This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Need Lots Of Help! Cant Do This Alone!

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1 Scan saved at 11:01:03 PM, on 7/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\SYSTEM32\USRshutA.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Coconut\Desktop\HijackThis.exe O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvkis.dll,startup O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\hvqawdof.dll",forkonce O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing) O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe thanks so much for the help!!
Hello CaptCoconut, and [external image: Posted Image] to Tom Coyote Forum.
I will be assisting you with your malware issues.

Please right-click on HijackThis.exe & select Rename to scanner.exe and post back a new Hijackthis log.

As I am still a trainee, everything that I post to you, must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long.
  • Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
  • Continue to respond to this thread until I give you the All Clean! If you have any question or you're stuck in there please reply it to me. I will try my best to help you!
  • Please bookmark or favourite this page. In case you need it as reference or etc.
Hello, and thanks for the speedy response chryssi. Here is my new log. Thanks again =) Logfile of HijackThis v1.99.1 Scan saved at 11:38:09 PM, on 7/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\SYSTEM32\USRshutA.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trillian\trillian.exe C:\Documents and Settings\Coconut\Desktop\scanner.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {416DBA28-8439-44E8-82D6-EB3C20F9FC13} - C:\WINDOWS\system32\urqop.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - C:\WINDOWS\system32\nccunyhd.dll O2 - BHO: (no name) - {FD2A7D3A-3DA1-4CA5-AD39-B4C3A72B567F} - C:\WINDOWS\system32\xxywusr.dll O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvkis.dll,startup O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\hvqawdof.dll",forkonce O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: urqop - C:\WINDOWS\system32\urqop.dll O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing) O20 - Winlogon Notify: windlt32 - C:\WINDOWS\SYSTEM32\windlt32.dll O20 - Winlogon Notify: xxywusr - C:\WINDOWS\SYSTEM32\xxywusr.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing) O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Hello CaptCoconut,

You aren't running Anti Virus Software

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network.
Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

1) Antivir PersonalEditionClassic
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition
-Anti-virus program for Windows.
-The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition
-Free edition of the AVG anti-virus program for Windows.
—————————————————-
Upload a File to Jotti
Please visit http://virusscan.jotti.org/
Click on Browse… and navigate to the following file: C:\WINDOWS\SYSTEM32\windlt32.dll
Click Open
Please let me know the results.
—————————————————-
Download and Run ComboFix
  • Download this file from either of the two below listed places :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
—————————————————-
Please download SmitfraudFix (by S!Ri)

Double-click SmitfraudFix.exe.
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
—————————————————-
Post back:
Jotti results.
Combofix report.
Smitfraud report.
A new HijackThis log.
Here are the joti results. Combofix said it may need to restart my computer so I figured I'd post the results for jotii before it restarted(if it does) so I dont lose them. Posting other results soon(might be later tonight after I get home from work. Thanks again. I already feel you have made my computer 100% better than it already is. File: windlt32.dll Status: INFECTED/MALWARE MD5: 7dc9b8a5d6d9405a514edc8af21552ef Packers detected: PE_PATCH.PECOMPACT, PECBUNDLE, PECOMPACT Bit9 reports: Not analyzed yet (more info) A-Squared Found nothing AntiVir Found TR/Crypt.PEC2X.Gen ArcaVir Found nothing Avast Found nothing AVG Antivirus Found Dialer.HWC BitDefender Found Trojan.Dialer.VTZ ClamAV Found nothing Dr.Web Found Trojan.Mezzia F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan.Win32.Dialer.qn Fortinet Found nothing Kaspersky Anti-Virus Found Trojan.Win32.Dialer.qn NOD32 Found Win32/Agent.QT Norman Virus Control Found W32/Dialer.BHFJ Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found Troj/Nebule-Gen VirusBuster Found nothing VBA32 Found nothing Here is the smidtfraud log. I'm currrently running the combo fix and will post that when i get back from work. I wasnt sure if i needed to run these programs in that order or if this was okay(trying to save time while so I can get to work) Thanks again! SmitFraudFix v2.204 Scan done at 9:39:28.40, 2007-07-14 Run from C:\Documents and Settings\Coconut\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\SYSTEM32\USRshutA.exe C:\WINDOWS\SYSTEM32\USRmlnkA.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trillian\trillian.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\xpupdate.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Coconut »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Coconut\Application Data C:\Documents and Settings\Coconut\Application Data\Install.dat FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Coconut\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: ADMtek AN983 10/100 PCI Adapter - Packet Scheduler Miniport DNS Server Search Order: 68.189.122.19 DNS Server Search Order: 68.189.122.26 DNS Server Search Order: 68.116.46.115 HKLM\SYSTEM\CCS\Services\Tcpip\..\{AB72FACC-C27C-467B-8E61-C2D49ED35A94}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{AB72FACC-C27C-467B-8E61-C2D49ED35A94}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{AB72FACC-C27C-467B-8E61-C2D49ED35A94}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Okay, so here is the combofix log

"Coconut" - 2007-07-14 9:41:18 - ComboFix 07-07-14.6 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\hvqawdof.dll
C:\WINDOWS\system32\jkkjjgd.dll
C:\WINDOWS\system32\nccunyhd.dll
C:\WINDOWS\system32\jkkjjgd.dll
C:\WINDOWS\system32\fodwaqvh.ini
C:\WINDOWS\system32\poqru.bak1
C:\WINDOWS\system32\poqru.ini
C:\WINDOWS\system32\poqru.bak1
C:\WINDOWS\system32\poqru.ini
C:\WINDOWS\system32\urqop.dll
C:\WINDOWS\system32\xxywusr.dll
C:\WINDOWS\system32\xxywusr.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\d.exe
C:\DOCUME~1\Coconut\APPLIC~1.\racle~1
C:\DOCUME~1\Coconut\APPLIC~1\Install.dat
C:\Program Files\Common Files\smbols~1
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\smbols~1
C:\Program Files\stem32~1
C:\Program Files\winpop
C:\WINDOWS\b122.exe
C:\WINDOWS\sembly~1
C:\WINDOWS\smbols~1
C:\WINDOWS\sstem3~1
C:\WINDOWS\system32\cookie.dat
C:\WINDOWS\system32\crosof~1.net
C:\WINDOWS\system32\gyrpsy23.dll
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\wr.txt
C:\windows\xpupdate.exe


((((((((((((((((((((((((( Files Created from 2007-06-14 to 2007-07-14 )))))))))))))))))))))))))))))))


2007-07-14 09:47 d——– C:\WINDOWS\system32\LogFiles
2007-07-14 09:39 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-07-14 09:39 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-07-14 09:39 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-07-14 09:39 1,296 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-14 09:31 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-12 22:51 1 –a—— C:\WINDOWS\system32\ps.dat
2007-07-12 22:46 31,254 –a—— C:\WINDOWS\system32\efcddab.dll
2007-07-10 13:57 d——– C:\Program Files\Ringtone-Chop-Shop
2007-07-03 00:06 d——– C:\Program Files\MSXML 4.0
2007-07-03 00:06 d——– C:\Program Files\Datel
2007-07-03 00:04 19,805 -ra—— C:\WINDOWS\system32\drivers\usbio.sys
2007-06-25 02:02 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-25 02:00 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-25 01:58 d——– C:\!KillBox
2007-06-25 01:56 d——– C:\Program Files\Lavasoft
2007-06-25 01:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-25 01:55 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-24 22:34 d——– C:\Program Files\Security Task Manager
2007-06-24 22:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-14 16:48:34 ——– d—–w C:\Program Files\Trillian
2007-06-25 05:48:47 ——– d—–w C:\Program Files\NetBattle
2007-06-14 21:58:34 ——– d—–w C:\DOCUME~1\Coconut\APPLIC~1\.BitTornado
2007-06-04 22:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 22:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 22:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-27 06:43:56 1,203 —-a-w C:\WINDOWS\checkip.dat
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-15 07:20:08 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 20:38 63128 –a—— C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2005-11-10 13:22 184423 –a—— C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 21:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-23 01:07]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-14 09:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\windlt32]
windlt32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-14 23:24:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-14 23:26:16 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-14 23:25

— E O F —



And the new hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 11:32:33 PM, on 7/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Coconut\Desktop\scanner.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O20 - Winlogon Notify: windlt32 - windlt32.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe


Okay, let me know if I did this wrong….hopefully i got everything right. Thanks again =)

Okay, let me know if I did this wrong….hopefully i got everything right.


Yes :) , i need sometime to review your reports and will be back.
Hello CapCoconut,

LIST OF PROGRAMS USING HIJACKTHIS
  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.
You will see a list with the programs installed in your computer.
Click on save list button and specify where you would like to save this file.
When you press Save button a notepad will open with the contents of that file.
Simply copy and paste the contents of that notepad into a reply in this topic.
————————————————
FIX HIJACKTHIS ENTRIES

Open up Hijackthis.
Click on do a system scan only.
Place a checkmark next to these lines(if still present).

O20 - Winlogon Notify: windlt32 - windlt32.dll (file missing)

Then close all windows except Hijackthis and click Fix Checked
————————————————
COMBOFIX-Do
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\WINDOWS\system32\ps.dat
    C:\WINDOWS\system32\efcddab.dll

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
————————————————
Run HijackThis again.
————————————————
Post back:
Programs List.
Combofix report.
A new HijackThis.
How is your computer behaving now?
Sorry this took me a bit longer than expected. I've unfortunatly been working a lot. Well here is the hijackthis uninstall list text

Action Replay Code Manager
Ad-Aware 2007
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player 9 ActiveX
Adobe Help Center 1.0
Adobe Photoshop 7.0
Adobe Photoshop CS2
Adobe Reader 7.0.8
Adobe Stock Photos 1.0
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI HydraVision
AVG 7.5
AVG Anti-Spyware 7.5
AviSynth 2.5
Beta 1.0.3
BitTornado 0.3.7
BitTorrent 4.0.4
CDex extraction audio
Charter High-Speed™ Self-Installation
DivX
DivX Player
DVD Shrink 3.2
Heroes of Might and Magic V
HijackThis 1.99.1
IsoBuster 1.8
iTunes
J2SE Runtime Environment 5.0 Update 6
Microsoft .NET Framework 1.1
mIRC
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 Parser and SDK
Nero 6 Ultra Edition
Nero Digital
OCTGN (remove only)
PureVoice
QuickTime
Security Task Manager 1.7e
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Spybot - Search & Destroy 1.4
StepMania (remove only)
Trillian
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
USB Dual Vibration Joystick
VideoLAN VLC media player 0.8.5
VobSub v2.23 (Remove Only)
WavePad Uninstall
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
XVid;-)

And here is the combofix report

"Coconut" - 2007-07-16 20:36:54 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Coconut\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ps.dat


((((((((((((((((((((((((( Files Created from 2007-06-17 to 2007-07-17 )))))))))))))))))))))))))))))))


2007-07-14 09:47 d——– C:\WINDOWS\system32\LogFiles
2007-07-14 09:39 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-07-14 09:39 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-07-14 09:39 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-07-14 09:39 1,296 –a—— C:\WINDOWS\system32\tmp.reg
2007-07-14 09:31 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-10 13:57 d——– C:\Program Files\Ringtone-Chop-Shop
2007-07-03 00:06 d——– C:\Program Files\MSXML 4.0
2007-07-03 00:06 d——– C:\Program Files\Datel
2007-07-03 00:04 19,805 -ra—— C:\WINDOWS\system32\drivers\usbio.sys
2007-06-25 02:02 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-25 02:00 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-25 01:58 d——– C:\!KillBox
2007-06-25 01:56 d——– C:\Program Files\Lavasoft
2007-06-25 01:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-25 01:55 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-24 22:34 d——– C:\Program Files\Security Task Manager
2007-06-24 22:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-14 16:48:34 ——– d—–w C:\Program Files\Trillian
2007-06-25 05:48:47 ——– d—–w C:\Program Files\NetBattle
2007-06-14 21:58:34 ——– d—–w C:\DOCUME~1\Coconut\APPLIC~1\.BitTornado
2007-06-04 22:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 22:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 22:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-27 06:43:56 1,203 —-a-w C:\WINDOWS\checkip.dat
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 05:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 20:38 63128 –a—— C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2005-11-10 13:22 184423 –a—— C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-03 21:10]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-23 01:07]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-07-14 09:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 05:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]


**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-16 20:38:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-16 20:39:44
C:\ComboFix-quarantined-files.txt … 2007-07-16 20:39
C:\ComboFix2.txt … 2007-07-14 23:26

— E O F —

and here is a new hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 8:43:02 PM, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Coconut\Desktop\scanner.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

And so far my computer seems to be doing much better. I dont know why i was under the impression that spyware and virus/trojan were the same thing. I have AVG the spyware version just for some reason didnt have the virus version too. Anyways, I had one more question. After all this is done should i put all the logs and program(like hijack this and combofix and such) into a folder and save them all? Also, how is it looking? It sounding almost done and saveable?

Thanks again!!!
Hello Coconut,

And so far my computer seems to be doing much better.

Good. :)

I dont know why i was under the impression that spyware and virus/trojan were the same thing.

No, they are not the same thing.

Anyways, I had one more question. After all this is done should i put all the logs and program(like hijack this and combofix and such) into a folder and save them all? Also, how is it looking? It sounding almost done and saveable?

We will remove all programs used together with the reports created by them when we are completely sure you are clean. You can create a folder and put them all in there if you want to. Just be sure you know where it is when we need to remove it.

I have AVG the spyware version just for some reason didnt have the virus version too

AVG Anti-Spyware is exactly what it says. It's only for Spyware.
————————————
Currently, you have HijackThis located directly on your desktop. In order to keep it together with the backups it makes, please do the following:
  • Right click on the desktop and select > New > Folder
  • Name the new folder HijackThis
  • Now, drag and drop scanner.exe into that new folder
————————————
You are running P2P filesharing programs.
  • Many of these programs come with unwanted components bundled with them.
  • If you wish to find out whether the one you're using does click
    BitTorrent & Bit Tornado.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.


My recommendation is you uninstall them.

If you wish to keep them, please do not use them until your computer is cleaned.
————————————
Please download ATFcleaner
This program is for XP and Windows 2000 only
Make sure that all browser windows are closed. Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved
passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
————————————
You have AVG Antispyware, but there is a new version around, so we have to check that.
  • The new version is 7.5.1.43. To verify that, please open AVG-AS and look in the panel on the right side of the window. The first line will list the version.
  • If you don't have the latest version you have to disable the shield if it's active.
    There will be an AVG-AS icon in the system tray if it is active.
    (The icon looks the same as the AVG Anti-virus icon except that the AVG-AS icon has an "S" in the center.) So please disable that.
*If you have the latest version please ignore the download part, and be sure you have the correct settings.

If you have the older version:
Please remove it, using add/remove programs, reboot your computer and install the new version as my instructions below.

AVG Anti-Spyware - 1st Part

Download the trial version of AVG Anti-Spyware from
here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database fromhere
    (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-clickon avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click
    active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? -make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
Do not run a scan yet.
————————————
Go in Safe Mode by restarting your computer, then continually tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.
Print out these instructions or save them into a notepad on your desktop, because you will not have internet access while in Safe Mode.
————————————
AVG Anti-Spyware - 2nd Part
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to:shows Quarantine
    • Important: Click on the Apply all Actions button (***This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
  • Reboot in normal mode and copy the report back to this topic.
————————————
Run Kaspersky Online AV Scanner
Using Internet Explore Go to http://www.kaspersky.com/virusscanner and click the Kaspersky Online Scanner button.
Note for Internet Explorer 7 users: If at any timeyou have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, clickNext.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then clickOK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save ReportAs…
  • Enter a name for the file in the Filename:text box and then click the down arrow to the right of Save as type: and select text file(*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
————————————
Run HijackThis again.
————————————
Post back:
AVG Anti-Spyware report.
Kaspersky report.
A new HijackThis.
Sorry about the long delay between posts, work just has me going all day and traveling so i havent been around my computer. Well here is the AVG Spyware report

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 6:49:50 PM 7/19/2007

+ Scan result:



C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045591.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045592.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045610.dll -> Adware.BraveSentry : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\SecTaskMan\lyvy.dll.q_804EE00_q -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP553\A0043035.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP564\A0043286.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP565\A0043340.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP565\A0044340.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP565\A0044341.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP567\A0045340.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP567\A0045341.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP567\A0045380.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP569\A0045423.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045548.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045549.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045550.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045606.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045612.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP577\A0045659.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\jkkjjgd.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045547.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045562.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP554\A0043077.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP564\A0043289.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP565\A0043332.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP566\A0044398.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP567\A0045383.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP569\A0045426.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP570\A0045461.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP575\A0045613.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{BB3B32DF-A5EA-4211-B4D8-A2FDDF387CA2}\RP554\A0043076.exe -> Trojan.Small.oa : Cleaned with backup (quarantined).


::Report end

And next is the Kasp virus report(oh yeah, i ran it 4 times and it stopped at 90%, 88%, 99% and 89%. The log im posting was the 90% one, it would just stop and my computer would just lock up and i couldnt even controll alt delete out of it. So i'm not sure what to do but here is the log i do have for it)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, July 19, 2007 11:23:41 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 20/07/2007
Kaspersky Anti-Virus database records: 365434
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 34652
Number of viruses found: 3
Number of infected objects: 2
Number of suspicious objects: 2
Duration of the scan process: 00:33:05

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\YazzleSudoku.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Coconut\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Coconut\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Coconut\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Coconut\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Coconut\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Coconut\Local Settings\History\History.IE5\MSHist012007071920070720\index.dat Object is locked skipped
C:\Documents and Settings\Coconut\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Coconut\My Documents\My Received Files\SPPScript4\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Documents and Settings\Coconut\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Coconut\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

Scan was interrupted by user!


and here is my HJT report

Logfile of HijackThis v1.99.1
Scan saved at 11:24:06 PM, on 7/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Coconut\Desktop\scanner.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe



Well things seem to be running pretty well so far. The only change ive noticed is my AVG Spyware box in my tool bar(or is it task bar?) isnt 4 colors anymore its black and white. Not sure if that means anything. Other than that it seems to be doing better. I'll assume its still not 100% seeing as how the internet thing that locked up on me found 3 files or something of that sort. Anyways, once again, Thanks for all the help and sorry about the delay!
Hello CaptCoconut,

The only change ive noticed is my AVG Spyware box in my tool bar(or is it task bar?) isnt 4 colors anymore its black and white. Not sure if that means anything.


Please disable AVG Antispyware.
  • Open AVG Anti-Spyware by double-clicking the multi-colored box emblazoned with an 'S' in the system tray.
  • In the 'Resident Shield' section, toggle the AVG Anti-Spyware active protection 'off' by clicking 'Change state' which will then change the protection status to 'inactive'.
Go in add/remove programs and remove AVG Anti-Spyware.

Reboot in normal mode and re-install it, but do not set it to automatic update.
Mannually update the program and tell me if there is any difference.
————————————–
Now open Spybot Search & Destroy, and click on Recovery button.

Find this YazzleSudoku.zip entry and click in the empty box in front of it.
Now click on Purge selected items, and click on yes to remove it.
————————————–
Using Windows Explore navigate to and find following folder and delete it.

C:\Documents and Settings\Coconut\My Documents\My Received Files\SPPScript4
————————————–
You need to update your Adobe Reader.
————————————–
I can't see any firewall in your HijackThis log, so i assume you use windows firewall.

FIREWALL
Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.
It's preferable to install one of the suggested firewalls.

FREE FIREWALLS
Tutorial about Firewalls can be found
here

You can choose a free firewall from
here
————————————–
Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of
    Java™ SE Runtime Environment 6u2.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
————————————–
Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.

Download
OTMoveIt by OldTimer to your Desktop.
  • Double click OTMoveIt.exe to launch it.
  • Click on the CleanUp! button.
  • OTMoveIt will download a list from the Internet, if your firewall or other defensive programs alerts you,allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTMoveIt
  • Now delete OTMoveIt.exe (if still present)
————————————–
PANDA ONLINE SCAN
Place a shortcut to Panda ActiveScan on your desktop.

Reboot back into Windows and click the Panda ActiveScan shortcut.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on Local Disks to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
————————————–
Run HijackThis again.
————————————–
Post back:
Panda report.
A new HijackThis.
How is AVG Antispyware shows now?
so here is the panda scan


Incident Status Location

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@2o7[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@adultfriendfinder[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@atdmt[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Coconut\Cookies\[removed]-sys[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@casalemedia[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@com[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@fastclick[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@questionmarket[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@serving-sys[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@tribalfusion[1].txt
Adware:Adware/Yazzle Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc10\Yazzle1162OinUninstaller.exe.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc22.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc29\Process.exe
Potentially unwanted tool:Application/SuperFast Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc29\restart.exe
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc6.exe[nircmd.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc8\nccunyhd.dll.vir
Spyware:Spyware/Virtumonde Not disinfected C:\RECYCLER\S-1-5-21-1454471165-1078145449-1060284298-1003\Dc8\xxywusr.dll.vir
Potentially unwanted tool:Application/RealSpy Not disinfected C:\WINDOWS\system32\actskn45.ocx
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Here is the new HJT report

Logfile of HijackThis v1.99.1
Scan saved at 1:01:27 AM, on 7/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Coconut\Desktop\scanner.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe


So far the AGV looks good. Though i'm not sure if i was supposed to set Resident Shield for active or inactive. Thanks again =) Hope your weekend went well
Hello CaptCoconut,

So far the AGV looks good. Though i'm not sure if i was supposed to set Resident Shield for active or inactive.

That is up to you. Have a read about Resident Shield.

AVG Antispyware/Real-time Protection
The resident shield of AVG Anti-Spyware is active for a period of 30 days. After that you need to order the full version to continue enjoying real-time protection. The resident shield provides effective protection against threats trying to access your system as well as threats already installed on your system. It blocks other programs from terminating AVG Anti-Spyware, it scans files on execution and scans for new applications loaded into the memory. Another handy feature is the setting to delete tracking cookies automatically. The resident shield makes it easy to take action against threats detected on your system and gives you the option to clean and move the object to quarantine, clean it, ignore it or ignore and add the infected object to exceptions.


Hope your weekend went well

Well, weekend is not over yet here. I hope it does. Thanks. :)
——————————————
Please run ATF cleaner and let it clean everything.
——————————————
In case you removed OTMoveIt, here is the link to download it again.

Download OTMoveIt by OldTimer to your Desktop.

  • Double click OTMoveIt.exe to launch it.
  • Copy/Paste the contents of the box below into the left hand pane of OTMoveIt.

C:\WINDOWS\system32\actskn45.ocx
C:\WINDOWS\system32\Process.exe

  • Click the Move It button.
  • The list will be processed and the results will appear in the right hand pane.
  • If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
  • When finished click Exit to exit the program.
——————————————
Now empty recycle-bin.
——————————————
Run Panda On-line scan again and post back the report.
Okay, so here is the new panda report Incident Status Location Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@2o7[1].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Coconut\Cookies\[removed][2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@adultfriendfinder[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@atdmt[2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Coconut\Cookies\[removed]-sys[1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@burstnet[2].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@casalemedia[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@com[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@fastclick[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@questionmarket[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@serving-sys[2].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Coconut\Cookies\coconut@tribalfusion[2].txt Potentially unwanted tool:Application/RealSpy Not disinfected C:\_OTMoveIt\MovedFiles\WINDOWS\system32\actskn45.ocx Potentially unwanted tool:Application/Processor I realized I forgot to download the firewall too. I'll probably do that after i get home from work. And again, thanks for all your help and ideas and time you have spent on making my computer not totally ruined =)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI