

+ Created at: 13:11 07-04-04

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175888.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175889.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175890.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175891.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175892.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175893.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175894.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175895.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175896.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175897.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175898.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175899.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175900.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175901.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175902.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175903.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175904.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175905.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175906.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175907.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175908.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175909.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175910.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175911.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175912.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175913.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175914.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175915.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175916.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175917.dll -> Adware.ClearSearch : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175887.EXE -> Adware.NewDotNet : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175920.dll -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175918.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned.
C:\WINDOWS\SYSTEM32\__delete_on_reboot__e_u_u_q_m_j_p_r_._d_l_l_ -> Proxy.Agent.jj : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@realnetworks.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@spiketv.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Gemius : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Lydia Griggs\Local Settings\Temp\Cookies\lydia [removed][2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@pocitadlo[1].txt -> TrackingCookie.Pocitadlo : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia griggs@toplist[2].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Lydia Griggs\Cookies\lydia [removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175881.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175882.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175883.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175884.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175885.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175886.exe -> Trojan.Agent.ny : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175879.dll -> Trojan.Crypt.o : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175875.exe -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175876.sys -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175877.dll -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175878.sys -> Trojan.Kolweb.a : Cleaned.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP769\A0175880.exe -> Trojan.Kolweb.d : Cleaned.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 10:15, on 07-04-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
No problem on the reply but let me tell ya, you had a ton of garbage on this system, its a wonder it even ran at all. :(

Open up AVG and look for the Quarantine folder and remove it all, nothing in there you want to keep on your system.

Still some work to do, you may want to print this out as we will be offline for the fix.

Download Process Explorer to your desktop.


Download Pocket Killbox to your desktop, unzip it to a folder that you can find

Reboot into Safemode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Unzip Process Explorer and double click on procexp.exe
  • In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen.
  • Click on the Threads tab at the top.
  • Once you see this screen click on each instance of: euuqmjpr.dll and
    inetsvc.dll
    once.
  • Then click the Kill button.
  • After you have killed all of: euuqmjpr.dll and
    inetsvc.dll
    under winlogon click OK.
BE SURE TO KILL ONLY THIS FILE
  • Next double-click on explorer.exe.
  • Select the Threads tab.
  • and again click once on each instance of: euuqmjpr.dll and
    inetsvc.dll
  • Then click the Kill button.
  • Once you have done that click OK again.
BE SURE TO KILL ONLY THIS FILE


Next run Hijack This! and place a check beside each of the following.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)




Highlight the files with the complete path in the Quote Box and press Ctrl C on your keyboard.

C:\WINDOWS\system32\euuqmjpr.dll
C:\WINDOWS\system32\inetsvc.dll

  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure All Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes

Run this free online virus scanner from Panda, its important that I see the report.

Run Panda's ActiveScan from here and perform a full system scan.
  • Once you are on the Panda site click the "Scan your PC" button
  • A new window will open…click the big "Check Now" button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
  • If you are on a slow connection it will take about 15 minuites for the scanner to load.
  • Click on "Local Disks" to start the scan
  • Once scan is done, click "see report" then "save report"
  • Save the log someplace you can find
  • 12. Reboot
  • Post the Panda scan results in your next reply
Let me see a new HJT log please along with the Panda report
hey, once again sorry it took so long to reply but I was out of town for spring break. I think I downloaded process explorer like you told me to, but when I tried to download pocket killbox, it told me that it was invalid for win32 or something. What should I do?
Spring Break, lucky you, :D

Just follow all the instructions for Process Explorer and then remove those entries with HJT, then bypass Killbox and lets see if you can remove them manually. You will have to have windows enabled to show all files and folders and still be in Safemode in order to delete them.

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.

Just right click on Start and then click on Explore > Then your C:\ drive> Then the windows folder> then the system32 folder and look for these files, right click them and click on Delete

C:\WINDOWS\system32\euuqmjpr.dll
C:\WINDOWS\system32\inetsvc.dll
Run this first and then do the Process Explorer fix.

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
hey,
I ran vundofix and it said that i did not have any infected files. But I ran the HJT anyways. Here is the log. What should I do next?

C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
I always need to see the complete HJT log including the header in normal windows or else it does not show me the whole picture.


1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to Delete:
C:\WINDOWS\system32\euuqmjpr.dll 
C:\WINDOWS\system32\inetsvc.dll


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply


Then remove these with HJT.

O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)



Forgot to mention that you have two Anti Virus programs running and thats a bit NoNo, it will slow your system down and cause you many problems. I am looking at Trendmicro and McAfee, you need to uninstall one of them.

Post a new HJT log please along with the Avenger report
I tried to run the avenger program with the inputed data like you told me but an error window popped up that said "selected file does not appear to be a vaild script, Error code 1813. Did I do something wrong?
Use this program instead of Avenger, reboot and then post a new log



Download Pocket Killbox to your desktop, unzip it to a folder that you can find. Pick the download server the closest to you.

Highlight all the files with the complete path inside the quote and press Ctrl C on your keyboard.
  • C:\WINDOWS\system32\euuqmjpr.dll
    C:\WINDOWS\system32\inetsvc.dll


  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes
If you get a message "pending operations has been stopped by external process!" then reboot the computer manually.
This is going to sound really stupid but I could not figure out where to download the pocket killbox program on that link. sorry, could you kinda walk me through it?
Not a problem, sometimes I have to scratch my head myself. When on that page, where it says Pocket KillBox 2.0.0.881

Right under it it will give you download locations to there different servers, it will say

Free Downloads From:

Download Pocket KillBox from the USA MajorGeeks TX - |USA|
Download Pocket KillBox from the USA MajorGeeks TX - |USA|
Download Pocket KillBox from the USA MajorGeeks FL - |USA|
Download Pocket KillBox fromthe USA MajorGeeks FL - |USA|
Download from Pocket KillBox from Europe MajorGeeks EU - |France|
Download from Internode Internode - |Australia|

Just pick the location nearest to where you live. You can save the download to your desktop, if done correctly it will look like a red circle with a white X, then just follow the rest of the instuctions for deleting those bad files.

Ken :D
ok, I think I did it right. here is my new HJT log. Please let me know if I need to do something else.

Logfile of HijackThis v1.99.1
Scan saved at 17:51, on 07-04-19
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\McAfee.com\Agent\McAgent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} (CSEQueryObject Object) - http://www.myheritage.com/Genoogle/Compone…EngineQuery.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1128395092080
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/deltacvx.cab
O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Ok This is where we are at.

1. I hope you removed everything from AVG Antispyware Quarantine folder.

2. You have TWO Anti Virus programs running and thats a big No No, they will suck up system resources and cause you all sorts of problems like slowing down your system. You have Trendmicro and Mcafee , its your call but you need to uninstall one of them via the Add-Remove Program in the Control Panel.

3. You have a ton a bad stuff in your System Restore program, you can flush it out like this, I can't stress enough how important it is to create a New Restore Point.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this
System Restore Tutorial <– If you need it


4. AVG had entries for Vundo, the first program did not fix it so you need to run this other one.

Please start by downloading VirtumondoBegone to your desktop.

  • Reboot your computer into Safemode
  • Go to START/ SHUT OF YOUR COMPUTER/ RESTART
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
  • Then press the ENTER KEY ON YOUR KEYBOARD
  • Doubleclick on VirtumundoBeGone.exe and follow the instructions.
  • Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.
  • When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply.



Still in Safemode , remove these with HJT.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O20 - Winlogon Notify: euuqmjpr - euuqmjpr.dll (file missing)
O20 - Winlogon Notify: inetsvc - C:\WINDOWS\system32\inetsvc.dll (file missing)



Reboot and let me see the Vundobegone log and a New HJT log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI