greyknight17 thanks for continued help,
cw shredder still crashed my system in the safe mode.
I forgot to mention to you that before you started helping me I had previously run cw shredder sucessfully in my own attempts to fix my problems.
You did not mention SpywareBlaster: do you recommend I keep that program installed?
Anyhow here are the logs:
ps Do want me to continue AB LogFile with everything or clean it before the next posting?
------------------------------------------------
Scan was ABORTED at 7:41:00 AM
AboutBuster 5.0 reference file 28
Scan started on [6/11/2005] at [8:19:08 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\aogqc.txt:rjcia
Removed Stream! C:\WINDOWS\clock.avi:jlhap
Removed Stream! C:\WINDOWS\comsetup.log:cifgr
Removed Stream! C:\WINDOWS\control.ini:vytufx
Removed Stream! C:\WINDOWS\GRACE.INI:buxvy
Removed Stream! C:\WINDOWS\iis6.log:nupocf
Removed Stream! C:\WINDOWS\ivexm.log:uplgo
Removed Stream! C:\WINDOWS\KB834707.log:mqelq
Removed Stream! C:\WINDOWS\KB885835.log:hmtpvm
Removed Stream! C:\WINDOWS\KB885835.log:khstd
Removed Stream! C:\WINDOWS\lhtbl.txt:sdwwbv
Removed Stream! C:\WINDOWS\msoffice(2).ini:uwcaag
Removed Stream! C:\WINDOWS\msoffice(3).ini:daupmk
Removed Stream! C:\WINDOWS\msoffice(3).ini:ojxok
Removed Stream! C:\WINDOWS\msoffice(4).ini:daupmk
Removed Stream! C:\WINDOWS\msoffice(4).ini:fpzfd
Removed Stream! C:\WINDOWS\ocgen.log:wddwe
Removed Stream! C:\WINDOWS\OEWABLog.txt:ayeqz
Removed Stream! C:\WINDOWS\orun32.ini:gvqfdh
Removed Stream! C:\WINDOWS\orun32.isu:gnmei
Removed Stream! C:\WINDOWS\orun32.isu:mpxin
Removed Stream! C:\WINDOWS\setupact.log:mjdaxw
Removed Stream! C:\WINDOWS\setupapi.del:opmmlz
Removed Stream! C:\WINDOWS\setupapi.del:qnipd
Removed Stream! C:\WINDOWS\setupapi.del:trbuy
Removed Stream! C:\WINDOWS\setuperr.del:fkwfrg
Removed Stream! C:\WINDOWS\setuperr.log:wnebo
Removed Stream! C:\WINDOWS\Sti_Trace.log:axbrd
Removed Stream! C:\WINDOWS\T30DebugLogFile.txt:uetrae
Removed Stream! C:\WINDOWS\TaxACT04.ini:amrdie
Removed Stream! C:\WINDOWS\TaxACT04.ini:qykklm
Removed Stream! C:\WINDOWS\tiagl.txt:qcaom
Removed Stream! C:\WINDOWS\tmnfs.log:tnkjkg
Removed Stream! C:\WINDOWS\wiaservc.log:xypprc
Removed Stream! C:\WINDOWS\WindowsUpdate.log:ymems
Removed Stream! C:\WINDOWS\winnt256.bmp:ehvmg
Removed Stream! C:\WINDOWS\wmsetup10.log:fxclgf
Removed Stream! C:\WINDOWS\WMSysPr9.prx:xvamz
Removed Stream! C:\WINDOWS\_default(10).pif:aldyy
Removed Stream! C:\WINDOWS\_default(11).pif:aldyy
Removed Stream! C:\WINDOWS\_default(12).pif:aldyy
Removed Stream! C:\WINDOWS\_default(13).pif:aldyy
Removed Stream! C:\WINDOWS\_default(14).pif:aldyy
Removed Stream! C:\WINDOWS\_default(2).pif:aldyy
Removed Stream! C:\WINDOWS\_default(3).pif:aldyy
Removed Stream! C:\WINDOWS\_default(4).pif:aldyy
Removed Stream! C:\WINDOWS\_default(5).pif:aldyy
Removed Stream! C:\WINDOWS\_default(6).pif:aldyy
Removed Stream! C:\WINDOWS\_default(7).pif:aldyy
Removed Stream! C:\WINDOWS\_default(8).pif:aldyy
Removed Stream! C:\WINDOWS\_default(9).pif:aldyy
Removed Stream! C:\WINDOWS\_default.pif:aefpte
Removed Stream! C:\WINDOWS\_default.pif:aldyy
Removed Stream! C:\WINDOWS\__delete_on_reboot__winqz32.dll:adjck
------------------------------------------------
Removed File! : C:\Windows\addso32.exe
Removed File! : C:\Windows\addvg32.exe
Removed File! : C:\Windows\addvz.exe
Removed File! : C:\Windows\addxy32.exe
Removed File! : C:\Windows\apiau.exe
Removed File! : C:\Windows\apibv.exe
Removed File! : C:\Windows\apicn32.exe
Removed File! : C:\Windows\apidq32.exe
Removed File! : C:\Windows\apifs32.exe
Removed File! : C:\Windows\apigy32.exe
Removed File! : C:\Windows\apike32.exe
Removed File! : C:\Windows\apilb32.exe
Removed File! : C:\Windows\apiqu32.exe
Removed File! : C:\Windows\apirq.exe
Removed File! : C:\Windows\apiuv32.exe
Removed File! : C:\Windows\apiyd32.exe
Removed File! : C:\Windows\apizo.exe
Removed File! : C:\Windows\appaf32.exe
Removed File! : C:\Windows\appbn32.exe
Removed File! : C:\Windows\appeg32.exe
Removed File! : C:\Windows\appgu32.exe
Removed File! : C:\Windows\apphz32.exe
Removed File! : C:\Windows\appjp32.exe
Removed File! : C:\Windows\appnd32.exe
Removed File! : C:\Windows\apppa32.exe
Removed File! : C:\Windows\apppt.exe
Removed File! : C:\Windows\apppx32.exe
Removed File! : C:\Windows\apppy.exe
Removed File! : C:\Windows\atlbh.exe
Removed File! : C:\Windows\atlej.exe
Removed File! : C:\Windows\atlhl32.exe
Removed File! : C:\Windows\atljj32.exe
Removed File! : C:\Windows\atlkk32.exe
Removed File! : C:\Windows\atlpz.exe
Removed File! : C:\Windows\atlqs32.exe
Removed File! : C:\Windows\atlsz32.exe
Removed File! : C:\Windows\atlth32.exe
Removed File! : C:\Windows\atlwe32.exe
Removed File! : C:\Windows\atlwq32.exe
Removed File! : C:\Windows\cran32.exe
Removed File! : C:\Windows\crde32.exe
Removed File! : C:\Windows\crfz32.exe
Removed File! : C:\Windows\crod32.exe
Removed File! : C:\Windows\crph.exe
Removed File! : C:\Windows\crqr32.exe
Removed File! : C:\Windows\crrs.exe
Removed File! : C:\Windows\crtj32.exe
Removed File! : C:\Windows\crtm32.exe
Removed File! : C:\Windows\crtx32.exe
Removed File! : C:\Windows\cruo.exe
Removed File! : C:\Windows\cruo32.exe
Removed File! : C:\Windows\crvz32.exe
Removed File! : C:\Windows\crww32.exe
Removed File! : C:\Windows\cyyfw.dll
Removed File! : C:\Windows\d3df32.exe
Removed File! : C:\Windows\d3el32.exe
Removed File! : C:\Windows\d3fs32.exe
Removed File! : C:\Windows\d3hk.exe
Removed File! : C:\Windows\d3mo.exe
Removed File! : C:\Windows\d3nd32.exe
Removed File! : C:\Windows\d3nq.exe
Removed File! : C:\Windows\d3oo32.exe
Removed File! : C:\Windows\d3ov.exe
Removed File! : C:\Windows\d3pv.exe
Removed File! : C:\Windows\d3qd32.exe
Removed File! : C:\Windows\d3qk32.exe
Removed File! : C:\Windows\d3ra.exe
Removed File! : C:\Windows\d3tu.exe
Removed File! : C:\Windows\d3xh.exe
Removed File! : C:\Windows\d3xi32.exe
Removed File! : C:\Windows\d3xl32.exe
Removed File! : C:\Windows\d3yl.exe
Removed File! : C:\Windows\eedmt.dll
Removed File! : C:\Windows\esgbw.dat
Removed File! : C:\Windows\gidji.dat
Removed File! : C:\Windows\hifxq.dat
Removed File! : C:\Windows\iejo32.exe
Removed File! : C:\Windows\ield.exe
Removed File! : C:\Windows\iema.exe
Removed File! : C:\Windows\iemg32.exe
Removed File! : C:\Windows\ieoa32.exe
Removed File! : C:\Windows\ieoj32.exe
Removed File! : C:\Windows\ietx.exe
Removed File! : C:\Windows\ieur.exe
Removed File! : C:\Windows\ievb32.exe
Removed File! : C:\Windows\iewe32.exe
Removed File! : C:\Windows\iewj.exe
Removed File! : C:\Windows\ieyg.exe
Removed File! : C:\Windows\iezm32.exe
Removed File! : C:\Windows\ipbe32.exe
Removed File! : C:\Windows\ipbi.exe
Removed File! : C:\Windows\ipbn32.exe
Removed File! : C:\Windows\ipjr.exe
Removed File! : C:\Windows\ipjw32.exe
Removed File! : C:\Windows\iplf32.exe
Removed File! : C:\Windows\ipnk.exe
Removed File! : C:\Windows\iprj.exe
Removed File! : C:\Windows\ipud.exe
Removed File! : C:\Windows\ipyn.exe
Removed File! : C:\Windows\javaca.exe
Removed File! : C:\Windows\javaeh.exe
Removed File! : C:\Windows\javaih.exe
Removed File! : C:\Windows\javaje.exe
Removed File! : C:\Windows\javajl32.exe
Removed File! : C:\Windows\javako32.exe
Removed File! : C:\Windows\javalh32.exe
Removed File! : C:\Windows\javasa32.exe
Removed File! : C:\Windows\javash.exe
Removed File! : C:\Windows\javask.exe
Removed File! : C:\Windows\javaux32.exe
Removed File! : C:\Windows\javave32.exe
Removed File! : C:\Windows\javavw32.exe
Removed File! : C:\Windows\javayy.exe
Removed File! : C:\Windows\kcavv.dat
Removed File! : C:\Windows\mduen.dll
Removed File! : C:\Windows\mfcah.exe
Removed File! : C:\Windows\mfcdf32.exe
Removed File! : C:\Windows\mfcdl.exe
Removed File! : C:\Windows\mfcdx32.exe
Removed File! : C:\Windows\mfces32.exe
Removed File! : C:\Windows\mfcge.exe
Removed File! : C:\Windows\mfcko.exe
Removed File! : C:\Windows\mfcpi.exe
Removed File! : C:\Windows\mfcqa.exe
Removed File! : C:\Windows\mfcri32.exe
Removed File! : C:\Windows\mfctm32.exe
Removed File! : C:\Windows\mfcuw.exe
Removed File! : C:\Windows\montc.dat
Removed File! : C:\Windows\msdn32.exe
Removed File! : C:\Windows\msfl.exe
Removed File! : C:\Windows\msfq.exe
Removed File! : C:\Windows\mske32.exe
Removed File! : C:\Windows\mskr32.exe
Removed File! : C:\Windows\msku.exe
Removed File! : C:\Windows\msop32.exe
Removed File! : C:\Windows\mssp.exe
Removed File! : C:\Windows\mstm.exe
Removed File! : C:\Windows\msxq.exe
Removed File! : C:\Windows\mszz32.exe
Removed File! : C:\Windows\nafzj.dat
Removed File! : C:\Windows\netbg32.exe
Removed File! : C:\Windows\netfn32.exe
Removed File! : C:\Windows\netgc32.exe
Removed File! : C:\Windows\netkl.exe
Removed File! : C:\Windows\netmo.exe
Removed File! : C:\Windows\netov32.exe
Removed File! : C:\Windows\netoz32.exe
Removed File! : C:\Windows\netqw32.exe
Removed File! : C:\Windows\netqx32.exe
Removed File! : C:\Windows\netrb.exe
Removed File! : C:\Windows\nettc32.exe
Removed File! : C:\Windows\netvy32.exe
Removed File! : C:\Windows\netyr.exe
Removed File! : C:\Windows\netzp.exe
Removed File! : C:\Windows\nftzf.dat
Removed File! : C:\Windows\ntcn.exe
Removed File! : C:\Windows\ntek.exe
Removed File! : C:\Windows\ntgp.exe
Removed File! : C:\Windows\ntih32.exe
Removed File! : C:\Windows\ntlr32.exe
Removed File! : C:\Windows\ntsx32.exe
Removed File! : C:\Windows\ntvb.exe
Removed File! : C:\Windows\ntxb.exe
Removed File! : C:\Windows\ntzq.exe
Removed File! : C:\Windows\qiwvt.dat
Removed File! : C:\Windows\rpksz.dat
Removed File! : C:\Windows\rwlfx.dat
Removed File! : C:\Windows\sdkfp.exe
Removed File! : C:\Windows\sdkio32.exe
Removed File! : C:\Windows\sdkjz32.exe
Removed File! : C:\Windows\sdkmb32.exe
Removed File! : C:\Windows\sdkpg.exe
Removed File! : C:\Windows\sdkpk32.exe
Removed File! : C:\Windows\sdkta.exe
Removed File! : C:\Windows\sdktd.exe
Removed File! : C:\Windows\sdkus.exe
Removed File! : C:\Windows\sdkwe32.exe
Removed File! : C:\Windows\sdkxd.exe
Removed File! : C:\Windows\sysao.exe
Removed File! : C:\Windows\sysdk.exe
Removed File! : C:\Windows\syshu.exe
Removed File! : C:\Windows\sysiu.exe
Removed File! : C:\Windows\sysje.exe
Removed File! : C:\Windows\sysje32.exe
Removed File! : C:\Windows\sysjo32.exe
Removed File! : C:\Windows\syskh32.exe
Removed File! : C:\Windows\syslw32.exe
Removed File! : C:\Windows\syswt32.exe
Removed File! : C:\Windows\ueeei.dat
Removed File! : C:\Windows\winbt32.exe
Removed File! : C:\Windows\wincq32.exe
Removed File! : C:\Windows\winsp.exe
Removed File! : C:\Windows\winvj32.exe
Removed File! : C:\Windows\winvq.exe
Removed File! : C:\Windows\winyw32.exe
Removed File! : C:\Windows\winzk32.exe
Removed File! : C:\Windows\zzpzp.dat
Removed File! : C:\Windows\System32\addbn32.exe
Removed File! : C:\Windows\System32\addbv32.exe
Removed File! : C:\Windows\System32\addci.exe
Removed File! : C:\Windows\System32\addew32.exe
Removed File! : C:\Windows\System32\addgb32.exe
Removed File! : C:\Windows\System32\addjy32.exe
Removed File! : C:\Windows\System32\addnl32.exe
Removed File! : C:\Windows\System32\addnt.exe
Removed File! : C:\Windows\System32\addpk32.exe
Removed File! : C:\Windows\System32\adduw.exe
Removed File! : C:\Windows\System32\addym32.exe
Removed File! : C:\Windows\System32\addzw32.exe
Removed File! : C:\Windows\System32\apiab32.exe
Removed File! : C:\Windows\System32\apifv.exe
Removed File! : C:\Windows\System32\apifw32.exe
Removed File! : C:\Windows\System32\apigk.exe
Removed File! : C:\Windows\System32\apiip.exe
Removed File! : C:\Windows\System32\apijp32.exe
Removed File! : C:\Windows\System32\apikm32.exe
Removed File! : C:\Windows\System32\apimh.exe
Removed File! : C:\Windows\System32\apims32.exe
Removed File! : C:\Windows\System32\apiqp32.exe
Removed File! : C:\Windows\System32\apirf32.exe
Removed File! : C:\Windows\System32\apito.exe
Removed File! : C:\Windows\System32\apium32.exe
Removed File! : C:\Windows\System32\apixl.exe
Removed File! : C:\Windows\System32\apixo.exe
Removed File! : C:\Windows\System32\apize32.exe
Removed File! : C:\Windows\System32\appdf.exe
Removed File! : C:\Windows\System32\appfc.exe
Removed File! : C:\Windows\System32\apphk32.exe
Removed File! : C:\Windows\System32\applz32.exe
Removed File! : C:\Windows\System32\appmo32.exe
Removed File! : C:\Windows\System32\appmy32.exe
Removed File! : C:\Windows\System32\appnb.exe
Removed File! : C:\Windows\System32\appph32.exe
Removed File! : C:\Windows\System32\apppo32.exe
Removed File! : C:\Windows\System32\appur.exe
Removed File! : C:\Windows\System32\appur32.exe
Removed File! : C:\Windows\System32\appzt32.exe
Removed File! : C:\Windows\System32\atles32.exe
Removed File! : C:\Windows\System32\atlgy32.exe
Removed File! : C:\Windows\System32\atlju.exe
Removed File! : C:\Windows\System32\atlni.exe
Removed File! : C:\Windows\System32\atlpa32.exe
Removed File! : C:\Windows\System32\atlur32.exe
Removed File! : C:\Windows\System32\axfjf.dll
Removed File! : C:\Windows\System32\bjaij.dll
Removed File! : C:\Windows\System32\cgfej.dat
Removed File! : C:\Windows\System32\cjzhe.dat
Removed File! : C:\Windows\System32\crbn32.exe
Removed File! : C:\Windows\System32\criz.exe
Removed File! : C:\Windows\System32\crmp.exe
Removed File! : C:\Windows\System32\crrv32.exe
Removed File! : C:\Windows\System32\crsp32.exe
Removed File! : C:\Windows\System32\cruu32.exe
Removed File! : C:\Windows\System32\crys.exe
Removed File! : C:\Windows\System32\crzt32.exe
Removed File! : C:\Windows\System32\crzy.exe
Removed File! : C:\Windows\System32\cwqbq.dat
Removed File! : C:\Windows\System32\cxlzy.dat
Removed File! : C:\Windows\System32\cyunn.dat
Removed File! : C:\Windows\System32\d3gr.exe
Removed File! : C:\Windows\System32\d3hd.exe
Removed File! : C:\Windows\System32\d3nt.exe
Removed File! : C:\Windows\System32\d3oh32.exe
Removed File! : C:\Windows\System32\d3pa32.exe
Removed File! : C:\Windows\System32\d3rf32.exe
Removed File! : C:\Windows\System32\d3rh32.exe
Removed File! : C:\Windows\System32\d3rp.exe
Removed File! : C:\Windows\System32\d3tz.exe
Removed File! : C:\Windows\System32\d3vs.exe
Removed File! : C:\Windows\System32\d3wt.exe
Removed File! : C:\Windows\System32\d3zb.exe
Removed File! : C:\Windows\System32\exlxl.dll
Removed File! : C:\Windows\System32\fburc.dat
Removed File! : C:\Windows\System32\gbxel.dat
Removed File! : C:\Windows\System32\ghdxg.dat
Removed File! : C:\Windows\System32\gzohn.dat
Removed File! : C:\Windows\System32\hitkn.dat
Removed File! : C:\Windows\System32\hylyg.dll
Removed File! : C:\Windows\System32\iefa.exe
Removed File! : C:\Windows\System32\iefr.exe
Removed File! : C:\Windows\System32\iejc.exe
Removed File! : C:\Windows\System32\iejd.exe
Removed File! : C:\Windows\System32\ielp32.exe
Removed File! : C:\Windows\System32\ienj.exe
Removed File! : C:\Windows\System32\ieoa32.exe
Removed File! : C:\Windows\System32\ieqd32.exe
Removed File! : C:\Windows\System32\iesn.exe
Removed File! : C:\Windows\System32\iewb.exe
Removed File! : C:\Windows\System32\ieyt32.exe
Removed File! : C:\Windows\System32\iezg32.exe
Removed File! : C:\Windows\System32\iezj32.exe
Removed File! : C:\Windows\System32\ikmza.dat
Removed File! : C:\Windows\System32\imhiz.dat
Removed File! : C:\Windows\System32\ipaa.exe
Removed File! : C:\Windows\System32\ipbi32.exe
Removed File! : C:\Windows\System32\ipde.exe
Removed File! : C:\Windows\System32\iphz.exe
Removed File! : C:\Windows\System32\ipqa.exe
Removed File! : C:\Windows\System32\iprs.exe
Removed File! : C:\Windows\System32\iprt32.exe
Removed File! : C:\Windows\System32\iptc.exe
Removed File! : C:\Windows\System32\ipvo.exe
Removed File! : C:\Windows\System32\ipwh.exe
Removed File! : C:\Windows\System32\ipwo.exe
Removed File! : C:\Windows\System32\ipyo32.exe
Removed File! : C:\Windows\System32\javabi.exe
Removed File! : C:\Windows\System32\javace.exe
Removed File! : C:\Windows\System32\javaef32.exe
Removed File! : C:\Windows\System32\javaim32.exe
Removed File! : C:\Windows\System32\javajb32.exe
Removed File! : C:\Windows\System32\javakt.exe
Removed File! : C:\Windows\System32\javamb.exe
Removed File! : C:\Windows\System32\javamz32.exe
Removed File! : C:\Windows\System32\javapm.exe
Removed File! : C:\Windows\System32\javatm32.exe
Removed File! : C:\Windows\System32\javazy32.exe
Removed File! : C:\Windows\System32\jpkde.dat
Removed File! : C:\Windows\System32\mfcaq.exe
Removed File! : C:\Windows\System32\mfcbk.exe
Removed File! : C:\Windows\System32\mfcbn.exe
Removed File! : C:\Windows\System32\mfccc32.exe
Removed File! : C:\Windows\System32\mfccv32.exe
Removed File! : C:\Windows\System32\mfceh32.exe
Removed File! : C:\Windows\System32\mfcex32.exe
Removed File! : C:\Windows\System32\mfchp32.exe
Removed File! : C:\Windows\System32\mfcjj.exe
Removed File! : C:\Windows\System32\mfclm32.exe
Removed File! : C:\Windows\System32\mfcny.exe
Removed File! : C:\Windows\System32\mfcrx32.exe
Removed File! : C:\Windows\System32\mfcyf.exe
Removed File! : C:\Windows\System32\mfcze32.exe
Removed File! : C:\Windows\System32\mqlbn.dll
Removed File! : C:\Windows\System32\mscg.exe
Removed File! : C:\Windows\System32\mscq32.exe
Removed File! : C:\Windows\System32\msgf.exe
Removed File! : C:\Windows\System32\msgl.exe
Removed File! : C:\Windows\System32\msgm32.exe
Removed File! : C:\Windows\System32\msjg32.exe
Removed File! : C:\Windows\System32\msju32.exe
Removed File! : C:\Windows\System32\mslb.exe
Removed File! : C:\Windows\System32\mssk.exe
Removed File! : C:\Windows\System32\msuu.exe
Removed File! : C:\Windows\System32\msve.exe
Removed File! : C:\Windows\System32\msxe.exe
Removed File! : C:\Windows\System32\msyy.exe
Removed File! : C:\Windows\System32\mszq32.exe
Removed File! : C:\Windows\System32\mudgu.dat
Removed File! : C:\Windows\System32\ndjah.dat
Removed File! : C:\Windows\System32\netcp.exe
Removed File! : C:\Windows\System32\netdf.exe
Removed File! : C:\Windows\System32\netfp32.exe
Removed File! : C:\Windows\System32\netfr.exe
Removed File! : C:\Windows\System32\netfv.exe
Removed File! : C:\Windows\System32\netid.exe
Removed File! : C:\Windows\System32\netlv32.exe
Removed File! : C:\Windows\System32\netwb32.exe
Removed File! : C:\Windows\System32\netwm32.exe
Removed File! : C:\Windows\System32\netxg32.exe
Removed File! : C:\Windows\System32\netzo.exe
Removed File! : C:\Windows\System32\nhkeo.dat
Removed File! : C:\Windows\System32\ntcy.exe
Removed File! : C:\Windows\System32\ntdg32.exe
Removed File! : C:\Windows\System32\ntew32.exe
Removed File! : C:\Windows\System32\ntkd.exe
Removed File! : C:\Windows\System32\ntof.exe
Removed File! : C:\Windows\System32\ntrz32.exe
Removed File! : C:\Windows\System32\nttw32.exe
Removed File! : C:\Windows\System32\nttx32.exe
Removed File! : C:\Windows\System32\ntur32.exe
Removed File! : C:\Windows\System32\ntwk.exe
Removed File! : C:\Windows\System32\ntxo32.exe
Removed File! : C:\Windows\System32\pfeuo.dll
Removed File! : C:\Windows\System32\sdkbn32.exe
Removed File! : C:\Windows\System32\sdkci32.exe
Removed File! : C:\Windows\System32\sdkdv.exe
Removed File! : C:\Windows\System32\sdkfc.exe
Removed File! : C:\Windows\System32\sdkjt.exe
Removed File! : C:\Windows\System32\sdkkr32.exe
Removed File! : C:\Windows\System32\sdkma.exe
Removed File! : C:\Windows\System32\sdkme.exe
Removed File! : C:\Windows\System32\sdkmm32.exe
Removed File! : C:\Windows\System32\sdkmy32.exe
Removed File! : C:\Windows\System32\sdkou.exe
Removed File! : C:\Windows\System32\sdkrp.exe
Removed File! : C:\Windows\System32\sdksd.exe
Removed File! : C:\Windows\System32\sdkti32.exe
Removed File! : C:\Windows\System32\sdkxz32.exe
Removed File! : C:\Windows\System32\sysbn32.exe
Removed File! : C:\Windows\System32\syscu32.exe
Removed File! : C:\Windows\System32\sysdm.exe
Removed File! : C:\Windows\System32\sysgr.exe
Removed File! : C:\Windows\System32\sysjx.exe
Removed File! : C:\Windows\System32\sysng32.exe
Removed File! : C:\Windows\System32\sysor32.exe
Removed File! : C:\Windows\System32\syspn32.exe
Removed File! : C:\Windows\System32\sysqw.exe
Removed File! : C:\Windows\System32\sysvw32.exe
Removed File! : C:\Windows\System32\syszd32.exe
Removed File! : C:\Windows\System32\tbjlz.dat
Removed File! : C:\Windows\System32\vogso.dat
Removed File! : C:\Windows\System32\wczvj.dat
Removed File! : C:\Windows\System32\winbn32.exe
Removed File! : C:\Windows\System32\windh32.exe
Removed File! : C:\Windows\System32\wingb32.exe
Removed File! : C:\Windows\System32\winht32.exe
Removed File! : C:\Windows\System32\winiz32.exe
Removed File! : C:\Windows\System32\winrp32.exe
Removed File! : C:\Windows\System32\wintn32.exe
Removed File! : C:\Windows\System32\winuo.exe
Removed File! : C:\Windows\System32\winvz32.exe
Removed File! : C:\Windows\System32\winyb32.exe
Removed File! : C:\Windows\System32\winzt.exe
Removed File! : C:\Windows\System32\wqumy.dll
Removed File! : C:\Windows\System32\wtoee.dll
Removed File! : C:\Windows\System32\wtygy.dat
Removed File! : C:\Windows\System32\xtzcp.dat
Removed File! : C:\Windows\System32\yikvw.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 8:36:58 AM
AboutBuster 5.0 reference file 28
Scan started on [6/12/2005] at [7:09:48 AM]
------------------------------------------------
Removed Stream! C:\WINDOWS\KB834707.log:rwvtir
Removed Stream! C:\WINDOWS\msoffice(3).ini:uqfzq
Removed Stream! C:\WINDOWS\orun32.isu:gnmei
Removed Stream! C:\WINDOWS\setuperr.del:fkwfrg
Removed Stream! C:\WINDOWS\setuperr.log:ypwsfk
Removed Stream! C:\WINDOWS\Sti_Trace.log:mfekj
Removed Stream! C:\WINDOWS\Sti_Trace.log:qsvzwu
Removed Stream! C:\WINDOWS\Sti_Trace.log:rqpxhm
Removed Stream! C:\WINDOWS\Sti_Trace.log:ygafic
Removed Stream! C:\WINDOWS\TaxACT04.ini:amrdie
Removed Stream! C:\WINDOWS\tiagl.txt:xkomoa
Removed Stream! C:\WINDOWS\tmnfs.log:tnkjkg
Removed Stream! C:\WINDOWS\_default(10).pif:auukp
Removed Stream! C:\WINDOWS\_default(11).pif:auukp
Removed Stream! C:\WINDOWS\_default(12).pif:auukp
Removed Stream! C:\WINDOWS\_default(13).pif:auukp
Removed Stream! C:\WINDOWS\_default(14).pif:auukp
Removed Stream! C:\WINDOWS\_default(2).pif:asxxh
Removed Stream! C:\WINDOWS\_default(3).pif:asxxh
Removed Stream! C:\WINDOWS\_default(4).pif:asxxh
Removed Stream! C:\WINDOWS\_default(5).pif:auukp
Removed Stream! C:\WINDOWS\_default(6).pif:auukp
Removed Stream! C:\WINDOWS\_default(7).pif:auukp
Removed Stream! C:\WINDOWS\_default(8).pif:auukp
Removed Stream! C:\WINDOWS\_default(9).pif:auukp
Removed Stream! C:\WINDOWS\_default.pif:auukp
Removed Stream! C:\WINDOWS\__delete_on_reboot__winqz32.dll:adytk
------------------------------------------------
Removed File! : C:\Windows\javayg32.exe
Removed File! : C:\Windows\mduen.dll
Removed File! : C:\Windows\msne32.exe
Removed File! : C:\Windows\ntcd.exe
Removed File! : C:\Windows\ntid32.exe
Removed File! : C:\Windows\rwlfx.dat
Removed File! : C:\Windows\yuybh.dll
Removed File! : C:\Windows\System32\apine.exe
Removed File! : C:\Windows\System32\apiwq.exe
Removed File! : C:\Windows\System32\avgvi.dat
Removed File! : C:\Windows\System32\dycly.dat
Removed File! : C:\Windows\System32\mfcvw32.exe
Removed File! : C:\Windows\System32\winym32.exe
Removed File! : C:\Windows\System32\xtzcp.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 7:26:02 AM
Logfile of HijackThis v1.99.1
Scan saved at 7:45:33 AM, on 6/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\ewidoctrl.exe
C:\Program Files\ewido\ewidoguard.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\winzq32.exe
C:\Program Files\Alarm++\Alarm.exe
C:\Program Files\YCIII\YankClip.exe
C:\Tools\Z Clock\ZClock-Digital.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\saqne.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell4me.com/mywayR3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {77D6A3EB-35E9-C062-5ADD-F1EC137D83E6} - C:\WINDOWS\netxj.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Class - {E75E8B80-0901-AC5A-6453-3114563FF460} - C:\WINDOWS\mfcds32.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [winzq32.exe] C:\WINDOWS\winzq32.exe
O4 - Startup: Alarm++.lnk = C:\Program Files\Alarm++\Alarm.exe
O4 - Startup: Yankee Clipper III.lnk = C:\Program Files\YCIII\YankClip.exe
O4 - Startup: ZClock.lnk = C:\Tools\Z Clock\ZClock-Digital.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logme...ivex/ractrl.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\javaia32.exe" /s (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\ewidoguard.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - 3am Labs, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - 3am Labs, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Thanks again.