This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Mal/DownLdr-O

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My spysweeper can not quarentine this. I'm going to be loading windows sp2 for XP and was told not to load until my computer is clean. How do I get rid of this Malware. Any help would be appreciated. Thanks Steph
Logfile of HijackThis v1.99.1
Scan saved at 4:34:23 PM, on 2/6/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aim toolbar 5.0\AolTbServer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Zero Knowledge Freedom] "C:\Program Files\Zero Knowledge\Freedom\Freedom.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.wbal.com
O16 - DPF: Canasta by pogo - http://game1.pogo.com/v/8.1.0.23/applet/ca…nasta-en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/v/8.1.0.23/applet/ma…jong2-en_US.cab
O16 - DPF: No-Limit Texas Hold'em by pogo - http://game1.pogo.com/v/8.1.0.25/applet/al…allin-en_US.cab
O16 - DPF: Payday Freecell Solitaire by pogo - http://game1.pogo.com/v/8.1.0.23/applet/fr…cell2-en_US.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/v/8.1.0.23/applet/wa…wheel-en_US.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/v/8.1.0.23/applet/pe…peaks-en_US.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by116fd.bay116.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Well not seeing anything there at first glance. One thing though, you do not have any antivirus software. I would advise you do that as soon as possible. Here are a couple of free for home use ones.

Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. Here is a list of some free and evaluation versions to try:
  • AVG AntiVirus
    Avast Antivirus Home Version–Free
    Antivir Personal - Free

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    In the meantime let's run a scan and do some cleanup to see what is found.

    Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

    If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG


  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.


Restart into normal mode and post the AVG Log and a new HJT Log. Also how are things now
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 9:59:21 PM 2/6/2008 + Scan result: C:\WINDOWS\system32\hogcg.dll -> Adware.Adstart : Cleaned with backup (quarantined). C:\Documents and Settings\Default User\Start Menu\Programs\EARN -> Adware.eZula : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1018.dll -> Adware.Gator : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\HDPlugin1018.dll -> Adware.Gator : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2739440239-2366572900-1554198012-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined). C:\Program Files\ZangoToolbar\Bin\4.8.2.0\ZbAds.dll -> Adware.HotBar : Cleaned with backup (quarantined). C:\Program Files\ZangoToolbar\Bin\4.8.2.0\ZbCoreSrv.dll -> Adware.HotBar : Cleaned with backup (quarantined). C:\Program Files\ZangoToolbar\Bin\4.8.2.0\ZbSrv.exe -> Adware.HotBar : Cleaned with backup (quarantined). C:\WINDOWS\Temp\upd124.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr0DA5\PIB.exe -> Adware.WebSearch : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr0DA5\TBPS.exe -> Adware.WebSearch : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~376849.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~379747.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~41438.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~445922.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~47131.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~477225.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~497589.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~502477.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~508554.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~509343.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~625305.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~710986.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~725947.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~736463.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~740467.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~765151.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~769295.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~774659.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~779399.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~889292.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~901002.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\Local Settings\Temp\~919776.tmp -> Adware.Wintol : Cleaned with backup (quarantined). C:\WINDOWS\system32\lwinksap.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP176\A0029241.exe/hidden32.exe -> Backdoor.Hupigon.hk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP176\A0029241.exe/rundll31.exe -> Backdoor.Iroffer.b : Cleaned with backup (quarantined). C:\Q250204.exe -> Downloader.WinShow.r : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\ffplszeu.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\hvdznubs.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\icornmqg.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\qohmbqdl.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\stfezhpv.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\Program Files\Internet Explorer\tnxiwvcu.exe -> Downloader.WinShow.z : Cleaned with backup (quarantined). C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\WTI3CXIJ\AppWrap[1].exe -> Dropper.Small.of : Cleaned with backup (quarantined). C:\WINDOWS\system32\config\systemprofile\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned. C:\WINDOWS\system32\TFTP3676 -> Trojan.Crypt.d : Cleaned with backup (quarantined). C:\WINDOWS\system32\dohey10.dll -> Trojan.Kolweb.f : Cleaned with backup (quarantined). C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\A1K3M5IX\exitpoplight1[1].htm -> Trojan.NoClose.i : Cleaned with backup (quarantined). ::Report end
Well AVG cleaned up quite a bit. Since you have had no Antivirus running let's get a virus scan too.

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log. Please let me know how it's running at this point also.

Dave
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Thursday, February 07, 2008 5:07:18 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 7/02/2008 Kaspersky Anti-Virus database records: 553461 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 138560 Number of viruses found: 29 Number of infected objects: 56 Number of suspicious objects: 0 Duration of the scan process: 03:48:12 Infected Object Name / Virus Name / Last Action C:\557a3af6a15be0825fe00ac0cdb3\admparse.dll Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\advpack.dll Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\browseui.dll Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\corpol.dll Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\custsat.dll Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\ieakmmc.chm Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\ieapfltr.dat Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\ieeula.chm Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\iesupp.chm Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\iexplore.chm Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\inetcpl.cpl Object is locked skipped C:\557a3af6a15be0825fe00ac0cdb3\inetres.adm Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\$shtdwn$.req Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\common\Eula.txt Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\common\spcustom.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\common\spmsg.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\common\spuninst.exe Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\common\update.exe Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp1\msgsvc.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp1\update\KB828035.cat Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp1\update\update.inf Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp1\update\update.ver Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp1\wkssvc.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\msgsvc.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\spmsg.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\spuninst.exe Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\eula.txt Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\KB828035.cat Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\spcustom.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\update.exe Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\update.inf Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\update\update.ver Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\sp2\wkssvc.dll Object is locked skipped C:\c3bd89f92b44d9a8e54408a3\xpsp1hfm.exe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dae474ba7e66ff56e36b7a288018a9b2_0b3ba1cc-6cc2-4908-bfc6-7c060b542cde Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dae474ba7e66ff56e36b7a288018a9b2_6c43c994-9396-4709-961b-c0664ba2c2c9 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dae474ba7e66ff56e36b7a288018a9b2_fe847bf1-b8c6-4b1f-8e40-4c241ecb68a1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea563f5ed0b8ea72081a19b9b561dd25_c7baa9d6-3fc6-470e-93fd-56e9f098a635 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea563f5ed0b8ea72081a19b9b561dd25_fe847bf1-b8c6-4b1f-8e40-4c241ecb68a1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\Default User\Local Settings\Temp\SaveCmS.exe/Sync.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped C:\Documents and Settings\Default User\Local Settings\Temp\SaveCmS.exe/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped C:\Documents and Settings\Default User\Local Settings\Temp\SaveCmS.exe CAB: infected - 2 skipped C:\Documents and Settings\Default User\Local Settings\Temp\ss_cdt_setup.exe/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.e skipped C:\Documents and Settings\Default User\Local Settings\Temp\ss_cdt_setup.exe NSIS: infected - 1 skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS02462604-9FA7-4A47-80AE-6B76DE9CEB44.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS02542FEC-E2B9-4807-BF5E-E25A2B0CCE16.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS057DC623-11F7-4613-84B1-8C1473AFFE0B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS077C5C8B-866A-456C-BCF1-7356E2C70356.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1B577592-F645-460C-B1A3-C3AE28931AC0.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1D77C9EF-402B-4B8C-B4DB-8B6C8B83B277.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1EB514E4-663D-431C-96F4-70DFF8538FF3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25DFB558-2DAB-42CE-BA4A-6F4454FCB765.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2863981A-F1FB-43C5-A987-F24327BEAFF3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS312DC1DA-DA4F-4844-9DF2-5BB365B79125.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS35259F90-5436-416E-8399-79FA65319544.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3B21C425-E884-4B64-9E17-8C12E64D0C0D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3C9ADD39-9896-44A0-A71A-FB8C70B786F7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3ED5AF4D-03E1-4F05-8198-4D6D122AD247.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4128D82B-5915-45C3-8DA1-4FD26A3E6EB6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS452721E0-8C1A-4A39-B0DB-8853A00C1BB9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS491767B8-B597-4846-AD64-9A7FCA7DE84D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4A06486E-522F-4D01-A8E9-A8AB210A9017.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4A0E6ED0-8033-450F-B264-CA2A6EDD0DB3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4C124CC1-47A1-4E69-A847-9A6D64A329AE.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5047D5A2-1593-4B52-9560-DE22590D4371.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS52003849-453E-4708-BF30-744550351A60.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5495D4B3-AC41-4C44-9217-C5192D556854.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS572F54A8-89CE-43AC-A58E-21BE757F4DD6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS579357C6-B50E-4088-BC2B-FBBEA6B15C5C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5948988D-C09F-4BE0-8BCA-450CB617F84F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5A74BCD9-6984-408A-A27A-AD0CB20EF190.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60361142-A21A-47B4-B31B-C4B5F6E09DB3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS60F78810-628B-4BB7-B0CD-1CB350E118DA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS62AE42B6-C892-41F1-A445-4F560D0EB114.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS62C3DE0F-AD9F-43FE-99EF-FFA278DB920F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS63EAEA4E-1D5A-4DB3-AD13-2EF2877215E4.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS649B0C63-CCA3-4C83-B9A7-2632587566CB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS64D78A90-75B4-4772-8A0E-44258F374786.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6748DAB8-B00E-4D7B-8AC4-7F821FA363F3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6A8303D4-EBA5-4F2B-BC1A-CED9DEEE2264.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6C972DF5-5A2F-4A81-9124-B3E2EEB016F5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6E72C50A-334A-4AF9-8233-5051A50DB2EC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS712E4CEB-6E01-4A00-BF4A-86A3EA63EA5D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS74510F52-8F59-4433-8D7D-ADA8017DD00A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7C8160B4-0492-48C4-B4A0-03C23439EF1B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS81A390F0-34D9-47BC-82AC-A2448F73FF79.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS833B0E46-41D2-40E8-9225-E2C9F6342577.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8CA7CF74-5A6B-4537-857F-5BE4D78D2A52.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E190534-2539-4587-80DD-6B9236B20F05.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8EEBB129-EC21-41A7-9ED5-FE967D57B3F9.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9359850A-3EC9-4D13-9473-768BD45F9EBA.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS98928F47-C86E-4482-8D4A-19DDD9F56934.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS997B5F51-FEF1-464E-99E4-94C75B21A37A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9A4331CC-BCB0-4211-A9A0-F8B56A588442.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9CDDB217-2AAE-42DA-9809-D57E1BB030B3.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9E8CA5E9-57F2-4B40-B8A8-AD36EFD86A96.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9F298972-F0A5-4DA5-BE08-3E1D94A3A662.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA0FAEF23-AB2A-4776-902C-F416879B17A5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA133D327-ACE9-44DC-988E-F566673350D6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA512C58E-6E41-4176-A361-8213A49FE775.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA846BE8B-83AC-4FEF-8FE6-D86DB256780A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAAA31EBE-9B6C-4E51-97A0-FA986BB51265.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB442554C-7507-4C6C-95A0-AC184CC7717A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB73B3FEC-4416-4756-BBE6-9AC12782D0D6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB8818F3B-4D3F-4A31-960E-1D180ABBF002.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB9479B47-A5BF-4A86-9203-2D51E369E712.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBA668A0F-ACB9-4EEB-88B1-C9F23B4FEC08.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBACEDB33-B678-4631-B722-4C8B682F9C6D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC59FFB6D-10C3-43CF-9C54-3CA10BD0AEEC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC916CCFE-0049-492E-BE3A-21CF4B48AE8E.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC9FE942E-572B-4408-8B48-9A502055A6F6.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCB778FBC-46CB-4416-B04C-FC9F92841F94.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCD470AB2-9C79-488E-A0D5-AC8285194922.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCE122449-F6A2-4C3C-B7DB-0A35D174D972.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCF552145-17CC-4DBD-84FB-EA8F8D6294DB.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD0985CD6-11D1-41B7-9072-05B135AC317D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD1D453DC-728E-4840-86D5-47BF9B4F43D7.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD46B4FC6-78DD-423A-876D-8A94BD82C87B.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD500EB37-0026-426D-B090-FFB882A1952C.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD5A5844C-6B23-4214-AA3C-E1DA97AD336D.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD812BDA1-FC95-4CE9-AFB4-13363AE35A81.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDA00C104-1A8B-460E-949E-390CD8A0150F.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDB9F803D-B991-475A-8CDA-9105DD775596.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDFF5D071-1C1B-472A-9686-2F32D1A84922.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0061735-0546-4F5A-A072-822B6BEF9ACF.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE4CE6F0B-63A0-4064-B5CE-0DF4DB5D1DE1.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE5503D44-6767-416B-9942-FEA42FCDF494.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEF489A7A-EE09-49C8-8762-95D3874587CC.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEFB43ECA-8FB9-4A0D-B3F6-BD809AE93A67.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF0CC00AB-3D45-4F32-8FBE-2ACC5E6B4443.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF6CB202D-CEF2-4FEE-BEC9-EF6891B0D07A.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFA1D4EB0-4A0C-4287-9539-2C9D057500D5.tmp Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFF5DC3DA-FD89-4610-A2A0-38675715F221.tmp Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Application Data\acccore\nss\cert8.db Object is locked skipped C:\Documents and Settings\Owner\Application Data\acccore\nss\key3.db Object is locked skipped C:\Documents and Settings\Owner\Application Data\Webroot\Spy Sweeper\Logs\080206220545.ses Object is locked skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\AOL OCP\AIM\Storage\All Users\localStorage\common.cls Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\AOL OCP\AIM\Storage\data\stephmadd815\localStorage\common.cls Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\UROF8J6V\msx[1].htm Infected: Trojan-Downloader.JS.Agent.eo skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\cache.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\chandir.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\chandir.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\chn.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\chn.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\D0000000.FCS Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\inuse.txt Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\L0000005.FCS Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\main.log Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_die.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_die.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_dnd.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_dnd.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_ext.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_ext.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_rcv.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\prs_rcv.idx Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\storydb.dat Object is locked skipped C:\Program Files\hp center\137903\Users\Default\Data\storydb.idx Object is locked skipped C:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\Program Files\MySearch\bar\1.bin\S42NS.EXE Infected: not-a-virus:AdWare.Win32.MyWay.j skipped C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ao skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP170\A0029176.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039212.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039213.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039214.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039215.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039216.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039217.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039218.exe Infected: Trojan-Downloader.Win32.WinShow.r skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039219.dll Infected: Trojan.Win32.Kolweb.f skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039220.dll Infected: not-a-virus:AdWare.Win32.HotBar.bq skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039221.dll Infected: not-a-virus:AdWare.Win32.HotBar.bw skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039222.exe Infected: not-a-virus:AdWare.Win32.HotBar.bt skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP206\A0039223.dll Infected: not-a-virus:AdWare.Win32.Adstart.i skipped C:\System Volume Information\_restore{6CD01810-EFB9-4AF0-A405-DE07EB8CD51D}\RP207\change.log Object is locked skipped C:\WINDOWS\$NtUninstallKB824141$\kb824141.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828035$\kb828035.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\kb828741.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\kb837001.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped C:\WINDOWS\$NtUninstallQ828026$\q828026.cat Object is locked skipped C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped C:\WINDOWS\rtpmsi32.dll Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\1setup.exe/data0006 Infected: Trojan-Downloader.Win32.Adload.a skipped C:\WINDOWS\system32\1setup.exe NSIS: infected - 1 skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0001.cab/DnldStub.exe Infected: Trojan-Downloader.Win32.Small.kl skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0001.cab Infected: Trojan-Downloader.Win32.Small.kl skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0002.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.c skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0002.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0002.cab Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0003.cab/Search.exe Infected: not-a-virus:AdWare.Win32.SaveNow.l skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002/data0003.cab Infected: not-a-virus:AdWare.Win32.SaveNow.l skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0002 Infected: not-a-virus:AdWare.Win32.SaveNow.l skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0002/data0002 Infected: Trojan-Downloader.Win32.Keenval skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0002/data0004 Infected: Trojan-Downloader.Win32.Keenval skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0002/data0005 Infected: Trojan-Downloader.Win32.Keenval skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0002 Infected: Trojan-Downloader.Win32.Keenval skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0003 Infected: Trojan-Downloader.Win32.Keenval.e skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003/data0004 Infected: Trojan-Downloader.Win32.Keenval.e skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0003 Infected: Trojan-Downloader.Win32.Keenval.e skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0005 Infected: not-a-virus:AdWare.Win32.EZula.l skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0006 Infected: not-a-virus:AdWare.Win32.180Solutions skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0007 Infected: Trojan-Downloader.Win32.QDown.b skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe/data0008 Infected: not-a-virus:AdWare.Win32.PurityScan.h skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe NSIS: infected - 19 skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\SaveCmS.exe/Sync.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\SaveCmS.exe/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\SaveCmS.exe CAB: infected - 2 skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\ss_cdt_setup.exe/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.e skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\ss_cdt_setup.exe NSIS: infected - 1 skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05SFWFCZ\install_iframe[1].jsp Infected: Trojan-Downloader.JS.Agent.kk skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\21BOLSNE\install_iframe[1].jsp Infected: Trojan-Downloader.JS.Agent.kk skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\85YZ896J\WToolsB[1].cab/WToolsB.dll Infected: not-a-virus:AdWare.Win32.Wintol skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\85YZ896J\WToolsB[1].cab CAB: infected - 1 skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\ldnlrn65.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\Temp\pft32~tmp\PatchWr.exe Object is locked skipped C:\WINDOWS\Temp\pft36~tmp\PatchWr.exe Object is locked skipped C:\WINDOWS\Temp\RebootXP.exe Object is locked skipped C:\WINDOWS\Temp\Reginfo.ini Object is locked skipped C:\WINDOWS\Temp\RtlCPAPI.dll Object is locked skipped C:\WINDOWS\Temp\RTLCPL.exe Object is locked skipped C:\WINDOWS\Temp\scs377.tmp Object is locked skipped C:\WINDOWS\Temp\soundman.exe Object is locked skipped C:\WINDOWS\Temp\SPL140.tmp Object is locked skipped C:\WINDOWS\Temp\SPL3AF.tmp Object is locked skipped C:\WINDOWS\Temp\SPL681.tmp Object is locked skipped C:\WINDOWS\Temp\SPL723.tmp Object is locked skipped C:\WINDOWS\Temp\tmp000001da\tmp00000000 Object is locked skipped C:\WINDOWS\Temp\tmp0000554e\tmp00000000 Object is locked skipped C:\WINDOWS\Temp\upd123.exe Infected: not-a-virus:AdWare.Win32.Look2Me.as skipped C:\WINDOWS\Temp\WGANotify.settings Object is locked skipped C:\WINDOWS\Temp\WrSetupUtils.dll Object is locked skipped C:\WINDOWS\Temp\_ISTMP0.DIR\1084a246.DLL Object is locked skipped C:\WINDOWS\Temp\_ISTMP0.DIR\Bbrd1.BMP Object is locked skipped C:\WINDOWS\Temp\_ISTMP0.DIR\Bbrd2.BMP Object is locked skipped C:\WINDOWS\Temp\_ISTMP0.DIR\Bbrd5.BMP Object is locked skipped C:\WINDOWS\Temp\_ISTMP0.DIR\Dialog.bmp Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. I'm doing ok. everything has been running smoothly. Thanks for the help.
Glad to hear it's running better. Some files and folders to clean up found by Kaspersky.

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Default User\Local Settings\Temp\SaveCmS.exe CAB
    C:\Documents and Settings\Default User\Local Settings\Temp\ss_cdt_setup.exe
    C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\UROF8J6V\msx[1].htm
    C:\Program Files\MySearch
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll
    C:\WINDOWS\system32\1setup.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\SaveCmS.exe CAB
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\ss_cdt_setup.exe
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05SFWFCZ\install_iframe[1].jsp
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\21BOLSNE\install_iframe[1].jsp
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\85YZ896J\WToolsB[1].cab CAB
    C:\WINDOWS\system32\ldnlrn65.ini
    C:\WINDOWS\Temp\upd123.exe


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Close OTMoveIt
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


Click "Exit" to close OTMoveIt.


Reboot and post a new Hijackthis log for review.
File/Folder C:\Documents and Settings\Default User\Local Settings\Temp\SaveCmS.exe CAB not found. C:\Documents and Settings\Default User\Local Settings\Temp\ss_cdt_setup.exe moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Internet Files\Content.IE5\UROF8J6V\msx[1].htm moved successfully. C:\Program Files\MySearch\bar\Settings moved successfully. C:\Program Files\MySearch\bar\History moved successfully. C:\Program Files\MySearch\bar\Cache moved successfully. C:\Program Files\MySearch\bar\1.bin moved successfully. C:\Program Files\MySearch\bar moved successfully. C:\Program Files\MySearch moved successfully. C:\WINDOWS\Downloaded Program Files\popcaploader.dll unregistered successfully. C:\WINDOWS\Downloaded Program Files\popcaploader.dll moved successfully. C:\WINDOWS\system32\1setup.exe moved successfully. C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\all_files7.exe moved successfully. File/Folder C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\SaveCmS.exe CAB not found. C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\ss_cdt_setup.exe moved successfully. C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\05SFWFCZ\install_iframe[1].jsp moved successfully. C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\21BOLSNE\install_iframe[1].jsp moved successfully. File/Folder C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\85YZ896J\WToolsB[1].cab CAB not found. C:\WINDOWS\system32\ldnlrn65.ini moved successfully. C:\WINDOWS\Temp\upd123.exe moved successfully. OTMoveIt2 v1.0.19 log created on 02072008_193502
Logfile of HijackThis v1.99.1
Scan saved at 8:02:07 PM, on 2/7/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aim toolbar 5.0\AolTbServer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe"
O4 - HKLM\..\Run: [CamMonitor] "c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe" nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Zero Knowledge Freedom] "C:\Program Files\Zero Knowledge\Freedom\Freedom.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\ShadowBar.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.wbal.com
O16 - DPF: Canasta by pogo - http://game1.pogo.com/v/8.1.0.23/applet/ca…nasta-en_US.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/v/8.1.0.23/applet/ma…jong2-en_US.cab
O16 - DPF: No-Limit Texas Hold'em by pogo - http://game1.pogo.com/v/8.1.0.25/applet/al…allin-en_US.cab
O16 - DPF: Payday Freecell Solitaire by pogo - http://game1.pogo.com/v/8.1.0.23/applet/fr…cell2-en_US.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/v/8.1.0.23/applet/wa…wheel-en_US.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/v/8.1.0.23/applet/pe…peaks-en_US.cab
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/2…can_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by116fd.bay116.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Looks clean, still no antivirus. I would recommend you install an AV, update it, and run a full system scan, letting it fix anything it finds. Then I would go for service pack 2 if no other issues. Dave
tried to load sp2 disc and received the same message: ACCESS DENIED. Don't know what else to do. Could it be my manufacturer? I hate to have to call them because they never help, just charge me money. Maybe I'll just get a new computer and start over. Ha Thanks for all your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI