Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Aurora fully removed? Casclient fully removed?


  • This topic is locked This topic is locked

#1
FelixFelicis

FelixFelicis

    New Member

  • Member
  • Pip
  • 7 posts
Hi.
Yesterday morning, after having left the computer on all night, i found a lot of pop-ups and Error messages on my computer screen. After fruitlessly struggly for a couple of hours, I followed the intructions given by Daemon here. I also noticed that an Adware(?) program called casclient had been installed onto my computer and random icons were being installed on my desktop. These included icons of Oreo cookies and Home Depot. I deleted these icons and deleted the casclient program. However, a file in the program's folder called csmf.dll would not delete, despite the fact that I have full privileges. I then followed the advice on another website and tried to un-register the dll. However, when i tried to use the Start-->Run function to unregister wtih Regsvr32 by typing regsvr32 /u c:\programfiles\cas\client\csmf.dll, it said that i could not find the module. I then opened up MS-DOS prompt and tried the line again when i was in the appropriate folder, but an Error message returned with a numeric return code.
I rebooted my computer and now have been able to delete the csmf.dll file. However, everytime I start up my computer I now receive the following error messages:

Posted Image

I was wondering if I had succesfully removed the Aurora ads and Casclient from my computer. Additionally, I am curious as to what is causing the error messages that pop up everytime I reboot and how I can go about preventing them from occuring. Please also let me know if any other malware is on my computer and how I can get rid of it. One pop-up that keeps coming up but fails to initialize is NDr20.tmp.html (except the number increases) and also NDr1E.tmp.html and NDr1D.tmp.html. I am very grateful for any advice that you can give me. Thank you in advance.

Sincerely,
FelixFelicis

here is my HiJackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 3:27:35 PM, on 7/26/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\ati2plab.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\WLANSTA.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\Atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE
C:\WINNT\system32\?hkntfs.exe
C:\Program Files\drpc\stoe.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Documents and Settings\Gerald Lee\My Documents\download\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINNT\dsr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe
O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\system32\wintask.exe
O4 - HKLM\..\Run: [ysoussd] c:\winnt\system32\gshbfrl.exe r
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Csvw] C:\WINNT\system32\?hkntfs.exe
O4 - HKCU\..\Run: [Sbts] C:\Program Files\drpc\stoe.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Siemens SpeedStream Wireless USB.lnk = C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.googl...gleActivate.cab
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: Telephony - C:\WINNT\system32\orprt400.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2plab.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

Edited by FelixFelicis, 26 July 2005 - 04:33 PM.

  • 0

Advertisements


#2
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Welcome FelixFelicis to Geeks to Go!

Let's see if we can get rid of the error messages as well as the infections in there.

Please read these instructions carefully. You may want to print them. Copy the text to a Notepad file and save it to your desktop! We will need the file later.
Be sure to follow ALL instructions!


***

Open Notepad. Copy the purple text to an empty file.


@ECHO OFF
cd %windir%
regsvr32.exe /u /s C:\WINNT\cfgmgr52.dll
attrib.exe -s -r -h cfgmgr52.dll
del cfgmgr52.dll
cd %windir%/system32
regsvr32.exe /u /s C:\WINNT\system32\AUNPS2.DLL
regsvr32.exe /u /s C:\WINNT\system32\E6F1873B.DLL
regsvr32.exe /u /s C:\WINNT\system32\orprt400.dll
attrib.exe -s -r -h AUNPS2.DLL
attrib.exe -s -r -h InstallAPS.exe
attrib.exe –s –r –h E6F1873B.DLL
attrib.exe -s -r -h orprt400.dll
del AUNPS2.DLL
del InstallAPS.exe
del E6F1873B.DLL
del orprt400.dll


Save it:
Location: desktop
Name : unreg.bat
Type : all types.

Close Notepad. Double-click unreg.bat
Grant permission when you are asked to.

***

Download SmitRem to your desktop.
Right click on the file and extract it to it's own folder on the desktop.

***

Place a shortcut to Panda ActiveScan on your desktop.

***

Please download the trial version of ewido security suite.Install ewido security suite
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

Launch ewido, there should be an icon on your desktop double-click it.
The program will prompt you to update click the OK button

The program will now go to the main screen
You will need to update ewido to the latest definition files.On the left hand side of the main screen click update
Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed, close Ewido for now.

***

If you have not already installed Ad-Aware SE 1.06, please download and install AdAware SE 1.06.
Check Here on how setup and use it - please make sure you update it first.

***

Download the Killbox.
Unzip it to the desktop

Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each

C:\WINNT\system32\exp.exe
C:\WINNT\dinst.exe
C:\WINNT\system32\wintask.exe
c:\winnt\system32\gshbfrl.exe
C:\Program Files\drpc\stoe.exe

For these file, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If your computer does not restart automatically, please restart it manually.

***

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml

***

Use Windows Explorer to remove this folder:
C:\Program Files\drpc\
Close Windows Explorer when you are done.

