This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hjt Fails To Remove Ddccy.dll And Xxyvvwt.dll

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi David, Good job on the research, thanks. I think your situation is a little different here though. You have some services that we need to deal with also. Did you run Combofix with the script I gave you yet? Please try that if not. If so post the log. Thanks
OK, cool, the file ddccv.dll didn't get removed, but it was unpinned and I was able to rename it and move it to C:|. Do you want me to send you the file as an attachment so you can examine it? It also unpinned c:\check_LSA7.txt, which was a growing file, the only thing in it is line after line that reads "check thread".

OK, here are the logs, what's next? I still have the problem with the view refreshing when I browse files, is something still loading itself? I also have had a problem with browser redirections, especially when I google something and click on links, I get two lines in the back history that say Jump and Redirect, about 2 out of 3 times I click a link.


=====================================================================
ComboFix 07-09-05.5 - "Owner" 2007-09-05 13:03:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.742 [GMT -5:00]
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINNT\system32\chniiupc.dll
C:\WINNT\system32\yccdd.bak2
C:\WINNT\system32\yccdd.bak1
C:\WINNT\system32\ddccy.dll
C:\WINNT\system32\6to4svcx.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Owner\APPLIC~1\29209.exe
C:\WINNT\system32\6to4svcx.exe
C:\WINNT\system32\yccdd.bak1
C:\WINNT\system32\yccdd.bak2


((((((((((((((((((((((((( Files Created from 2007-08-05 to 2007-09-05 )))))))))))))))))))))))))))))))


2007-09-05 13:09 1,645 –a—— C:\DOCUME~1\Owner\APPLIC~1\22557.exe
2007-09-05 12:18 d——– C:\VundoFix Backups
2007-09-05 10:05 51,200 –a—— C:\WINNT\NirCmd.exe
2007-09-05 09:47 d——– C:\BRIDAL
2007-09-05 00:54 d——– C:\HJT
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterVideo
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
2007-09-04 22:41 d——– C:\WINNT\system32\carp**
2007-09-04 21:21 244,832 ——— C:\WINNT\system32\ddccy.dll
2007-09-04 21:11 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
2007-08-20 17:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-17 09:48 d–h—– C:\WINNT\PIF
2007-08-17 00:34 d——– C:\Program Files\Security Task Manager
2007-08-17 00:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-14 11:09 21,760 –a—— C:\WINNT\system32\dllcache\usbstor.sys
2007-08-14 10:27 d——– C:\music library
2007-08-13 23:32 d——– C:\Program Files\Real
2007-08-13 23:27 d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-08-13 23:13 d——– C:\Program Files\Best Buy Rhapsody
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\iviaspi.sys
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\drivers\_iviaspi.sys
2007-08-13 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-13 22:55 d——– C:\Program Files\Sandisk


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-05 13:08 ——— d——– C:\Program Files\Norton Internet Security
2007-09-05 13:08 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-08-17 03:15 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-16 20:54 ——— d——– C:\Program Files\Symantec
2007-08-14 08:57 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:56 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-13 22:32 ——— d——– C:\Program Files\Norton AntiVirus
2007-08-13 22:32 ——— d——– C:\Program Files\2Wire
2007-08-03 01:11 59985 -r-hs—- C:\WINNT\system32\adsldpx.exe
2007-07-22 11:32 59985 -r-hs—- C:\WINNT\system32\3076d.exe
2007-07-12 06:02 59985 -r-hs—- C:\WINNT\system32\accwizt.exe
2007-07-11 06:06 59985 -r-hs—- C:\WINNT\system32\2052b.exe
2007-07-05 00:42 59636 -r-hs—- C:\WINNT\system32\a3db.exe
2007-07-05 00:42 11776 –ahs—- C:\WINNT\system32\acluiv.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [2004-03-03 11:29]
"Keyboard Preload Check"="C:\OEMDRVRS\KEYB\Preload.exe" []
"PROMon.exe"="PROMon.exe" [2002-04-18 18:32 C:\WINNT\system32\PROMon.exe]
"CTHelper"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINNT\system32\cthelper.exe]
"UpdReg"="C:\WINNT\UpdReg.EXE" []
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2006-11-18 14:19]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-11-18 14:19]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2006-11-18 14:19]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 14:50 C:\WINNT\system32\SK9910DM.EXE]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2006-11-18 14:19]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2006-11-18 14:19]
"NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [2004-03-03 11:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []
"ctfmon.exe"="C:\WINNT\System32\ctfmon.exe" [2002-08-29 05:41]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [2007-07-24 13:21]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DriverLoad"=
"DriverCheck"=
"SystemDriverLoad"=
"SystemDriver"=
"FDriver"=
"ADriver"=
"CDriver"=
"DDriver"=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINNT\\System32\\ddccy

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll, xlibgfl254.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCheck]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvcAudioSrv"=2 (0x2)
"mnmsrvc"=3 (0x3)

R1 cdudf_xp;cdudf_xp;C:\WINNT\System32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINNT\System32\drivers\pwd_2k.sys
R1 Sk9920nt;PS/2 Keyboard Filter Driver for NT 4.0;C:\WINNT\System32\DRIVERS\Sk9920nt.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINNT\System32\drivers\UdfReadr_xp.sys
R2 NISSERV;Norton Internet Security Service;C:\Program Files\Norton Internet Security\NISSERV.EXE
R2 NMSSvc;Intel® NMS;C:\WINNT\System32\NMSSvc.exe
R2 RioPNP;RioPNP;C:\WINNT\System32\drivers\RioPNP.sys
R3 2WIREPCP;2Wire USB;C:\WINNT\System32\DRIVERS\2WirePCP.sys
R3 GTWModem;GTW V.92 Voicemodem;C:\WINNT\System32\DRIVERS\GWMDM.sys
R3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINNT\System32\drivers\NMSCFG.SYS
R3 Sk99202k;PS/2 Keyboard Filter Driver for Win2000;C:\WINNT\System32\DRIVERS\Sk99202k.sys
S2 COMSysAppSamSs;COM+ System Application COMSysAppSamSs;C:\WINNT\System32\6to4svcx.exe srv
S2 dnlsvc;MS Software Shadow Download Provider;"C:\DOCUME~1\Owner\LOCALS~1\Temp\dnlsvc.exe"
S2 RasManaspnet_state;Remote Access Connection Manager RasManaspnet_state;C:\WINNT\System32\accwizt.exe srv
S2 SCardDrvNtmsSvc;Smart Card Helper SCardDrvNtmsSvc;C:\WINNT\System32\a3db.exe srv
S2 SCardDrvSCardDrv;Smart Card Helper SCardDrvSCardDrv;C:\WINNT\System32\adsldpx.exe srv
S2 SharedAccesshelpsvc;Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccesshelpsvc;C:\WINNT\System32\3076d.exe srv
S3 BCMModem;BCM V.90 56K Modem;C:\WINNT\System32\DRIVERS\BCMDM.sys
S3 dvd_2K;dvd_2K;C:\WINNT\System32\drivers\dvd_2K.sys
S3 mmc_2K;mmc_2K;C:\WINNT\System32\drivers\mmc_2K.sys
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\Atf\Qctest\PCDoc\PCDRDRV.sys
S4 mnmsrvcAudioSrv;NetMeeting Remote Desktop Sharing mnmsrvcAudioSrv;C:\WINNT\System32\2052b.exe srv

*Newly Created Service* - NMSSVC
*Newly Created Service* - SYMTDI

Contents of the 'Scheduled Tasks' folder
"2007-09-05 03:45:23 C:\WINNT\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-05 13:09:30
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-05 13:11:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-05 13:11
C:\ComboFix2.txt … 2007-09-05 10:17

— E O F —


================================================================

Logfile of HijackThis v1.99.1
Scan saved at 1:17:36 PM, on 9/5/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\WINNT\System32\PROMon.exe
C:\WINNT\System32\CTHELPER.EXE
C:\WINNT\System32\NMSSvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\System32\SK9910DM.EXE
C:\WINNT\System32\RUNDLL32.EXE
C:\WINNT\System32\ctfmon.exe
C:\WINNT\system32\notepad.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.historytoday.com/CFIDE/classes/CFJava.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned32.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe
O20 - AppInit_DLLs:
O23 - Service: COM+ System Application COMSysAppSamSs (COMSysAppSamSs) - Unknown owner - C:\WINNT\System32\6to4svcx.exe (file missing)
O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\dnlsvc.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Remote Access Connection Manager RasManaspnet_state (RasManaspnet_state) - Unknown owner - C:\WINNT\System32\accwizt.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Smart Card Helper SCardDrvNtmsSvc (SCardDrvNtmsSvc) - Unknown owner - C:\WINNT\System32\a3db.exe
O23 - Service: Smart Card Helper SCardDrvSCardDrv (SCardDrvSCardDrv) - Unknown owner - C:\WINNT\System32\adsldpx.exe
O23 - Service: Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccesshelpsvc (SharedAccesshelpsvc) - Unknown owner - C:\WINNT\System32\3076d.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Hey David, Nice work. I have a question before we continue with the fix. Do you know what this service is by any chance? I can't find much on it. My inclination is to kill it but…; O23 - Service: Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccesshelpsvc (SharedAccesshelpsvc) - Unknown owner - C:\WINNT\System32\3076d.exe Let me know.
I'm not sure, but I think it has to do with having a Gateway tech log onto my comp remotely a week ago to fix a driver problem I was having with my CD-ROMs. I was working on getting rid of spyware (I've been hacking on this a while) and I think I trashed a registry entry, anyway he had me install something so he could get on and fix the problem. I removed all the files afterwards, but I guess the service entry might be part of it. There is no program on my system with that name.
Please copy (Ctrl C) and paste (Ctrl V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat. Please save it on your desktop.

sc stop COMSysAppSamSs
sc delete COMSysAppSamSs

sc stop dnlsvc
sc delete dnlsvc

sc stop SharedAccesshelpsvc
sc delete SharedAccesshelpsvc

exit

Double click FixServices.bat. A window will open and close. This is normal.

—————————————————————————-

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O20 - AppInit_DLLs:
O23 - Service: COM+ System Application COMSysAppSamSs (COMSysAppSamSs) - Unknown owner - C:\WINNT\System32\6to4svcx.exe (file missing)
O23 - Service: MS Software Shadow Download Provider (dnlsvc) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\dnlsvc.exe (file missing)
O23 - Service: Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS) SharedAccesshelpsvc (SharedAccesshelpsvc) - Unknown owner - C:\WINNT\System32\3076d.exe

Then close all windows except this one and press Fix checked.

—————————————————————————-

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

—————————————————————————–

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
The batch file ran ok. When I brought up HJT, the 023 items you mentioned did not appear. I checked the 020 and clicked fix it, and I got an error popup: An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: ) Error #5 - Invalid procedure call or argument Please email me at [removed], reporting the following: * What you were trying to fix when the error occurred, if applicable * How you can reproduce the error * A complete HijackThis scan log, if possible Windows version: Windows NT 5.01.2600 MSIE version: 6.0.2800.1106 HijackThis version: 1.99.1 This message has been copied to your clipboard. Click OK to continue the rest of the scan.
I tried to install the scanner, I get a popup window that says "The file '002E08D9.key' on (Unknown) is needed." Then it instructs me to type the path where the file is located, there is a window below with a default path of C:\DOCUME~1\Owner\LOCALS~1\Temp\lCD1.tmp. I did a search and there is no such file on my comp.
Yes, Kaspersky is having a problem. I've had a couple of complaints and tested it tonight myself and got the same error. I'll have to look into it. Fortunately there are other scanners.

You will need to run this with Internet Explorer.
Run Panda's ActiveScan from here and perform a full system scan.
  • Once you are on the Panda site click the "Scan your PC" button
  • A new window will open…click the big "Check Now" button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
  • If you are on a slow connection it will take about 15 minuites for the scanner to load.
  • Click on "Local Disks" to start the scan
  • Once scan is done, click "see report" then "save report"
  • Save the log someplace you can find
  • Reboot
  • Post the Panda scan results in your next reply
OK, here is the log, it looks like it's padded with a bunch of cookies that SpyEraser quarantined, but there was at least one virus that from what I can tell infected norton AV and a few other programs. I'm not sure if the log means they are still affected or not. My NAV is out of date, it's expired so I can't get new definitions, and it isn't working right any more, perhaps it's been compromised. I tried to uninstall it and couldn't, it keeps telling me I need admin priviledges. I have a security suite from Gateway that I'm waiting to install once the system is clean (I don't want to put it on a system that's messed up, and I'm still considering I may need to reformat, but I have no way atm of backing up several large directories without spending extensive time breaking them up. =========================================================================== Incident Status Location Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_01_03_2007_17_43_13.asq18467 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_01_03_2007_17_43_13.asq41 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_05_02_2007_03_02_49.asq2995 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_05_02_2007_03_02_49.asq491 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_14_08_2007_00_03_23.asq15724 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_14_08_2007_00_03_23.asq19169 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_24_02_2007_08_20_13.asq18467 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_24_02_2007_08_20_13.asq41 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_29_06_2007_06_21_29.asq26500 Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\adrevolver_29_06_2007_06_21_29.asq6334 Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Adserver.com_05_02_2007_03_02_49.asq12859 Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Adserver.com_14_08_2007_00_03_23.asq18467 Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Adserver.com_24_02_2007_08_20_13.asq32391 Adware:Adware/CommAd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Adware.cmdService_04_09_2007_22_14_05.asq23811 Adware:Adware/DollarRevenue Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Apropos_04_09_2007_22_14_06.asq30333 Adware:Adware/CommAd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Aurora_04_09_2007_22_14_05.asq17035 Adware:Adware/CommAd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Aurora_04_09_2007_22_14_05.asq9894 Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\BFast.com_24_02_2007_08_20_14.asq292 Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Bravenet.com_14_08_2007_00_03_23.asq18716 Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Bravenet.com_24_02_2007_08_20_14.asq12382 Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Bravenet.com_29_06_2007_06_21_29.asq32391 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_01_03_2007_17_43_13.asq26500 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_04_09_2007_22_14_04.asq16827 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_05_02_2007_03_02_49.asq27529 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_14_08_2007_00_03_23.asq19895 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_14_08_2007_10_07_52.asq41 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_16_08_2007_21_50_57.asq18467 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_24_02_2007_08_20_14.asq17421 Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\casalemedia.com_29_06_2007_06_21_29.asq14604 Spyware:Cookie/Clicktracks Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\ClickTracks_29_06_2007_06_21_30.asq28703 Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DomainSponsor.com_05_02_2007_03_02_49.asq15350 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_01_03_2007_17_43_13.asq16827 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_04_09_2007_22_14_04.asq14604 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_05_02_2007_03_02_49.asq8942 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_14_08_2007_00_03_23.asq20037 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_14_08_2007_22_49_34.asq41 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_16_08_2007_21_50_58.asq5705 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_18_08_2007_23_32_30.asq26962 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_24_02_2007_08_20_14.asq11538 Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\DoubleClick_29_06_2007_06_21_29.asq17421 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_01_03_2007_17_43_13.asq491 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_01_03_2007_17_43_13.asq9961 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_04_09_2007_22_14_04.asq12382 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_05_02_2007_03_02_49.asq27446 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_14_08_2007_00_03_24.asq22190 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_18_08_2007_23_32_30.asq24464 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_24_02_2007_08_20_14.asq23811 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_24_02_2007_08_20_14.asq31322 Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FastClick.com_29_06_2007_06_21_30.asq14771 Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FortuneCity.com_01_03_2007_17_43_13.asq2995 Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\FortuneCity.com_24_02_2007_08_20_14.asq17673 Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Hitbox.com_14_08_2007_00_03_23.asq12859 Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Hitbox.com_24_02_2007_08_20_14.asq1869 Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Hitbox.com_29_06_2007_06_21_29.asq18716 Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\hitslink.com_18_08_2007_23_32_30.asq29358 Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\hitslink.com_24_02_2007_08_20_14.asq19718 Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\HotLog.ru_04_09_2007_22_14_04.asq18716 Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\HotLog.ru_14_08_2007_00_03_24.asq1842 Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\HotLog.ru_24_02_2007_08_20_14.asq15141 Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\LinkSynergy.com_24_02_2007_08_20_14.asq28253 Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\LinkSynergy.com_29_06_2007_06_21_30.asq11538 Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\maxserving_01_03_2007_17_43_13.asq11942 Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\maxserving_05_02_2007_03_02_49.asq15006 Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\maxserving_24_02_2007_08_20_14.asq6868 Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\maxserving_29_06_2007_06_21_30.asq1869 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_01_03_2007_17_43_13.asq4827 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_04_09_2007_22_14_04.asq19895 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_14_08_2007_00_03_24.asq288 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_18_08_2007_23_32_30.asq5705 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_24_02_2007_08_20_14.asq25547 Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Mediaplex.com_29_06_2007_06_21_30.asq19912 Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\myaffiliateprogram_14_08_2007_00_03_24.asq15006 Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\PayCounter.com_05_02_2007_03_02_49.asq31101 Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\PayCounter.com_14_08_2007_00_03_24.asq30106 Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\PayCounter.com_14_08_2007_10_07_52.asq15724 Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\PayCounter.com_29_06_2007_06_21_30.asq25667 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_01_03_2007_17_43_13.asq5436 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_04_09_2007_22_14_04.asq5447 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_05_02_2007_03_02_49.asq3548 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_14_08_2007_00_03_24.asq9040 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_18_08_2007_23_32_30.asq28145 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_24_02_2007_08_20_14.asq27644 Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\QuestionMarket.com_29_06_2007_06_21_30.asq26299 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_01_03_2007_17_43_13.asq32391 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_04_09_2007_22_14_04.asq21726 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_05_02_2007_03_02_49.asq19629 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_14_08_2007_00_03_24.asq8942 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_16_08_2007_21_50_58.asq16827 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_18_08_2007_23_32_30.asq23281 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_24_02_2007_08_20_14.asq32662 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_26_06_2007_18_40_15.asq11478 Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\RealMedia.com_26_06_2007_18_40_15.asq29358 Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Revenue.net_05_02_2007_03_02_50.asq12623 Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Revenue.net_14_08_2007_00_03_24.asq22648 Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Revenue.net_24_02_2007_08_20_13.asq153 Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexList.com_04_09_2007_22_14_04.asq11538 Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexList.com_14_08_2007_00_03_24.asq6729 Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexList.com_14_08_2007_10_07_52.asq11478 Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexList.com_16_08_2007_21_50_58.asq9961 Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexList.com_29_06_2007_06_21_30.asq17035 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_04_09_2007_22_14_04.asq11942 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_04_09_2007_22_14_04.asq2995 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_04_09_2007_22_14_04.asq491 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq11538 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq17035 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq17673 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq1869 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq19912 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq23811 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq25667 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq26299 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq28703 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq30333 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq31322 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq5447 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_00_03_23.asq9894 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_10_07_52.asq18467 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_14_08_2007_10_07_52.asq6334 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_16_08_2007_21_50_57.asq15724 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_16_08_2007_21_50_57.asq19169 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_16_08_2007_21_50_57.asq26500 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_24_02_2007_08_20_14.asq19895 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_24_02_2007_08_20_14.asq5447 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_29_06_2007_06_21_29.asq153 Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SexTracker.com_29_06_2007_06_21_29.asq292 Spyware:Cookie/Santa Monica networks inc Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SMNI.com_05_02_2007_03_02_50.asq24084 Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SpyLog.com_24_02_2007_08_20_14.asq32757 Adware:Adware/PestCapture Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\SpySheriff_05_02_2007_03_02_48.asq23281 Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Statcounter_01_03_2007_17_43_13.asq14604 Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Statcounter_05_02_2007_03_02_50.asq19954 Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Statcounter_24_02_2007_08_20_14.asq20037 Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Statcounter_29_06_2007_06_21_30.asq9894 Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Targetnet Cookie_24_02_2007_08_20_14.asq12859 Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tickle Cookie_05_02_2007_03_02_49.asq12316 Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_01_03_2007_17_43_13.asq15724 Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_01_03_2007_17_43_13.asq19169 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_01_03_2007_17_43_13.asq26962 Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_04_09_2007_22_14_04.asq11478 Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_04_09_2007_22_14_04.asq26962 Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_04_09_2007_22_14_04.asq6334 Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq15141 Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq17673 Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq21726 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq23811 Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq292 Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq32391 Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq3902 Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_05_02_2007_03_02_49.asq4827 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq153 Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq26962 Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq29358 Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq2995 Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq5436 Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq5705 Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_14_08_2007_00_03_23.asq9961 Spyware:Cookie/Lop Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_16_08_2007_21_50_58.asq28145 Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_18_08_2007_23_32_29.asq41 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_18_08_2007_23_32_29.asq6334 Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq11942 Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq15724 Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq16827 Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq19169 Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq26500 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq491 Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_24_02_2007_08_20_13.asq6334 Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_29_06_2007_06_21_29.asq11478 Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_29_06_2007_06_21_29.asq11942 Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_29_06_2007_06_21_29.asq15724 Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Tracking Cookie_29_06_2007_06_21_29.asq491 Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TradeDoubler.com_24_02_2007_08_20_14.asq8723 Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TradeDoubler.com_29_06_2007_06_21_30.asq23811 Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Trafficmp Cookie_01_03_2007_17_43_13.asq3902 Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Trafficmp Cookie_24_02_2007_08_20_14.asq9741 Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Trafficmp Cookie_29_06_2007_06_21_30.asq31322 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_01_03_2007_17_43_13.asq153 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_05_02_2007_03_02_50.asq4966 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_14_08_2007_00_03_24.asq24370 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_18_08_2007_23_32_30.asq16827 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_24_02_2007_08_20_14.asq27529 Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\TribalFusion.com_29_06_2007_06_21_30.asq30333 Adware:Adware/CommAd Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Unclassified.Spyware.149_04_09_2007_22_14_06.asq31322 Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\XXXCounter.com_04_09_2007_22_14_04.asq25667 Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\XXXCounter.com_14_08_2007_00_03_24.asq31101 Spyware:Cookie/XXXCounter Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\XXXCounter.com_16_08_2007_21_50_58.asq491 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_01_03_2007_17_43_13.asq292 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_04_09_2007_22_14_04.asq26299 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_05_02_2007_03_02_50.asq13931 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_14_08_2007_00_03_24.asq24393 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_24_02_2007_08_20_14.asq3035 Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Uniblue\SpyEraser\Quarantine\Zedo Cookie_29_06_2007_06_21_30.asq4664 Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Owner\Desktop\cleanup tools\ComboFix.exe[nircmd.exe] Spyware:Spyware/Virtumonde Not disinfected C:\Downloads\backups\backup-20070904-232924-287.dll Spyware:Spyware/Virtumonde Not disinfected C:\Downloads\backups\backup-20070904-233423-100.dll Spyware:Spyware/Virtumonde Not disinfected C:\Downloads\backups\backup-20070904-233615-464.dll Spyware:Spyware/Virtumonde Not disinfected C:\Downloads\backups\backup-20070905-000025-222.dll Spyware:Spyware/Virtumonde Not disinfected C:\Downloads\backups\backup-20070905-000947-837.dll Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\nircmd.exe Spyware:Spyware/Virtumonde Not disinfected C:\HJT\backups\backup-20070905-010410-189.dll Virus:W32/ZlFake.A Disinfected C:\Program Files\2Wire\2PortalMon.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\2Wire\2PortalMon.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\2Wire\2PortalMon.ex_ Virus:W32/ZlFake.A Disinfected C:\Program Files\Creative\SBAudigy\Program\ADGJDet.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\Creative\SBAudigy\Program\ADGJDet.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\Creative\SBAudigy\Program\ADGJDet.ex_ Adware:Adware/Look2Me Not disinfected C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Virus:W32/ZlFake.A Disinfected C:\Program Files\Norton AntiVirus\navapw32.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\Norton AntiVirus\navapw32.exe Adware:Adware/Look2Me Not disinfected C:\Program Files\Norton AntiVirus\navapw32.ex_ Virus:W32/ZlFake.A Disinfected C:\Program Files\Norton Internet Security\IAMAPP.EXE Adware:Adware/Look2Me Not disinfected C:\Program Files\Norton Internet Security\IAMAPP.EXE Adware:Adware/Look2Me Not disinfected C:\Program Files\Norton Internet Security\IAMAPP.EX_ Adware:Adware/Look2Me Not disinfected C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe Virus:Trj/Agent.GEY Disinfected C:\qoobox\Quarantine\C\WINNT\system32\6to4svcx.exe.vir Virus:Bck/Agent.GBW Disinfected C:\qoobox\Quarantine\C\WINNT\system32\regscan.exe.vir Virus:Trj/Downloader.OZB Disinfected C:\qoobox\Quarantine\C\WINNT\system32\rhqfudxa.exe.vir Virus:Generic Malware Disinfected C:\qoobox\Quarantine\catchme2007-09-05_101441.25.zip[29209.exe] Potentially unwanted tool:Application/ServUBased.A Not disinfected C:\WINNT\Config\rundll32.exe Virus:Backdoor Program Disinfected C:\WINNT\java\inf\rps.exe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINNT\NirCmd.exe Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\2052b.exe Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\3076d.exe Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\a3db.exe Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\accwizt.exe Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\acluiv.dll Virus:Trj/Downloader.MDW Disinfected C:\WINNT\system32\adsldpx.exe Adware:Adware/SecurityError Not disinfected C:\WINNT\system32\xlibgfl254.dll Adware:Adware/Look2Me Not disinfected C:\WINNT\UpdReg-back.EXE
Hi David,

If the virus definitions on your Norton have run out you want to remove that ASAP. Norton can be a bear to remove, hence the need for "special" removal tools. Why they don't design these "special" removal tools right INTO their product is beyond me (but don't get me started on Norton, oops, too late).
This is right from their web site:

http://service1.symantec.com/SUPPORT/tsgen…005033108162039

Unless they are false positives from Panda, which could be the case?, it looks like you were infected by Look2Me at one point. Although up to the Panda scan I did not see any evidence of it. Any thoughts there? Something in the past maybe?

I may be wrong here but let's run a scan for Look2Me. Run only the scan now.

Download L2mfix from one of these two locations:

http://www.downloads.subratam.org/l2mfix.exe
http://www.atribune.org/downloads/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe,
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."…then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.


I'm putting together the rest of the fix for you now. If you had any information on my question that would help too.

Please post a fresh HJT log too.

Thanks
OK, it ran fine, took about 3 seconds.

Hmm, looking at the BHOs from HJT, looks like a new one got installed.

=====================================================================

L2MFIX find log 051206
These are the registry keys present
********************************************************************************
*
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

********************************************************************************
*
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

********************************************************************************
*
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"

********************************************************************************
*
HKEY ROOT CLASSIDS:
********************************************************************************
*
Files Found are not all bad files:

No matches found.
Locate .tmp files:

No matches found.
********************************************************************************
*
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is F8C8-694E

Directory of C:\WINNT\System32

09/05/2007 01:06 PM 1,983,248 yccdd.ini
09/05/2007 10:05 AM 295 cpuiinhc.ini
08/14/2007 11:09 AM dllcache
08/14/2007 09:07 AM 384 4173883726.dat
08/11/2007 03:06 AM 238 index.dat
09/14/2002 07:59 PM Microsoft
4 File(s) 1,984,165 bytes
2 Dir(s) 2,499,989,504 bytes free

============================================================================

Logfile of HijackThis v1.99.1
Scan saved at 10:23:09 AM, on 9/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINNT\System32\PROMon.exe
C:\WINNT\System32\CTHELPER.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\System32\SK9910DM.EXE
C:\WINNT\System32\RUNDLL32.EXE
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
O2 - BHO: TB Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.historytoday.com/CFIDE/classes/CFJava.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned32.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Remote Access Connection Manager RasManaspnet_state (RasManaspnet_state) - Unknown owner - C:\WINNT\System32\accwizt.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Smart Card Helper SCardDrvNtmsSvc (SCardDrvNtmsSvc) - Unknown owner - C:\WINNT\System32\a3db.exe (file missing)
O23 - Service: Smart Card Helper SCardDrvSCardDrv (SCardDrvSCardDrv) - Unknown owner - C:\WINNT\System32\adsldpx.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Hi David,

Yes, nothing bad that I can see in Look2Me log. You're right on with the new BHO, and it's a baddie. Where did that come from???

Keyword hijacker, file located in a -"Program Files\WinBudget\bin" directory, detected by Kaspersky antivirus as AdWare.Win32.BHO.by - - NOTE: Do not confuse with the legitimate Budget_For_Windows file of the same name!

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: TB Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll

Then close all windows except this one and press Fix checked.

You can also delete the folder using Windows Explorer.

C:\Program Files\WinBudget

I have posted a reg fix based on your Combofix log also to be reviewed by an expert/teacher here and will post that when I get a response.
While we're waiting on the reg fix, can you give me a line-by-line blurb of what the rest of the stuff in the HJT log is doing? A lot of it I can't make heads or tails of, and it can probably be killed.
Hey Dave, Well, some of the lines are pretty self-explanatory, like anything that says Norton obviously is your AV, ect…and you don't want to kill those. Rather than have me have to go through every other line why don't you post back with ones your not sure of and I'll give you my take on it and whether or not it can be killed. Hopefully that's Okay.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI