Active ScanAdware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OTE2NLS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CQUSALGO.DLL
Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM\ELITEGFS32.EXE
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\NSVSVC\NSVS.DLL
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM\ELITEG~1.EXE
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
Adware:Adware/SaveNow No disinfected Windows Registry
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM\exclean.exe
Adware:Adware/nCase No disinfected C:\Temp\FLEOK
Spyware:Spyware/AdClicker No disinfected Windows Registry
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\unstall.exe
Adware:Adware/CWS No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\polall1r.inf
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/TopConvert No disinfected C:\WINDOWS\Downloaded Program Files\mp3.ocx
Spyware:Spyware/YourSiteBar No disinfected C:\WINDOWS\Downloaded Program Files\YSBactivex.???
Spyware:Spyware/SurfSideKick No disinfected Windows Registry
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\EYENU.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\VDHELPER.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WYW32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SE_8M.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RGSAPI16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MLAFD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wgpshell.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CGMOCX.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInst.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WYADMOE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OKESVR32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DBDRG8X.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MAXBDE40.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AYCODC32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RDCLTC1.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wpp.dll
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\Nyblvq.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\Uvuxff.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\Udccue.exe
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\Dxkytc.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IZWDIAL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SXRIALUI.DLL
Adware:Adware/DealHelper No disinfected C:\WINDOWS\SYSTEM\Ownlix.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AMMUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DWSENH.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MEPWL32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\zmib.dll
Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM\elitegfs32.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM\temperror32.dat
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NRTOS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IDROP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SBDOCLC.DLL
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\vidctrl\vidctrl.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SII.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\APMUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WTADMOD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DFCVW_32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\GIU32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\lvqp7c25q.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IZS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wep.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MWVCRT40.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MZCUIA32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CCMOCX.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WJNMM.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ZUPFLDR.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WON87EM.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OOBC32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DDNMPNTW.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PQWEROLD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\VRDX16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DGDRGBXF.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CQUSALGO.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OTE2NLS.DLL
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsvs.dll
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsv.ocx
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MRR.DLL
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM\exclean.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM\2r5qf5lt.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mtvbvm60.dll
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\POLALL1R.INF
Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\unstall.exe
Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\Downloaded Program Files\m67m.ocx
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.inf
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\installer_VENDARE3.exe
Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.inf
Adware:Adware/WinAD No disinfected C:\WINDOWS\Downloaded Program Files\MediaPassX.dll
Adware:Adware/EliteBar No disinfected C:\WINDOWS\Downloaded Program Files\OSD149F.OSD
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\installer_VENDARE3.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.3\installer_VENDARE3.exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.3\YSBactivex.dll
Spyware:Spyware/YourSiteBar No disinfected C:\WINDOWS\Downloaded Program Files\ysbactivex.inf
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\Downloaded Program Files\installer_VENDARE3.exe
Adware:Adware/TopConvert No disinfected C:\WINDOWS\Downloaded Program Files\mp3.ocx
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\Downloaded Program Files\ysbactivex.dll
Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\Downloaded Program Files\m67m.inf
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\setup4002b.ini
Spyware:Spyware/SurfSideKick No disinfected C:\WINDOWS\SSK3_B5_SSK3_B5.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\blocklist.reg
Adware:Adware/nCase No disinfected C:\WINDOWS\salm_kyf.dat
Adware:Adware/nCase No disinfected C:\WINDOWS\salmau.dat
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\joyiconsbbb.exe
Adware:Adware/DelFinMedia No disinfected C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows FormatAd\WinFormKeep.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Windows FormatAd\WinForm.exe
Adware:Adware/nCase No disinfected C:\temp\salmau.dat
Hijack ThisLogfile of HijackThis v1.99.1
Scan saved at 9:03:25 PM, on 6/17/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\ELITEGFS32.EXE
C:\WINDOWS\SYSTEM\NSVSVC\NSVSVC.EXE
C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [checkrun] C:\WINDOWS\SYSTEM\ELITEGFS32.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [ccleaner] "C:\PROGRAM FILES\CCLEANER\CCLEANER.exe" /AUTO
O4 - Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real...ArcadeRdxIE.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.c...utocomplete.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/pote_x.cabO16 - DPF: {90918C20-FB99-495A-BD79-CB91ACF44887} -
http://www.typingmas...ick/TMSetup.cabO16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) -
http://rd1.surfernet...urferplugin.ocxO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.co...aploader_v6.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabO16 - DPF: {8DA664DC-123E-4836-B7B3-6653A8B082AB} (ChatOCX Control) -
http://www.igl.net/c...ChatOCXProj.cabO16 - DPF: {64D01C7F-810D-446E-A07E-16C764235644} (AtlAtomadersCtlAttrib Class) -
http://zone.msn.com/...t/atomaders.cabO16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) -
http://zone.msn.com/...WebLauncher.cabO16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) -
http://zone.msn.com/...pandaonline.cabO16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) -
http://dlmanager.aka...vex-2.0.2.7.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.ao.../ampx_en_dl.cabO16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} -
http://www.ysbweb.co...ysb_1002952.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...ebscan_ansi.cabO16 - DPF: {7149E79C-DC19-4C5E-A53C-A54DDF75EEE9} (IObjSafety.DemoCtl) -
http://cabs.media-mo...bs/joysaver.cab