***

Open HijackThis
Place a check against each of the following, making sure you get them all and not any others by mistake:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINNT\dsr.dll

O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun

O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16

O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C

O4 - HKLM\..\Run: [exp.exe] C:\WINNT\system32\exp.exe

O4 - HKLM\..\Run: [Dinst] C:\WINNT\dinst.exe

O4 - HKLM\..\Run: [WinTask driver] C:\WINNT\system32\wintask.exe

O4 - HKLM\..\Run: [ysoussd] c:\winnt\system32\gshbfrl.exe r

O4 - HKCU\..\Run: [Csvw] C:\WINNT\system32\?hkntfs.exe

O4 - HKCU\..\Run: [Sbts] C:\Program Files\drpc\stoe.exe

O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx

O20 - Winlogon Notify: Telephony - C:\WINNT\system32\orprt400.dll

Close all programs leaving only HijackThis running.
Click on Fix Checked when finished and exit HijackThis.

***

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed.
Post me the contents of the smitfiles.txt log as you post back.

***

Open Ad-aware and do a full scan. Remove all it finds.

***

Now open Ewido Security Suite:* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop
Reboot your computer.

***

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

***

Reboot back into Windows and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked!
Save the scan log and post it along with a new HijackThis Log, the contents of the smitfiles.txt log and the Ewido Log by using Add Reply.
  • 0

#3
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Hi! Thanks for the prompt response. :tazz:

When I scanned with HijackThis, I could not find the following from the ones you listed so was unable to have them "fix checked":

O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun

O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C

O4 - HKLM\..\Run: [ysoussd] c:\winnt\system32\gshbfrl.exe r

New HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:19:06 AM, on 7/28/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\rundll32.exe
C:\Documents and Settings\Gerald Lee\My Documents\download\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [richup] C:\WINNT\system32\richup.exe
O4 - HKLM\..\Run: [Sysnet] C:\WINNT\TEMP\sysnet.exe
O4 - HKLM\..\Run: [9id909g3] C:\WINNT\system32\9id909g3.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINNT\system32\lanbrup.exe
O4 - HKLM\..\Run: [uykiuk] c:\winnt\system32\cpquzl.exe r
O4 - HKLM\..\Run: [mscin] C:\WINNT\system32\m190309.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINNT\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINNT\system32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [SystemService] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [dpnxmo] C:\WINNT\system32\dpnxmo.exe
O4 - HKCU\..\RunOnce: [dpnxmo] C:\WINNT\system32\dpnxmo.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Siemens SpeedStream Wireless USB.lnk = C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.googl...gleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O20 - Winlogon Notify: AdminDebug - C:\WINNT\system32\dTdim.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2plab.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINNT\svcproc.exe


Smitfiles.txt log


smitRem log file
version 2.2

by noahdfear

The current date is: Thu 07/28/2005
The current time is: 11:21:01.30

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Wininet.dll ~~~

CLEAN!

Ewido Log

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 4:09:36 PM, 7/28/2005
+ Report-Checksum: 467EE2A9

+ Scan result:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKU\S-1-5-21-57989841-1580818891-1060284298-1000\Software\Mvu -> Spyware.Delfin : Cleaned with backup
[264] C:\WINNT\system32\dTdim.dll -> Spyware.Look2Me : Error during cleaning
[416] C:\WINNT\system32\oFkley.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][10].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][11].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][12].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][13].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][14].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][15].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][16].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][17].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][18].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][19].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][20].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][21].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][22].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][23].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][24].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][25].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][26].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][27].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][28].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][29].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][30].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][31].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][32].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][33].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][34].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][35].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][36].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][37].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][38].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][39].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][3].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][4].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][5].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][6].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][7].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][8].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][9].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[10].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[11].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[12].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[13].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[14].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[15].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[16].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[17].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[18].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[19].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[20].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[21].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[22].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[23].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[24].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[25].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[26].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[27].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[28].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[29].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[30].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[31].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[32].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[33].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[34].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[35].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[36].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[37].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[38].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[39].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[3].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[40].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[41].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[42].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[43].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[44].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[45].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[46].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[47].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[48].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[49].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[4].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[50].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[51].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[52].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[53].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[54].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[55].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[56].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[57].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[58].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[59].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[5].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[60].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[61].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[62].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[63].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[64].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[65].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[66].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[67].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[68].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[69].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[6].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[70].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[71].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[72].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[73].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[74].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[75].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[76].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[77].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[78].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[79].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[7].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[80].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[81].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[82].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[83].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[84].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[85].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[86].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[87].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[88].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[89].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[8].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[90].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[91].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[92].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[93].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[94].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[95].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[96].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[97].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[98].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[99].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@abetterinternet[9].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][10].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][11].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][12].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][13].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][14].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][15].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][16].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][17].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][18].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][19].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][20].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][21].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][22].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][23].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][24].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][25].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][26].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][27].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][28].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][29].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][30].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][31].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][32].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][33].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][34].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][35].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][36].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][37].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][38].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][39].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][3].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][40].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][41].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][42].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][43].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][44].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][45].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][46].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][47].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][48].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][49].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][4].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][50].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][51].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][52].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][53].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][54].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][55].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][56].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][57].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][58].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][59].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][5].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][60].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][61].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][62].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][63].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][64].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][65].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][66].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][67].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][68].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][69].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][6].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][70].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][71].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][72].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][73].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][74].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][75].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][76].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][77].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][78].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][79].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][7].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][80].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][81].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][82].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][83].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][84].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][85].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][86].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][87].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][88].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][89].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][8].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][90].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][91].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][92].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][93].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][94].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][95].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][96].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][97].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][98].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][99].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][9].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][10].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][11].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][12].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][13].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][14].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][15].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][16].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][17].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][18].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][19].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][20].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][21].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][22].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][23].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][24].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][25].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][26].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][27].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][28].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][29].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][3].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][4].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][5].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][6].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][7].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][8].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected][9].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[10].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[11].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[3].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[4].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[5].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[6].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[7].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[8].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@burstnet[9].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald [email protected] -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Gerald Lee\Cookies\gerald lee@C
  • 0

#4
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
err...Ewido Log seems to have been cut off as is really quite long. Most of the stuff has been "cleaned with backup" but i'll post the "Error during Cleaning" stuff. If you need to the rest of the Ewido Log tell me but it will probably take a few replies just to fit it all.

C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\456789EF\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\456789EF\F654671472A06555F573A64361C68446A5E[1].html -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\4HEVKT6N\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\4HEVKT6N\AppWrap[2].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\4HEVKT6N\AppWrap[3].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\4HEVKT6N\AppWrap[4].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\6L8ROTQD\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\6L8ROTQD\AppWrap[2].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\8T6705A7\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\8T6705A7\F654672442905565C573A64361C68446A5E[1].html -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\AFSNMDYT\Poller[1].exe -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CLM3G5QJ\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CLM3G5QJ\AuroraHandler[1].dll -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CPI3CPMF\abiuninst[1].exe -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CPI3CPMF\F654671472A06555F573A64361C68446A5E[1].html -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\FRDN31GC\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\FV53RX80\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\JQSFVP49\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\MTH2JQ10\aurora[1].exe -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\MTH2JQ10\pcs_0026[1].exe -> Spyware.Pacer : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\O9AFK96B\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\O9AFK96B\F654673452804575D573A64361C68446A5E[1].html -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\OJ1RUQ3T\AppWrap[1].exe -> TrojanDropper.Agent.pb : Error during cleaning
C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\OJ1RUQ3T\Nail[1].exe -> Adware.BetterInternet : Error during cleaning
C:\Documents and Settings\Gerald Lee\thin-175-1-x-x.exe -> Adware.BetterInternet : Error during cleaning

Panda ActiveScan Log:


Incident Status Location

Possible Virus. No disinfected C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\4527OX6B\!update-2264[1].0000
Possible Virus. No disinfected C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\4T6FKPAJ\!update-2264[1].0000
Possible Virus. No disinfected C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\C1MR096N\!update-2214[1].0000
Possible Virus. No disinfected C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\C1MR096N\!update-2264[1].0000
Adware:Adware/PortalScan No disinfected C:\Documents and Settings\Gerald Lee\InstallAPS.exe
Virus:W32/Gaobot.JGO.worm Disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\456789EF\pictures[1].pif
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\456789EF\webservice[1].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\456789EF\webservice[2].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\4HEVKT6N\webservice[1].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\6L8ROTQD\webservice[1].htm
Spyware:Spyware/SafeSurf No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\8T6705A7\thin_installer[1].exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CLM3G5QJ\AppWrap[1].exe
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CLM3G5QJ\AuroraHandler[1].dll
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CPI3CPMF\abiuninst[1].exe
Adware:Adware/E2Give No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\CPI3CPMF\IeBHOs[1].dll
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\FRDN31GC\webservice[1].htm
Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\FV53RX80\AppWrap[1].exe
Adware:Adware/ConsumerAlertSystemNo disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\GHYVC9MZ\cassetup[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\GHYVC9MZ\webservice[2].htm
Adware:Adware/E2Give No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\JQSFVP49\IeBHOs[1].dll
Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\MTH2JQ10\pcs_0026[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\MTH2JQ10\webservice[2].htm
Adware:Adware/ConsumerAlertSystemNo disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\O9AFK96B\cassetup[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\O9AFK96B\webservice[2].htm
Possible Virus. No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\OJ1RUQ3T\!update-2295[1].0000
Spyware:Spyware/XXXToolbar No disinfected C:\Documents and Settings\Gerald Lee\Local Settings\Temporary Internet Files\Content.IE5\WDER81AV\prompt[1].php[prompt[1]]
Possible Virus. No disinfected C:\Documents and Settings\Gerald Lee\My Documents\download\AIMFix.exe
Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Gerald Lee\SSK39.exe
Virus:Trj/Downloader.BJG Disinfected C:\Documents and Settings\Gerald Lee\VB3.exe
Adware:Adware/DelFinMedia No disinfected C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe
Adware:Adware/E2Give No disinfected C:\Program Files\E2G\IeBHOs.dll
Adware:Adware/Look2Me No disinfected C:\WINNT\system32\guard.tmp
Spyware:Spyware/SafeSurf No disinfected C:\WINNT\system32\InstallerV3.exe
Possible Virus. No disinfected C:\WINNT\system32\m190309.exe
Adware:Adware/DelFinMedia No disinfected C:\WINNT\system32\nsvsvc\nsv.ocx
Adware:Adware/DelFinMedia No disinfected C:\WINNT\system32\nsvsvc\nsvs.dll
Adware:Adware/DelFinMedia No disinfected C:\WINNT\system32\nsvsvc\nsvsvc.exe
Adware:Adware/PurityScan No disinfected C:\WINNT\system32\Shex.exe
Adware:Adware/DelFinMedia No disinfected C:\WINNT\system32\vidctrl\vidctrl.exe







Thanks for all the help! Still getting random pop-ups and error messages though (although pop-ups no longer have Aurora ABI in the title) :tazz:
  • 0

#5
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
We will get there, it will take a few posts though. There is more than 'just' Aurora there. We will get to the not removed files ones we have cleaned up a bit.

Download CleanUp!.
If that doesn’t work, use this link.
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Scan local drives for temporary files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

Once it's done, press Close.

Let the system reboot.

***
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your post
  • Close HijackThis.
***

Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
  • 0

#6
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
HijackThis Uninstall List:
Ad-Aware SE Personal
Adobe Download Manager 1.2 (Remove Only)
Adobe Reader 6.0
Advanced WMA Workshop version 2.09b
AOL Instant Messenger
ATI NT Display Driver
Audio Converter
CleanUp!
CursorXP
DirectX 9 Hotfix - KB839643
E2give Plug-in
EPGY Course Series System
ewido security suite
Google Toolbar for Internet Explorer
GunboundWC
HijackThis 1.99.1
HP Image Zone 3.5
HP Photosmart Cameras 3.5
HP Software Update
InterActual Player
Internet Explorer Q903235
iTunes
Jasc Paint Shop Pro 8
LimeWire 4.8.1
LiveUpdate 1.7 (Symantec Corporation)
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Internet Explorer 6 SP1
Microsoft MapPoint 2002 North America
Microsoft MapPoint Europe 2002
Microsoft Office 2000 Professional
Microsoft VGX Q833989
Microsoft Windows Journal Viewer
Microsoft XML Parser and SDK
middle_man
Network Play System (Patching)
Norton AntiVirus Corporate Edition
NuCalc 2.0
OIN
Panasonic KX-FLM600/650
QuickTime
RealPlayer
RichEditor
Select CashBack
Shockwave
Siemens SpeedStream Wireless USB
Sketchpad
Spybot - Search & Destroy 1.3
Synaptics TouchPad
Sysnet
The Sims Livin' Large
WeatherBug
Windows 2000 Hotfix - KB329115
Windows 2000 Hotfix - KB820888
Windows 2000 Hotfix - KB822831
Windows 2000 Hotfix - KB823182
Windows 2000 Hotfix - KB823559
Windows 2000 Hotfix - KB823980
Windows 2000 Hotfix - KB824105
Windows 2000 Hotfix - KB824141
Windows 2000 Hotfix - KB824146
Windows 2000 Hotfix - KB825119
Windows 2000 Hotfix - KB826232
Windows 2000 Hotfix - KB828028
Windows 2000 Hotfix - KB828035
Windows 2000 Hotfix - KB828741
Windows 2000 Hotfix - KB828749
Windows 2000 Hotfix - KB835732
Windows 2000 Hotfix - KB837001
Windows 2000 Hotfix - KB839645
Windows 2000 Hotfix - KB840315
Windows 2000 Hotfix - KB840987
Windows 2000 Hotfix - KB841356
Windows 2000 Hotfix - KB841533
Windows 2000 Hotfix - KB841872
Windows 2000 Hotfix - KB841873
Windows 2000 Hotfix - KB842526
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB867282
Windows 2000 Hotfix - KB871250
Windows 2000 Hotfix - KB873333
Windows 2000 Hotfix - KB873339
Windows 2000 Hotfix - KB883939
Windows 2000 Hotfix - KB885250
Windows 2000 Hotfix - KB885835
Windows 2000 Hotfix - KB885836
Windows 2000 Hotfix - KB887797
Windows 2000 Hotfix - KB888113
Windows 2000 Hotfix - KB889293
Windows 2000 Hotfix - KB890046
Windows 2000 Hotfix - KB890175
Windows 2000 Hotfix - KB890859
Windows 2000 Hotfix - KB891711
Windows 2000 Hotfix - KB891781
Windows 2000 Hotfix - KB893066
Windows 2000 Hotfix - KB893086
Windows 2000 Hotfix - KB894320
Windows 2000 Hotfix - KB896358
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB897715
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix (SP5) Q818043
Windows Installer 3.1 (KB893803)
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows Media Player Hotfix [See KB837272 for more information]
Windows Media Player Hotfix [See wm828026 for more information]
Windows Media Player system update (9 Series)
WinRAR archiver
Winupdate
WinZip

l2mfix Log:
L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ExtShellViews]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINNT\\system32\\dTdim.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C4DC4420-3415-0AB0-3423-087F4030C014}"=""
"iebar"=" "

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network and Dial-up Connections"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{1A9BA3A0-143A-11CF-8350-444553540000}"="Shell Favorite Folder"
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"="My Computer"
"{86747AC0-42A0-1069-A2E6-08002B30309D}"="Briefcase Folder"
"{0AFACED1-E828-11D1-9187-B532F1E9575D}"="Folder Shortcut"
"{12518493-00B2-11d2-9FA5-9E3420524153}"="Mounted Volume"
"{21B22460-3AEA-1069-A2DC-08002B30309D}"="File Property Page Extension"
"{B091E540-83E3-11CF-A713-0020AFD79762}"="File Types Page"
"{FBF23B41-E3F0-101B-8488-00AA003E56F8}"="MIME File Types Hook"
"{C2FBB630-2971-11d1-A18C-00C04FD75D13}"="Microsoft CopyTo Service"
"{C2FBB631-2971-11d1-A18C-00C04FD75D13}"="Microsoft MoveTo Service"
"{13709620-C279-11CE-A49E-444553540000}"="Shell Automation Service"
"{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}"="Shell Automation Folder View"
"{4622AD11-FF23-11d0-8D34-00A0C90F2719}"="Start Menu"
"{7BA4C740-9E81-11CF-99D3-00AA004AE837}"="Microsoft SendTo Service"
"{D969A300-E7FF-11d0-A93B-00A0C90F2719}"="Microsoft New Object Service"
"{09799AFB-AD67-11d1-ABCD-00C04FC30936}"="Open With Context Menu Handler"
"{3FC0B520-68A9-11D0-8D77-00C04FD70822}"="Display Control Panel HTML Extensions"
"{75048700-EF1F-11D0-9888-006097DEACF9}"="ActiveDesktop"
"{6D5313C0-8C62-11D1-B2CD-006097DF8C11}"="Folder Options Property Page Extension"
"{57651662-CE3E-11D0-8D77-00C04FC99D61}"="CmdFileIcon"
"{4657278A-411B-11d2-839A-00C04FD918D0}"="Shell Drag and Drop helper"
"{A470F8CF-A1E8-4f65-8335-227475AA5C46}"="Add encryption item to context menus in explorer"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{568804CA-CBD7-11d0-9816-00C04FD91972}"="Menu Shell Folder"
"{5b4dae26-b807-11d0-9815-00c04fd91972}"="Menu Band"
"{8278F931-2A3E-11d2-838F-00C04FD918D0}"="Tracking Shell Menu"
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}"="Menu Site"
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}"="Menu Desk Bar"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}"="IShellFolderBand"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}"="&Links"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7487cd30-f71a-11d0-9ea7-00805f714772}"="Thumbnail Image"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}"="Thumbnails"
"{EAB841A0-9550-11CF-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{1AEB1360-5AFC-11D0-B806-00C04FD706EC}"="Office Graphics Filters Thumbnail Extractor"
"{9DBD2C50-62AD-11D0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{500202A0-731E-11D0-B829-00C04FD706EC}"="LNK file thumbnail interface delegator"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8C-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{fe1290f0-cfbd-11cf-a330-00aa00c16e65}"="Directory Namespace"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{450D8FBA-AD25-11D0-98A8-0800361B1103}"="MyDocs Folder"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}"="LDVP Shell Extensions"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}\InprocServer32]
@="C:\\WINNT\\system32\\alsldpc.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINNT\SYSTEM32\
alsldpc.dll Fri Jul 29 2005 10:57:48p ..... 417,792 408.00 K
cdm.dll Thu May 26 2005 4:16:24a A.... 75,544 73.77 K
dtdim.dll Thu Jul 28 2005 12:39:08a ..S.R 417,792 408.00 K
icm32.dll Wed Jun 29 2005 12:30:56a A.... 246,032 240.27 K
inetcomm.dll Tue May 3 2005 4:26:50p A.... 596,480 582.50 K
iuengine.dll Thu May 26 2005 4:16:24a A.... 198,424 193.77 K
mscms.dll Wed Jun 29 2005 12:30:56a A.... 69,904 68.27 K
msi.dll Wed May 4 2005 2:45:32p A.... 2,890,240 2.75 M
msihnd.dll Wed May 4 2005 2:45:36p A.... 271,360 265.00 K
msimsg.dll Wed May 4 2005 2:45:36p A.... 884,736 864.00 K
msisip.dll Wed May 4 2005 2:45:36p A.... 15,360 15.00 K
onwafube.dll Wed Jul 27 2005 7:56:36p A.... 225,280 220.00 K
pncrt.dll Sat Jul 2 2005 9:13:02p A.... 278,528 272.00 K
pndx5016.dll Sat Jul 2 2005 9:13:06p A.... 6,656 6.50 K
pndx5032.dll Sat Jul 2 2005 9:13:06p A.... 5,632 5.50 K
richedtr.dll Wed Jul 27 2005 2:29:14p A.... 225,280 220.00 K
rmoc3260.dll Sat Jul 2 2005 9:13:32p A.... 176,167 172.04 K
wirelanb.dll Wed Jul 27 2005 7:56:32p A.... 417,792 408.00 K
wuapi.dll Thu May 26 2005 4:16:30a A.... 465,176 454.27 K
wuaueng.dll Thu May 26 2005 4:16:30a A.... 1,343,768 1.28 M
wuaueng1.dll Thu May 26 2005 4:16:30a A.... 194,328 189.77 K
wucltui.dll Thu May 26 2005 4:16:30a A.... 127,256 124.27 K
wups.dll Thu May 26 2005 4:16:30a A.... 41,240 40.27 K
wups2.dll Thu May 26 2005 4:16:30a A.... 18,200 17.77 K
wuweb.dll Thu May 26 2005 4:16:30a A.... 173,536 169.47 K

25 items found: 25 files (1 H/S), 0 directories.
Total of file sizes: 9,782,503 bytes 9.33 M
Locate .tmp files:

C:\WINNT\SYSTEM32\
guard.tmp Fri Jul 29 2005 11:08:48p ..S.R 417,792 408.00 K

1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 417,792 bytes 408.00 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is 98E1-C5D4

Directory of C:\WINNT\System32

07/29/2005 11:08p 417,792 guard.tmp
07/28/2005 12:39a 417,792 dTdim.dll
07/25/2005 12:18p <DIR> dllcache
07/21/2005 07:00a 401,408 ?hkntfs.exe
07/21/2005 06:55a 401,408 j?vaw.exe
4 File(s) 1,638,400 bytes
1 Dir(s) 2,659,704,832 bytes free





Thanks again!
-FelixFelicis
  • 0

#7
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Open HiJackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on
    Winupdate
    E2give Plug-in
    Select CashBack
    RichEditor
    WeatherBug
    Sysnet
  • Click on Delete this entry
  • Click "Yes"
Close HijackThis.

***

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
  • 0

#8
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
;) When I tried to delete the E2give Plug-in through HijackThis it didn't really work and keeps reappearing everytime i click refresh list. :tazz:

New l2mfix Log:

L2Mfix 1.03a

Running From:
C:\Documents and Settings\Gerald Lee\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Gerald Lee\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Gerald Lee\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [email protected]
Killing PID 1140 'explorer.exe'
Killing PID 1140 'explorer.exe'
Error 0x5 : Access is denied.


Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [email protected]
Killing PID 952 'rundll32.exe'
Killing PID 1360 'rundll32.exe'

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINNT\system32\dTdim.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\dTdim.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\lHme_enc.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\lHme_enc.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\mmvcp70.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\mmvcp70.dll
1 file(s) copied.
Backing Up: C:\WINNT\system32\guard.tmp
1 file(s) copied.
Backing Up: C:\WINNT\system32\guard.tmp
1 file(s) copied.
deleting: C:\WINNT\system32\dTdim.dll
Successfully Deleted: C:\WINNT\system32\dTdim.dll
deleting: C:\WINNT\system32\dTdim.dll
Successfully Deleted: C:\WINNT\system32\dTdim.dll
deleting: C:\WINNT\system32\lHme_enc.dll
Successfully Deleted: C:\WINNT\system32\lHme_enc.dll
deleting: C:\WINNT\system32\lHme_enc.dll
Successfully Deleted: C:\WINNT\system32\lHme_enc.dll
deleting: C:\WINNT\system32\mmvcp70.dll
Successfully Deleted: C:\WINNT\system32\mmvcp70.dll
deleting: C:\WINNT\system32\mmvcp70.dll
Successfully Deleted: C:\WINNT\system32\mmvcp70.dll
deleting: C:\WINNT\system32\guard.tmp
Successfully Deleted: C:\WINNT\system32\guard.tmp
deleting: C:\WINNT\system32\guard.tmp
Successfully Deleted: C:\WINNT\system32\guard.tmp


Zipping up files for submission:
adding: dTdim.dll (152 bytes security) (deflated 48%)
adding: lHme_enc.dll (152 bytes security) (deflated 48%)
adding: mmvcp70.dll (152 bytes security) (deflated 48%)
adding: guard.tmp (152 bytes security) (deflated 48%)
adding: clear.reg (152 bytes security) (deflated 22%)
adding: echo.reg (152 bytes security) (deflated 9%)
adding: direct.txt (152 bytes security) (stored 0%)
adding: lo2.txt (152 bytes security) (deflated 79%)
adding: readme.txt (152 bytes security) (deflated 49%)
adding: report.txt (152 bytes security) (deflated 63%)
adding: test.txt (152 bytes security) (deflated 77%)
adding: test2.txt (152 bytes security) (stored 0%)
adding: test3.txt (152 bytes security) (stored 0%)
adding: test5.txt (152 bytes security) (stored 0%)
adding: xfind.txt (152 bytes security) (deflated 74%)
adding: backregs/8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4.reg (152 bytes security) (deflated 70%)
adding: backregs/shell.reg (152 bytes security) (deflated 75%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

deleting local copy: dTdim.dll
deleting local copy: dTdim.dll
deleting local copy: lHme_enc.dll
deleting local copy: lHme_enc.dll
deleting local copy: mmvcp70.dll
deleting local copy: mmvcp70.dll
deleting local copy: guard.tmp
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


The following are the files found:
****************************************************************************
C:\WINNT\system32\dTdim.dll
C:\WINNT\system32\dTdim.dll
C:\WINNT\system32\lHme_enc.dll
C:\WINNT\system32\lHme_enc.dll
C:\WINNT\system32\mmvcp70.dll
C:\WINNT\system32\mmvcp70.dll
C:\WINNT\system32\guard.tmp
C:\WINNT\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}"=-
[-HKEY_CLASSES_ROOT\CLSID\{8EE02AD7-5A9A-4B12-B46E-2CDC4BB548A4}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************


Edited by FelixFelicis, 31 July 2005 - 01:34 AM.

  • 0

#9
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Hmm, let's deal with E2Give later than.

Where do we stand now. Can you show me a fresh HijackThis log?

BTW, how are things now?
  • 0

#10
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
New HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 3:21:22 PM, on 7/31/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\ati2plab.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\WLANSTA.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\Atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\internat.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Gerald Lee\My Documents\download\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.sho...6648&id=1.20030
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.sho...6648&id=1.20030
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.sho...6648&id=1.20030
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.sho...6648&id=1.20030
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.sho...6648&id=1.20030
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.sho...6648&id=1.20030
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.shopnav.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINNT\system32\onwafube.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [richup] C:\WINNT\system32\richup.exe
O4 - HKLM\..\Run: [Sysnet] C:\WINNT\TEMP\sysnet.exe
O4 - HKLM\..\Run: [9id909g3] C:\WINNT\system32\9id909g3.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINNT\system32\lanbrup.exe
O4 - HKLM\..\Run: [uykiuk] c:\winnt\system32\cpquzl.exe r
O4 - HKLM\..\Run: [mscin] C:\WINNT\system32\m190309.EXE
O4 - HKLM\..\Run: [vidctrl] C:\WINNT\system32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [SystemService] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [AutoLoaderAproposClient] "C:\WINNT\system32\cxtpls_loader.EXE" /HideUninstall /HideDir /PC= CP.AOP /ForSupportedBrowsers /ShowLegalNote=nonbranded
O4 - HKLM\..\Run: [wFnW3sT] hosvent.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [dpnxmo] C:\WINNT\system32\dpnxmo.exe
O4 - HKCU\..\Run: [ho46RifnS] gluas.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - HKCU\..\RunOnce: [dpnxmo] C:\WINNT\system32\dpnxmo.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Siemens SpeedStream Wireless USB.lnk = C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.googl...gleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2plab.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

i know that some of these programs definitely are spyware/malware/programs that got installed on my computer without my consent, such as the richup.exe and pokapoka62.exe. As of right now, my computer seems to be working normally, but twice before when I rebooted my computer, everytime I opened an application I would get an error saying "________ has created errors and will be shut down by Windows." I would have to attempt many times before i would be able to use the program.
  • 0

#11
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Let's do this in parts.

Please print out or copy this page to Notepad . Make sure to work through the steps in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fix.
  • Download DSRFIX from HERE onto your Desktop.
    • Unzip and EXTRACT the files to your Desktop.
    • The program creates and names the new folder to house the files.
    • DO NOT RUN IT YET
  • Download Cleanup from Here (Alternate site if the above is not working Go Here)
    • A window will open and choose SAVE, then DESKTOP as the destination.
    • On your Desktop, click on Cleanup40.exe icon.
    • Then, click RUN and place a checkmark beside "I Agree"
    • Then click NEXT followed by START and OK.
    • A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
    • Click OK
    • DO NOT RUN IT YET
  • CLOSE INTERNET EXPLORER, if it is open


  • Open the folder dsrfix
    • Double click on the dsrfix batch file( the one with the little gear in it )
    • Once dsrfix has completed it will close on its own
  • Run Cleanup
    • Click on the "Cleanup" button and let it run.
    • Once its done, close the program.
  • REBOOT your system.


  • Please restart HJT and post back a fresh HJT log for review.

  • 0

#12
FelixFelicis

FelixFelicis

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
:) when i tried to use dsrfix.bat i got this error message:
Posted Image

and when i restarted my computer kept getting those error messages everytime i tried to run a program again. the ones that go "_______.exe has generated errors and will be closed by Windows." ;)

oh yeah. and i already had Cleanup! from a few posts ago, remember? :tazz:

New HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:52:21 PM, on 7/31/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\ati2plab.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\WLANSTA.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINNT\system32\Atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\etb\pokapoka62.exe
C:\WINNT\system32\hosvent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINNT\system32\dpnxmo.exe
C:\WINNT\system32\internat.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINNT\system32\dpnxmo.exe
C:\WINNT\system32\gluas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\DOCUME~1\GERALD~1\LOCALS~1\Temp\ei.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Gerald Lee\My Documents\download\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.sho...6648&id=1.20030
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WLANSTA.EXE] WLANSTA.EXE START
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [richup] C:\WINNT\system32\richup.exe
O4 - HKLM\..\Run: [Sysnet] C:\WINNT\TEMP\sysnet.exe
O4 - HKLM\..\Run: [9id909g3] C:\WINNT\system32\9id909g3.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINNT\system32\lanbrup.exe
O4 - HKLM\..\Run: [uykiuk] c:\winnt\system32\cpquzl.exe r
O4 - HKLM\..\Run: [mscin] C:\WINNT\system32\m190309.EXE
O4 - HKLM\..\Run: [vidctrl] C:\WINNT\system32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [SystemService] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe
O4 - HKLM\..\Run: [AutoLoaderAproposClient] "C:\WINNT\system32\cxtpls_loader.EXE" /HideUninstall /HideDir /PC= CP.AOP /ForSupportedBrowsers /ShowLegalNote=nonbranded
O4 - HKLM\..\Run: [wFnW3sT] hosvent.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [dpnxmo] C:\WINNT\system32\dpnxmo.exe
O4 - HKCU\..\Run: [ho46RifnS] gluas.exe
O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe
O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Siemens SpeedStream Wireless USB.lnk = C:\Program Files\Siemens\SpeedStream Wireless USB\SSUSBCfg.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.googl...gleActivate.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2plab.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
  • 0

#13
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Please download the Nailfix utility. Unzip it to your desktop.

DO NOT run it yet.

***

Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each

C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Program Files\ezula\mmod.exe
C:\WINNT\etb\pokapoka62.exe
C:\WINNT\system32\9id909g3.exe
c:\winnt\system32\cpquzl.exe
C:\WINNT\system32\cxtpls_loader.EXE
C:\WINNT\system32\dpnxmo.exe
C:\WINNT\system32\E6F1873B.DLL
C:\WINNT\system32\gluas.exe
C:\WINNT\system32\hosvent.exe
C:\WINNT\system32\lanbrup.exe
C:\WINNT\system32\m190309.EXE
C:\WINNT\system32\richup.exe
C:\WINNT\TEMP\sysnet.exe
C:\WINNT\ttupt.exe
C:\WINNT\system32\Shex.exe
C:\WINNT\system32\InstallerV3.exe


For these file, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If your computer does not restart automatically, please restart it manually.

***

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.co.../safemode.shtml

***

Once in Safe Mode, please double-click on nailfix.exe[/b. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

***

Then run HijackThis, click Scan, and place a checkmark by the following item:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.sho...6648&id=1.20030

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php

F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe

O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C

O4 - HKLM\..\Run: [richup] C:\WINNT\system32\richup.exe

O4 - HKLM\..\Run: [Sysnet] C:\WINNT\TEMP\sysnet.exe

O4 - HKLM\..\Run: [9id909g3] C:\WINNT\system32\9id909g3.exe

O4 - HKLM\..\Run: [lanbrup] C:\WINNT\system32\lanbrup.exe

O4 - HKLM\..\Run: [uykiuk] c:\winnt\system32\cpquzl.exe r

O4 - HKLM\..\Run: [mscin] C:\WINNT\system32\m190309.EXE

O4 - HKLM\..\Run: [vidctrl] C:\WINNT\system32\vidctrl\vidctrl.exe

O4 - HKLM\..\Run: [SystemService] C:\WINNT\etb\pokapoka62.exe

O4 - HKLM\..\Run: [System service62] C:\WINNT\etb\pokapoka62.exe

O4 - HKLM\..\Run: [AutoLoaderAproposClient]
"C:\WINNT\system32\cxtpls_loader.EXE" /HideUninstall /HideDir /PC= CP.AOP
/ForSupportedBrowsers /ShowLegalNote=nonbranded

O4 - HKLM\..\Run: [wFnW3sT] hosvent.exe

O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"

O4 - HKLM\..\Run: [ttupt] C:\WINNT\ttupt.exe

O4 - HKCU\..\Run: [dpnxmo] C:\WINNT\system32\dpnxmo.exe

O4 - HKCU\..\Run: [ho46RifnS] gluas.exe

O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe

O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe

Close all open windows except for HijackThis and click Fix Checked.

***

Open Windows Explorer.

Remove these folders:
C:\WINNT\system32\vidctrl\
C:\PROGRAM FILES\Web Offer\
C:\WINNT\system32\nsvsvc\
C:\Program Files\E2G\

Then move to the folder:
c:\windows\downloaded program files
find this item:
CWebDownloader Object
and remove it.

Please check to see it you have this one:
C:\WINDOWS\System32\[b]msdirectx.sys


Close Windows Explorer.

***

Reboot to normal mode. Rerun Panda and post me the results. Also post me a fresh HijackThis log.



EDIT:
As there has been no reply from the original poster for more than two weeks this topic is now closed.

If you are the original poster and still need assistance, please send me a PM.

Edited by g2i2r4, 17 August 2005 - 02:21 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP