Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Help....Aurora Pop-Ups [RESOLVED]


  • This topic is locked This topic is locked

#1
doh_nuts

doh_nuts

    New Member

  • Member
  • Pip
  • 6 posts
I'm another one that is having problems with nasty pop ups....please help. Here is my Hijack This log. Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 3:56:56 PM, on 6/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\lxbtcoms.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
C:\Program Files\Pgfslw\Lomnxx.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\Aaaqyg.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\windows\system32\nvevkh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...31518313&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...31518313&id=5.0
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox.com/en-US/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...65676883&id=5.0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotf...ount_id=1000834
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...65676883&id=5.0
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - (no file)
O2 - BHO: NavErrRedir Class - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [Internet Optimizer] C:\Program Files\Internet Optimizer\update\optimize313.exe
O4 - HKLM\..\Run: [Cvgraom] C:\Program Files\Pgfslw\Lomnxx.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [BOBDAuOO] C:\WINDOWS\ikjre.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\Dtlbcu.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Aaaqyg.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [acjukna] c:\windows\system32\nvevkh.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll//iemenu
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash...ers/SAXFile.cab
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/...pandaonline.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_1.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolba...006_regular.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://wdownload.wea...uginstaller.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://www.blowsearc...er_Enhancer.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...4.48/ttinst.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://bannerfarm.ac...r1123030429.exe
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/p.../v13/ticker.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O18 - Protocol: ayb - {07C0D34D-11D7-43F7-832B-C6BB41726F5F} - C:\DOCUME~1\CHRIST~1\APPLIC~1\zllqueenanv.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please download Nailfix from here:
http://www.noidea.us...050515010747824
Unzip it to the desktop but please do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml


Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Next please run HijackThis, click Scan, and check:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HijackThis and click Fix Checked.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
  • 0

#3
doh_nuts

doh_nuts

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
ok. Here are the new logs.

Hijack This:

Logfile of HijackThis v1.99.1
Scan saved at 6:59:29 PM, on 6/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
C:\Program Files\Pgfslw\Lomnxx.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\WINDOWS\system32\Aaaqyg.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
c:\windows\system32\tsyksw.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...31518313&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...31518313&id=5.0
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox.com/en-US/default.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...65676883&id=5.0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotf...ount_id=1000834
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...65676883&id=5.0
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - (no file)
O2 - BHO: NavErrRedir Class - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [Internet Optimizer] C:\Program Files\Internet Optimizer\update\optimize313.exe
O4 - HKLM\..\Run: [Cvgraom] C:\Program Files\Pgfslw\Lomnxx.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [BOBDAuOO] C:\WINDOWS\ikjre.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\Dtlbcu.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Aaaqyg.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [nzcnewv] c:\windows\system32\tsyksw.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll//iemenu
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash...ers/SAXFile.cab
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/...pandaonline.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_1.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolba...006_regular.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://wdownload.wea...uginstaller.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://www.blowsearc...er_Enhancer.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...4.48/ttinst.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://bannerfarm.ac...r1123030429.exe
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/p.../v13/ticker.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O18 - Protocol: ayb - {07C0D34D-11D7-43F7-832B-C6BB41726F5F} - C:\DOCUME~1\CHRIST~1\APPLIC~1\zllqueenanv.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe





EWIDO:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:48:56 PM, 6/5/2005
+ Report-Checksum: 380E0FCB

+ Date of database: 6/5/2005
+ Version of scan engine: v3.0

+ Duration: 118 min
+ Scanned Files: 142930
+ Speed: 20.03 Files/Second
+ Infected files: 467
+ Removed files: 0
+ Files put in quarantine: 0
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\Documents and Settings\Christine\Application Data\zllqueenanv.dll -> Spyware.Lop -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@18938953[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@237246[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@35487201[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@41409448[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@45813911[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@86254376[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@a.websponsors[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@adknowledge[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ads.addynamix[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ads.adsag[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ads.as4x.tmcs[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ads.businessweek[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ads.monster[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@adserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@adsremote.scripps[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@adv.webmd[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@advertising[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@articles.health.msn[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@atdmt[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@bcentral[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@bfast[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@bilbo.counted[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@bluestreak[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@bravenet[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@burstnet[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@buy.rpts[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@cgi-bin[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@cgi-bin[3].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@clickagents[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@com[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@counter.hitslink[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@counter2.hitslink[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ctx[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@data.coremetrics[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@dcsp2u8wocydgsl4ukg1ydkws_8x5k[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@dcsyguctyqljwppi8dfri3h3q_9x3n[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-aha.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-bestbuy.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-cbs.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-console.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-dig.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-findlaw.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-foxsports.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-futuredontics.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-inforspaceinc.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-kodak.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-kohls.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-lowermybills.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-nestleusainc.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-theviptour.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-traderelectronicmedia.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-uniontrib.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg-zoomerang.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@ehg.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@fastclick[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@geocities[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@hb.lycos[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@hc2.humanclick[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@hits.411web[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@html[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@landing.domainsponsor[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@linksynergy[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@link[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@mediaplex[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@overture[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@perf.overture[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@p[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@realmedia[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@real[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S002-00-7-28-167600-20431[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S005-01-9-4-275581-101357[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S109821[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S119579[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S132930[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S144370[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@S149285[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@search.msn[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@servedby.advertising[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@server.iad.liveperson[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@statse.webtrendslive[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@targetnet[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@theobserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@tribalfusion[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@tvplex.go[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@twci.coremetrics[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@valueclick[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@valueclick[3].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@web4.realtracker[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@www.burstnet[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@www.eadexchange[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@www.myaffiliateprogram[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@www.shopathomeselect[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Cookies\christine@zedo[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\AEL\aurareco.exe -> Spyware.BetterInternet -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\alchem.exe -> TrojanDownloader.Alchemic -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\BTGrab.dll -> Spyware.DlMax.a -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\btgupg.exe -> Spyware.BetterInternet -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@a.websponsors[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ads.adsag[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ads.specificclick[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ads.specificpop[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ads4.clearchannel[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@adsremote.scripps[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@adv.webmd[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@advertising[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@atdmt[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@bfast[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@bilbo.counted[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@blackhawkstriker[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@bluestreak[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@bravenet[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@clickagents[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@commission-junction[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ctx[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@data.coremetrics[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@dcsajnkbj11e5hmi283hr30a8_2c7p[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ehg-aol.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ehg-bestbuy.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ehg-cbs.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@ehg-dig.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@gator[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@geocities[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@hg1.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@linksynergy[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@link[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@mediaplex[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@media[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@orbitz.rpts[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@perf.overture[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@real[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@S005-01-9-4-275581-101357[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@S121753[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@S136907[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@search.msn[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@server.iad.liveperson[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@specificpop[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@statse.webtrendslive[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@tmpad[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@web4.realtracker[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@websearch[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@www.picturepeople[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@xml2.trafficsyndicate[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Cookies\christine@zedo[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\dealhelper.exe -> TrojanDownloader.Agent.hw -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\djebmm350.exe -> Spyware.TopMoxie -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\ICD1.tmp\SNDbMark.dll -> Spyware.SaveNow.n -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\iinstall.exe -> TrojanDownloader.IstBar.jj -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\jab66.exe -> Dialer.Generic -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\jkill.exe -> Spyware.VX2 -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\MSView.dll -> Trojan.KeyHost.e -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\MSVprep.exe -> Spyware.BiSpy.r -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\polall1b.exe -> Trojan.Agent.ay -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\polall1m.exe -> TrojanDownloader.Agent.ae -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\polmx.exe -> TrojanDownloader.Agent.ae -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\preInsTT.exe -> Trojan.KeyHost.e -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\randreco.exe -> Spyware.BetterInternet -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\Sentry.exe -> TrojanDownloader.Stubby.b -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\sidefind.exe -> TrojanDownloader.IstBar.jd -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\syn_reco.exe -> Spyware.BetterInternet -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\THI2068.tmp\BTGrab.dll -> Spyware.BiSpy.t -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\THI2068.tmp\polall1b.exe -> TrojanDropper.Small.pv -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\THI4A3D.tmp\polall1r.exe -> TrojanDownloader.Agent.ae -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\THI5161.tmp\polall1r.exe -> TrojanDownloader.Agent.ae -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\THI714F.tmp\gsim.dll -> Spyware.Visicom -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\TKa04876\enhupdt.exe -> TrojanDownloader.Agent.gz -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\twaintec.dll -> Spyware.BiSpy.t -> Ignored
C:\Documents and Settings\Christine\Local Settings\Temp\wupdt.exe -> TrojanDownloader.Intexp -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@a.websponsors[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@ads18.bpath[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@adserv.internetfuel[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@advertising[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@atdmt[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@bfast[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@cgi-bin[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@data.coremetrics[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@ehg-bestbuy.hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@fastclick[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@hitbox[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@p[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@realmedia[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@servedby.advertising[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@spylog[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@tribalfusion[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Cookies\edward rosikiewicz@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\cln407.tmp -> TrojanDownloader.Dyfuca.dp -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\cln40C.tmp -> TrojanDownloader.Dyfuca.de -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\Del40D.tmp -> Spyware.180Solutions -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\DelE.tmp -> Spyware.180solutions -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\iinstall.exe -> TrojanDownloader.IstBar.ji -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\sidefind.exe -> TrojanDownloader.IstBar.jd -> Ignored
C:\Documents and Settings\Edward Rosikiewicz\Local Settings\Temp\uninstall.exe -> TrojanDownloader.IstBar.gi -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@a.websponsors[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@adopt.hotbar[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@advertising[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@atdmt[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@dcsh96g8k11e5hm2y5e3gkcv5_3u8j[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@dcswkdum9pljwpslkirxaz7o5_7t5n[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@ehg-dig.hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@ehg-dig.hitbox[3].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@hitbox[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@hits.411web[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@realmedia[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@statse.webtrendslive[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@www.eadexchange[2].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@z1.adserver[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Cookies\rebecca@zedo[1].txt -> Spyware.Tracking-Cookie -> Ignored
C:\Documents and Settings\Rebecca\Local Settings\Temp\randreco.exe -> Spyware.BetterInternet -> Ignored
C:\Documents and Settings\Rebecca\Local Settings\Temporary Internet Files\Content.IE5\HYLC2KXN\istrecover[1].exe -> TrojanDownloader.IstBar.ij -> Ignored
C:\Documents and Settings\Rebecca\Local Settings\Temporary Internet Files\Content.IE5\HZRCV18Z\istsvc[1].exe -> TrojanDownloader.IstBar -> Ignored
C:\Program Files\Comet Systems\DM\bin\dmserver.exe -> Spyware.Cometsystems -> Ignored
C:\Program Files\Internet Optimizer\optimize.exe -> TrojanDownloader.Dyfuca.du -> Ignored
C:\Program Files\Internet Optimizer\update\rogue.exe -> Trojan.Small.cy -> Ignored
C:\Program Files\ISTsvc\istsvc.exe -> TrojanDownloader.IstBar -> Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe -> Spyware.NavExcel -> Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll -> Spyware.NavExcel -> Ignored
C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHUninstaller.exe -> Spyware.NavExcel -> Ignored
C:\Program Files\Pgfslw\Lomnxx.exe -> Trojan.Small.cy -> Ignored
C:\Program Files\SideFind\sfbho.dll -> Spyware.SideFind -> Ignored
C:\RECYCLER\NPROTECT\01653414.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01653415.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01653416.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01655446.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01655447.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01655448.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01656140.TXT -> Spyware.Tracking-Cookie -> Ignored
C:\RECYCLER\NPROTECT\01656880.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01656909.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01656911.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01656930.EXE -> Spyware.BetterInternet -> Ignored
C:\RECYCLER\NPROTECT\01657351.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01657445.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01657896.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01657905.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\NPROTECT\01658095.exe -> Trojan.Agent.cp -> Ignored
C:\RECYCLER\S-1-5-21-773119264-2106517767-3757435101-1007\Dc5\randreco.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP207\A0049198.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP208\A0049555.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP209\A0049668.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP209\A0049796.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP211\A0049873.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP211\A0049874.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP211\A0050002.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP213\A0050111.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP214\A0050330.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP215\A0050396.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP215\A0050564.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP219\A0050677.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP219\A0050678.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP220\A0051102.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP221\A0051181.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP221\A0051257.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP222\A0052289.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP222\A0053287.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP223\A0053506.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP226\A0053625.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP226\A0053627.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP227\A0053908.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP228\A0054006.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP229\A0054056.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP231\A0054263.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP231\A0054310.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP232\A0054463.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP233\A0054651.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP236\A0055290.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP237\A0055310.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP237\A0055311.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP238\A0055442.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP239\A0055656.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP239\A0055745.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP240\A0055774.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP241\A0055970.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP244\A0056043.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP244\A0056044.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP245\A0056145.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056300.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056327.exe -> Trojan.Popmon.a -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056328.dll -> Spyware.DealHelper.ab -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056358.exe -> Spyware.180Solutions -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056362.dll -> Spyware.180solutions -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056395.exe -> TrojanDownloader.Dyfuca.dp -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056396.exe -> TrojanDownloader.Dyfuca.dp -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056462.exe -> Spyware.SAHA -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056469.dll -> Spyware.YourSiteBar.c -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056477.exe -> Spyware.BetterInternet -> Ignored
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP246\A0056595.EXE -> Spyware.PowerScan.d -> Ignored
C:\System
  • 0

#4
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
1. Make sure your PC is set to show all hidden files and folders go here for instructions on how to do this. http://www.xtra.co.n...1916458,00.html

2. Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

3. Go to Start > Settings > Add/Remove and uninstall the following.

Internet Optimizer
NavExcel
ISTsvc

4. While still in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...31518313&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...31518313&id=5.0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...65676883&id=5.0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotf...ount_id=1000834
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...65676883&id=5.0
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...65676883&id=5.0
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - (no file)
O2 - BHO: NavErrRedir Class - {0026AD90-C86F-4269-97F3-DAB4897C6D06} - (no file)
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll
O4 - HKLM\..\Run: [DM_Server] C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [Internet Optimizer] C:\Program Files\Internet Optimizer\update\optimize313.exe
O4 - HKLM\..\Run: [Cvgraom] C:\Program Files\Pgfslw\Lomnxx.exe
O4 - HKLM\..\Run: [BOBDAuOO] C:\WINDOWS\ikjre.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\system32\Dtlbcu.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Aaaqyg.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [nzcnewv] c:\windows\system32\tsyksw.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolba...006_regular.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} - http://wdownload.wea...uginstaller.cab
O16 - DPF: {A1DC3241-B122-195F-B21A-000000000000} - http://www.blowsearc...er_Enhancer.exe
O16 - DPF: {D9EC0A76-03BF-11D4-A509-0090270F86E3} - http://bannerfarm.ac...r1123030429.exe
O18 - Protocol: ayb - {07C0D34D-11D7-43F7-832B-C6BB41726F5F} - C:\DOCUME~1\CHRIST~1\APPLIC~1\zllqueenanv.dll
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

5. Delete the folders. (if present)

C:\Program Files\NavExcel
C:\Program Files\Internet Optimizer
C:\Program Files\Pgfslw
C:\Program Files\ISTsvc
C:\Program Files\Ebates_MoeMoneyMaker
C:\Program Files\COMETS~1\ < Folder starts with COMETS

6. Delete the files. (if present)

C:\WINDOWS\Nail.exe
C:\WINDOWS\alchem.exe
C:\WINDOWS\satmat.exe
C:\WINDOWS\ikjre.exe
C:\WINDOWS\system32\Dtlbcu.exe
C:\WINDOWS\system32\Aaaqyg.exe
c:\windows\system32\tsyksw.exe

7. Reboot and post a new Hijackthis log here in a reply.
  • 0

#5
doh_nuts

doh_nuts

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
here is the new log.



Logfile of HijackThis v1.99.1
Scan saved at 8:18:03 PM, on 6/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
c:\windows\system32\pznrqj.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox.com/en-US/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Sentry] C:\WINDOWS\Sentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [hiudmle] c:\windows\system32\pznrqj.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll//iemenu
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash...ers/SAXFile.cab
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/...pandaonline.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_1.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...4.48/ttinst.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/p.../v13/ticker.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#6
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
1. Make sure your PC is set to show all hidden files and folders go here for instructions on how to do this. http://www.xtra.co.n...1916458,00.html

2. Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

3. While in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

O4 - HKLM\..\Run: [hiudmle] c:\windows\system32\pznrqj.exe < Might of changed to another random name
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

4. Delete the folders. (if present)

C:\Program Files\Ebates_MoeMoneyMaker

5. Delete the files. (if present)

c:\windows\system32\pznrqj.exe < Might of changed to another random name
C:\WINDOWS\svcproc.exe

6. Reboot and post a new Hijackthis log here in a reply.
  • 0

#7
doh_nuts

doh_nuts

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
sorry it took so long. I was away on for a week. here is the new log. none of the files or folders you say to delete are comming up.

Logfile of HijackThis v1.99.1
Scan saved at 8:37:52 AM, on 6/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox.com/en-US/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll//iemenu
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash...ers/SAXFile.cab
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/...pandaonline.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_1.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...4.48/ttinst.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/p.../v13/ticker.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#8
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Go to start, run type "services.msc" with out the quotes find the service.

System Startup Service

Right click and stop it, make the start up type to disabled. When you have done that go into Hijackthis > open the misc tools section > delete an NT service and delete SvcProc. Then post a new Hijackthis log here in a reply.
  • 0

#9
doh_nuts

doh_nuts

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Here is the new log.

Logfile of HijackThis v1.99.1
Scan saved at 2:36:05 PM, on 6/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox.com/en-US/default.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm
O8 - Extra context menu item: Power Search - res://C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll//iemenu
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Go Fish - http://download.game...nts/y/zt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash...ers/SAXFile.cab
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/...pandaonline.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) - http://us.games2.yim...ctl_0_0_0_1.ocx
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com..._1/axofupld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...4.48/ttinst.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v5.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) - http://fdl.msn.com/p.../v13/ticker.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\GHOSTS~2.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#10
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Your log is clean :tazz:

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.

Credit to PGPhantom for canned speech.
  • 0

#11
doh_nuts

doh_nuts

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thank you for all the help.
  • 0

#12
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP