This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Clean infections or wipe hard drive?

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A friend asked me to check out a computer that is often locking up and runs CD's at the wrong speed. It has very few documents or programs on it. I did some preliminary checks and it is a mess- Windows XP SP1!, run on the internet a few years ago with neither firewall nor virus protection. The Lavasoft defs are more than 900 days old. I ran AVG Anti-Spyware- scan only. It shows over 200 infections including worm Welchia.b, multiple downloaders, backdoors, trojans, Rootkit.Agent.O, and something suspicious in the trusted zone. :pullhair: My friend is searching for her installation disks, in case we take the wipe option. I am concerned that it could have a boot sector virus and would like guidance in the quickest, easiest way to heal this sick machine. I am attaching my Hijackthis log and AVG log. Thank you for your help.-Jcatsmom

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:06 AM, on 2/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\aim.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\lsass.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\system12.exe
C:\windows\adtech2005.exe
C:\WINDOWS\System32\Lcuninst.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Laura Whipple\Desktop\computer tools\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Microsoft Windows 128bit Subsystem] C:\WINDOWS\System32\system12.exe
O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe
O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe
O4 - HKLM\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKUS\S-1-5-18\..\Run: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [kquz] C:\PROGRA~1\COMMON~1\kquz\kquzm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows Processe Manager] mspn32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\p4r40e9qeh.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe

–
End of file - 4439 bytes


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:27:44 AM 2/26/2008

+ Scan result:



C:\Documents and Settings\Laura Whipple\Local Settings\Temp\180sainstaller.exe/clientax.dll -> Adware.180Solutions : Ignored.
C:\WINDOWS\Temp\180sainstallernu.exe/clientax.dll -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller.1 -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Adware.180Solutions : Ignored.
C:\Program Files\Aprps -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\AI_22-08-2005.log -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.exe -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ProxyStub.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\WinGenerics.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ace.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\data.bin -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\libexpat.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\uninstaller.exe -> Adware.Apropos : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\thin-143-1-x-x[1].exe -> Adware.BetterInternet : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049309.exe -> Adware.CommAd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049314.DLL -> Adware.CommAd : Ignored.
HKLM\SOFTWARE\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update\actalert.exe -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-21-329068152-2111687655-1957994488-1004\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\installer[1].exe -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0000.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041299.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048304.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049318.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0050319.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\HZF_INST.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\SELSRV32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\anptif.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\csb.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dirgres.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dlound.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\drsapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\en22l1fo1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl2l13o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl6l13s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ennml1511.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp2l17o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp6l17s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ess.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\g4jo0e13eh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\gctuname.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i6lolg3316.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iGshlpr.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iLsrecst.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iketmib1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j0j6la1s1d.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0080adued080.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0js0a17ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kcdsf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdcz2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kidtuf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kt2ul7f91.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ktdhela2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l0j80a1ued.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4p20e7oeh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4r00e9meh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ljazutil.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\maisip.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mbd32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mewsock.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mfpmspsv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhcpx32r.dLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\miwmdmsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mkconf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\moacm32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mviseq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mxmefilt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nMlanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nalanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ndmarta.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nginstnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nirsja.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nmxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nnprint.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nstlogon.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nutui0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nuxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nyptools.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o0480ahued480.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\oibc16gt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p24ulch91f4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pbwrprof.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pcrfproc.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pih.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\puspl.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q668lgju16o8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rLssapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rbcdll.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rehx32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rvchost.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rycns4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sfbcsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sqtupapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sumapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sximgvw.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sydpsrv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\szc_os.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\t48u0el9ehq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\tapmonui.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ukdmxfrm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\vtmdbg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wfninet.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wghatm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wpwfaxui.dll -> Adware.Look2Me : Ignored.
C:\installer.exe -> Adware.Look2Me : Ignored.
[1128] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
[1548] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\seeve[1].exe -> Adware.MediaMotor : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\mm63[1].ocx -> Adware.MediaMotor : Ignored.
C:\WINDOWS\mm63.ocx -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl\Clsid -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Ignored.
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Ignored.
HKLM\SOFTWARE\VGroup\SAHAgent -> Adware.SAHA : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temp\1CCPRAB8.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\bundle_mediamotor1004[1].exe -> Adware.Sahat : Ignored.
C:\WINDOWS\Temp\9JIK1H9M.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\drsmartload[1].exe -> Adware.SmartLoad : Ignored.
C:\drsmartload1.exe -> Adware.SmartLoad : Ignored.
C:\Program Files\Common Files\kquz\kquzd\kquzc.dll -> Adware.TargetServer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Ignored.
C:\Program Files\TheSearchAccelerator -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\INSTALL.LOG -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\IUCmore.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UNWISE.EXE -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\logo.ico -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\toolbar.cfg -> Adware.UCmore : Ignored.
C:\UCmore - The Search Accelerator\How To Uninstall.lnk -> Adware.Ucmore : Ignored.
C:\UCmore - The Search Accelerator\UCmore Tour.lnk -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/empty_00000001 -> Adware.Ucmore : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCmore - The Search Accelerator -> Adware.UCmore : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\41UBCD2P\iesetup6b[1].exe -> Adware.WinAD : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\69IBC3CN\iesetup6a[1].exe -> Adware.WinAD : Ignored.
C:\ad.exe -> Adware.WinAD : Ignored.
C:\ada.exe -> Adware.WinAD : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\unstall[1].exe -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent.1 -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CLSID -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CurVer -> Adware.Zango : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049310.exe -> Backdoor.Codbot.al : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049315.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP1964 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP308 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\mspn32.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\eraseme_50661.exe -> Backdoor.Rbot.aad : Ignored.
C:\WINDOWS\system32\TFTP2256 -> Backdoor.Rbot.adf : Ignored.
C:\WINDOWS\system32\TFTP1128 -> Backdoor.Rbot.c : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049308.exe -> Backdoor.SdBot.xd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049311.exe -> Backdoor.SdBot.xd : Ignored.
C:\WINDOWS\system32\eraseme_46480.exe -> Backdoor.SdBot.xd : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\drsmartload106a[1].exe -> Downloader.Adload.j : Ignored.
C:\dolrz.exe -> Downloader.Adload.j : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temporary Internet Files\Content.IE5\WHGD05YV\actalert[1].exe -> Downloader.Dyfuca.dp : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\optimize[1].exe -> Downloader.Dyfuca.ei : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049312.exe -> Downloader.Dyfuca.ei : Ignored.
C:\WINDOWS\optimize.exe -> Downloader.Dyfuca.ei : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\xtc[1].exe -> Downloader.Small.aqt : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stubinstaller6282[1].exe -> Downloader.Small.asf : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\mte3ndi6odoxng[1].exe -> Downloader.Small.buy : Ignored.
C:\mte3ndi6odoxng.exe -> Downloader.Small.buy : Ignored.
C:\Program Files\Common Files\kquz\kquzp.exe -> Downloader.TSUpdate.f : Ignored.
C:\Program Files\Common Files\kquz\kquzd\vocabulary -> Downloader.TSUpdate.j : Ignored.
C:\Program Files\Common Files\kquz\kquza.exe -> Downloader.TSUpdate.l : Ignored.
C:\Program Files\Common Files\kquz\kquzm.exe -> Downloader.TSUpdate.n : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stub_113_4_0_4_0[1].exe -> Downloader.TSUpdate.o : Ignored.
C:\stub_113_4_0_4_0.exe -> Downloader.TSUpdate.o : Ignored.
C:\Program Files\Common Files\kquz\kquzl.exe -> Downloader.TSUpdate.p : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[1].exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[2].exe -> Downloader.VB.jl : Ignored.
C:\mmxmetal.exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\timessquare[1].exe -> Hijacker.StartPage.aw : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049323.exe -> Hijacker.StartPage.aw : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[1].exe -> Proxy.Ranky : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[2].exe -> Proxy.Ranky : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049317.EXE -> Proxy.Ranky : Ignored.
C:\prox.exe -> Proxy.Ranky : Ignored.
C:\FOUND.005\FILE0003.CHK -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041303.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0042302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0043302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0044302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0045302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0046302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0047302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048308.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049307.sys -> Rootkit.Agent.o : Ignored.
C:\WINDOWS\system32\rdriv.sys -> Rootkit.Agent.o : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura [removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][4].txt -> TrackingCookie.Msn : Ignored.
D:\Documents and Settings\laura whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Shopathomeselect : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\contextplus[1].exe -> Trojan.Crypt.t : Ignored.
C:\contextplus.exe -> Trojan.Crypt.t : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\teller2[1].htm -> Trojan.Small : Ignored.
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\n3IYwAH0pZ1DwJ1Ptk.vbs -> Trojan.Small : Ignored.
C:\WINDOWS\teller2.chk -> Trojan.Small : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\adtech2005[1].exe -> Trojan.VB.afn : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049316.exe -> Trojan.VB.afn : Ignored.
C:\WINDOWS\system32\drivers\svchost.exe -> Worm.Welchia.b : Ignored.


::Report end
Boot sector viruses aren't that common any more, so i'd be more concerned with what you can see than what you can't. That much slime means the time that will need to be invested plus the possibility of it being wasted equals one choice - reformat and reinstall. No AV and a couple of years of missing patches is a recipe for disaster and it's easier, quicker and safer to start over with a fresh install.
Backdoor.SdBot.xd is a trojan that was written to create a backdoor, no surprise there, that gives somebody the same access to the PC as they would have if they were sat in front of it. The chance that system files have been corrupted or replaced and security settings lowered makes it a prime candidate for reinfection even if it is possible to dig out all the slime that has been picked up, which it may not be.
Sorry it isn't better news but if it was mine, it would have already been wiped.
Noviciate- Thank you for looking over my logs. I kind of expected your answer. Someone sent me a link to download Linux and create and OP system installation disk with it. If my friend can't find her Windows disks, what do you think of this as an option? I've not worked with Linux before. :unsure:
Thanks!- Jcatsmom
This isn't really my area, but I have had a play with a previous version of Ubuntu - http://www.ubuntu.com/products/whatisubuntu The advantage this one has over some is that you can play with it before you install it by creating a disc image and just booting from it - the speed will be slower than with a hard drive based OS due to different access times with a CD Rom, but it will give your friend a taste without having you go to too much trouble. All you need to do then, assuming that this version is the same as the one I played with, is to click the Install icon on the Desktop and let it do it's thing.
The one issue that I had was with drivers for my wireless kit, which is unfortunately one of the problems with open source software, but the latest Ubuntu has apparently been improved in the area of drivers.
I'd give the live CD a go and see what you think as unless you like to tweak, or need to, it works without much user involvement. If it does need some hand holding there are quite a few forums that can offer help, but it is up to you whether you have the patience to work through any issues.
As Firefox comes as standard, as long as you can get it online, surfing is good out of the box, and that's always a good place to start.
Noviciate- Thanks for your suggestion about Ubuntu. I'm seeing if Microsoft will do anything for us about a replacement CD. We'll go from there. I appreciate your help. You may close the topic now, if you'd like to.- Jcatsmom :notworthy:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI