Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Winfixer and other beasties [RESOLVED]


  • This topic is locked This topic is locked

#1
wayne_cramp

wayne_cramp

    Member

  • Member
  • PipPip
  • 10 posts
Well, I had thought Winfixer was my major problem, but my PC has taken a turn for the worst. Sometimes upon boot it won't start up Explorer without me opening it myself.

I downloaded clean-up and the other utilities (I was already running Spybot and Ad-Aware, alonth with Norton).

Here is my Hi-jack this log:

Logfile of HijackThis v1.99.1
Scan saved at 12:35:09 PM, on 8/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\WINDOWS\System32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Valued Customer\My Documents\Software Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [Kill-Pop-Ups.com] C:\Documents and Settings\Valued Customer\Desktop\program.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [7F8P3Fi] wmptok.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0614] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe"
O4 - HKLM\..\Run: [qrhjo] C:\WINDOWS\System32\qrhjo.exe
O4 - HKLM\..\Run: [SystemService] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ojrpon.exe reg_run
O4 - HKLM\..\Run: [ibikju] C:\WINDOWS\System32\ibikju.exe
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [yxlx] C:\WINDOWS\System32\yxlx.exe
O4 - HKLM\..\Run: [hlcilp] C:\WINDOWS\System32\hlcilp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [oebxjhn] C:\WINDOWS\System32\oebxjhn.exe
O4 - HKLM\..\Run: [suziiwj] C:\WINDOWS\System32\suziiwj.exe
O4 - HKLM\..\Run: [jmrhqvd] C:\WINDOWS\System32\jmrhqvd.exe
O4 - HKLM\..\Run: [wdyqmu] C:\WINDOWS\System32\wdyqmu.exe
O4 - HKLM\..\Run: [qwfpej] C:\WINDOWS\System32\qwfpej.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe"
O4 - HKLM\..\Run: [ozureho] C:\WINDOWS\System32\ozureho.exe
O4 - HKLM\..\Run: [eebo] C:\WINDOWS\System32\eebo.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [tempx] C:\WINDOWS\System32\tempx.exe
O4 - HKLM\..\Run: [tcl] C:\WINDOWS\System32\tcl.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative....ClientNoMFC.cab
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\khdur.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



I hope someone can make heads or tails out of this because I'm completely out of my element here.

Thanks in advance to anyone who can give me any help.
  • 0

Advertisements


#2
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
You have the latest version of VX2. Download L2mfix from

http://www.atribune....oads/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
  • 0

#3
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
I downloaded the file, but when I attempted tp install it I get the following error:

"The archive is either in an unknown format or damaged
Cannot open C:\Documents & Settings\Valued Customer\Desktop\l2mfix.exe
  • 0

#4
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
OK, got it to work. Here is the log generated by it:

L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IPConfTSP]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\lzbkscin.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{6ED61E8A-8A07-8D1C-0EF6-95AF48FE5AF8}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{A68865DD-EE3C-4442-9BE9-1BAB2576E3FA}"="NOMAD Explorer"
"{2DEC3B75-F93C-47C5-BE07-6298F41BEA21}"=""
"{A34FBC15-037E-40A1-85CC-7E17299CAD17}"=""
"{B8C72277-1F2B-4EFD-9E82-8D24F1AE86DB}"=""
"{284DBF12-F697-4491-8AD8-350CB7CE9C5C}"=""
"{63C1011B-065C-4151-8B8A-9BEE151976D9}"=""
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2DEC3B75-F93C-47C5-BE07-6298F41BEA21}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2DEC3B75-F93C-47C5-BE07-6298F41BEA21}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2DEC3B75-F93C-47C5-BE07-6298F41BEA21}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2DEC3B75-F93C-47C5-BE07-6298F41BEA21}\InprocServer32]
@="C:\\WINDOWS\\system32\\irxndw30102lib.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A34FBC15-037E-40A1-85CC-7E17299CAD17}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A34FBC15-037E-40A1-85CC-7E17299CAD17}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A34FBC15-037E-40A1-85CC-7E17299CAD17}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A34FBC15-037E-40A1-85CC-7E17299CAD17}\InprocServer32]
@="C:\\WINDOWS\\system32\\ptisdecd.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{B8C72277-1F2B-4EFD-9E82-8D24F1AE86DB}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8C72277-1F2B-4EFD-9E82-8D24F1AE86DB}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8C72277-1F2B-4EFD-9E82-8D24F1AE86DB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{B8C72277-1F2B-4EFD-9E82-8D24F1AE86DB}\InprocServer32]
@="C:\\WINDOWS\\system32\\wfcdlg.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{284DBF12-F697-4491-8AD8-350CB7CE9C5C}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{284DBF12-F697-4491-8AD8-350CB7CE9C5C}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{284DBF12-F697-4491-8AD8-350CB7CE9C5C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{284DBF12-F697-4491-8AD8-350CB7CE9C5C}\InprocServer32]
@="C:\\WINDOWS\\system32\\lzbkscin.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{63C1011B-065C-4151-8B8A-9BEE151976D9}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{63C1011B-065C-4151-8B8A-9BEE151976D9}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{63C1011B-065C-4151-8B8A-9BEE151976D9}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{63C1011B-065C-4151-8B8A-9BEE151976D9}\InprocServer32]
@="C:\\WINDOWS\\system32\\mfhgrcoi.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:
Locate .tmp files:
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is F828-8BE5

Directory of C:\WINDOWS\System32

08/08/2005 01:53 PM 417,792 utl.dll
08/08/2005 01:51 PM 417,792 qghjoaeg06.dll
08/08/2005 01:51 PM 417,792 rEsauto.dll
08/08/2005 06:32 AM 417,792 guard.tmp
08/07/2005 08:48 PM <DIR> dllcache
08/07/2005 12:02 PM 82,432 eetu.exe
08/06/2005 05:14 PM 417,792 lzbkscin.dll
07/29/2005 04:32 PM 417,792 mfhgrcoi.dll
07/29/2005 07:11 AM 417,792 ptisdecd.dll
07/29/2005 06:51 AM 417,792 cefgnt.dll
07/29/2005 06:51 AM 417,792 cdutil.dll
07/26/2005 07:17 AM 417,792 khdur.dll
07/23/2005 12:35 PM 417,792 wppsrcwp.dll
07/23/2005 12:35 PM 417,792 wfcdlg.dll
07/23/2005 11:26 AM 417,792 rkgdctxndw30102lib.dll
07/23/2005 11:26 AM 417,792 rQsdlg.dll
07/23/2005 10:19 AM 417,792 FU20.DLL
07/23/2005 10:19 AM 417,792 gmkcsp.dll
07/23/2005 09:13 AM 417,792 kcdhe220.dll
07/23/2005 09:13 AM 417,792 kvdhe.dll
07/23/2005 07:57 AM 417,792 dHdramp.dll
07/23/2005 07:57 AM 417,792 cZrds.dll
07/23/2005 06:48 AM 417,792 ksymgr.dll
07/23/2005 06:48 AM 417,792 kldne.dll
07/23/2005 05:24 AM 417,792 czfgnt.dll
07/23/2005 05:24 AM 417,792 bfowser.dll
07/23/2005 02:33 AM 417,792 mwpbde40.dll
07/23/2005 02:33 AM 417,792 moltus40.dll
07/23/2005 01:07 AM 417,792 mfvcrt.dll
07/23/2005 01:07 AM 417,792 mvvcp71.dll
07/22/2005 11:38 PM 417,792 mzrdim.dll
07/22/2005 11:37 PM 417,792 mpsystem.dll
07/22/2005 10:38 PM 417,792 ccedui.dll
07/22/2005 10:37 PM 417,792 cuyptdll.dll
07/22/2005 09:31 PM 417,792 xakhndw30102lib.dll
07/22/2005 09:30 PM 417,792 xQctsrv.dll
07/22/2005 05:47 PM 417,792 hbtplug.dll
07/22/2005 05:46 PM 417,792 hbsetup.dll
07/22/2005 04:42 PM 417,792 FY20.DLL
07/22/2005 04:41 PM 417,792 FQ20.DLL
07/22/2005 03:40 PM 417,792 sKfrdm.dll
07/22/2005 03:39 PM 417,792 rdcdll.dll
07/22/2005 02:31 PM 417,792 ksdhe.dll
07/22/2005 02:31 PM 417,792 ksdhu.dll
07/22/2005 01:09 PM 417,792 zqegokbndw30102lib.dll
07/22/2005 01:08 PM 417,792 xynndw30102lib.dll
07/22/2005 11:47 AM 417,792 rOsrad.dll
07/22/2005 11:46 AM 417,792 rJsmans.dll
07/22/2005 10:43 AM 417,792 wxpsrcwp.dll
07/22/2005 10:42 AM 417,792 wcpasf.dll
07/22/2005 09:28 AM 417,792 namsevt.dll
07/22/2005 09:27 AM 417,792 nttman.dll
07/22/2005 08:06 AM 417,792 kvdycc.dll
07/22/2005 08:05 AM 417,792 kedru1.dll
07/22/2005 06:48 AM 417,792 nnmsmgr.dll
07/22/2005 06:47 AM 417,792 nxtman.dll
07/22/2005 05:17 AM 417,792 ixxpromn.dll
07/22/2005 05:17 AM 417,792 iyv6mon.dll
07/22/2005 04:14 AM 417,792 mjc70.dll
07/22/2005 04:13 AM 417,792 myiqtz32.dll
07/22/2005 02:58 AM 417,792 iIsads.dll
07/22/2005 02:58 AM 417,792 iIspolcy.dll
07/22/2005 01:39 AM 417,792 iaxmontr.dll
07/22/2005 01:39 AM 417,792 iihlpapi.dll
07/22/2005 12:09 AM 417,792 cDmocx.dll
07/22/2005 12:09 AM 417,792 cVrds.dll
07/21/2005 10:48 PM 417,792 skgina.dll
07/21/2005 10:48 PM 417,792 scc_os.dll
07/21/2005 09:31 PM 417,792 kkduk.dll
07/21/2005 09:31 PM 417,792 kadus.dll
07/21/2005 08:21 PM 417,792 nzmsmgr.dll
07/21/2005 08:21 PM 417,792 nzlanui2.dll
07/21/2005 07:11 PM 417,792 hyetmon.dll
07/21/2005 07:11 PM 417,792 cOtsrv.dll
07/21/2005 05:43 PM 417,792 wbstream.dll
07/21/2005 05:43 PM 417,792 whpencen.dll
07/21/2005 04:42 PM 417,792 ismpagnt.dll
07/21/2005 04:41 PM 417,792 hopertrm.dll
07/21/2005 03:14 PM 417,792 ltgif11n.dll
07/21/2005 03:13 PM 417,792 lEprxy.dll
08/28/2004 05:26 PM <DIR> Microsoft
79 File(s) 32,670,208 bytes
2 Dir(s) 38,091,796,480 bytes free
  • 0

#5
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log, and we'll clean up what's left. :tazz:

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
  • 0

#6
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
OK. I had to manually start Explorere after the reboot (opened task manager and ran it from there), but here is the logfile generated by Hijack This after the restart:

Logfile of HijackThis v1.99.1
Scan saved at 2:43:14 PM, on 8/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Valued Customer\My Documents\Software Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [Kill-Pop-Ups.com] C:\Documents and Settings\Valued Customer\Desktop\program.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [7F8P3Fi] wmptok.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0614] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe"
O4 - HKLM\..\Run: [qrhjo] C:\WINDOWS\System32\qrhjo.exe
O4 - HKLM\..\Run: [SystemService] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ojrpon.exe reg_run
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [yxlx] C:\WINDOWS\System32\yxlx.exe
O4 - HKLM\..\Run: [hlcilp] C:\WINDOWS\System32\hlcilp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [jmrhqvd] C:\WINDOWS\System32\jmrhqvd.exe
O4 - HKLM\..\Run: [wdyqmu] C:\WINDOWS\System32\wdyqmu.exe
O4 - HKLM\..\Run: [qwfpej] C:\WINDOWS\System32\qwfpej.exe
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe"
O4 - HKLM\..\Run: [eebo] C:\WINDOWS\System32\eebo.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [tempx] C:\WINDOWS\System32\tempx.exe
O4 - HKLM\..\Run: [tcl] C:\WINDOWS\System32\tcl.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [ieewk] C:\WINDOWS\System32\ieewk.exe
O4 - HKLM\..\Run: [nnf] C:\WINDOWS\System32\nnf.exe
O4 - HKLM\..\Run: [ajyk] C:\WINDOWS\System32\ajyk.exe
O4 - HKLM\..\Run: [ybh] C:\WINDOWS\System32\ybh.exe
O4 - HKLM\..\Run: [iuocoyn] C:\WINDOWS\System32\iuocoyn.exe
O4 - HKLM\..\Run: [ndiemps] C:\WINDOWS\System32\ndiemps.exe
O4 - HKLM\..\Run: [second] C:\Documents and Settings\Valued Customer\Desktop\l2mfix\second.bat
O4 - HKLM\..\Run: [zyrqadi] C:\WINDOWS\System32\zyrqadi.exe
O4 - HKLM\..\Run: [bafja] C:\WINDOWS\System32\bafja.exe
O4 - HKLM\..\Run: [wgrd] C:\WINDOWS\System32\wgrd.exe
O4 - HKLM\..\Run: [gafntfm] C:\WINDOWS\System32\gafntfm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative....ClientNoMFC.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#7
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

Open Ewido again
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Reboot and Post the report Ewido made and a new Hijackthis log here in a reply.
  • 0

#8
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Done and done (with 620+ infected. A new record!)

Anyway, the Ewido log is as follows:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:12:11 PM, 8/8/2005
+ Report-Checksum: 6931327B

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{36A59337-6EEF-40AE-94B1-ED443A0C4740} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{EE6AE627-8F18-4986-BEAD-52073EDFC776} -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\XParam.XParamObj -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\XParam.XParamObj\CLSID -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Classes\XParam.XParamObj\CurVer -> Spyware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Mvu -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Need2Find -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\Need2Find\bar\Partner -> Spyware.Need2Find : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Spyware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\2m50l60r.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Sitestat : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.416:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.450:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.451:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.452:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.453:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.454:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.485:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.486:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.487:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.670:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.671:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.672:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.678:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.679:C:\Documents and Settings\Mom\Application Data\Mozilla\Firefox\Profiles\jw6oxfit.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Need2Find -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\History -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\History\search -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\Need2Find\bar\Settings -> Spyware.Need2Find : Cleaned with backup
C:\Program Files\SearchRelevant\SearchRelevant.dll -> Spyware.Relevance : Cleaned with backup
C:\WINDOWS\bsx32 -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADTMI1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVCTX2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASI2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIB9894.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIC29667.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASICLRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASICLV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASID12180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIE17070.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIEPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIEZ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF29819.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIF4502.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFA15376.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIFWH29233.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIG21943.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIGT10102.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH21180.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIH7853.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASII21469.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIKAB.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIL18549.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASILS29399.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIM9740.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIMBC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOG19375.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIOT25456.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIPF1965.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIR21184.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRCPRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIRE20082.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS24110.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIS31590.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISS2RE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASISSRE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT17011.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIT26116.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIW11211.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ASIWS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\AUTOS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\bspace.html -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARD2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DATE4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\EML1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FAST1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FINC5.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FLWR1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\FMND1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\HERBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\JOBS4.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MOVS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\NEWS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SHOP2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TECH2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPC.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPD.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPE.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPF.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFAM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFI.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPFIN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPG.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPH.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPHL.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPJ.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPM.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPMTV.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPN.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPR.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPS.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPSHOP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPSP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMPW.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TRVL6.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TVEN1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\UTONE2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WEBS1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WEBS2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\WWW3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ZNETGP.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\bundles\HelperInstaller.exe -> TrojanDropper.Delf.z : Cleaned with backup
C:\WINDOWS\cfgmgr52\EECH1.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\cfgmgr52\SPZ3.bsx -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ActiveX.ocx -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\epx30102.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\search3.dll -> Spyware.MegaSearch : Cleaned with backup
C:\WINDOWS\etb\nt_hide61.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\nt_hide62.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\pokapoka61.exe -> TrojanDropper.Agent.qz : Cleaned with backup
C:\WINDOWS\etb\pokapoka62.exe -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\xud2f.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\xud_62.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\icont.exe -> Spyware.AdURL : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\system32\acmjych.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\aehgcdj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ajyk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\akhq.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\akhqndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\amfryr.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\amfryrndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\aoamfi.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\aoamfindw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\aob.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\aobndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\aqcwjndw30101lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\aud.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\audndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\avov.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\avovndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\awus.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\awusndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\aza.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\azandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\azdv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\azdvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bafja.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bcanrj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bcanrjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bcbr.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bcbrndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bfowser.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\bgiqll.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\bkxby.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bkxbyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bmja.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\bpqp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bpqpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bpxaufe.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bpxaufendw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bqwqd.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bqwqdndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bto.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\btondw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\bvniys.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\bvniysndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\cbwu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\cbwundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ccedui.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cdutil.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cefgnt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cfp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\cfpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\cfvtrek.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\cfvtrekndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\chqg.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\chqgndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ckgevj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ckgevjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\clcyjhk.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\cuyptdll.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\cvb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\cvbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\cypj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\cypjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\czfgnt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\czmrd.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\czmrdndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\cZrds.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\czzf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\czzfndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\den.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\denndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\dHdramp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\diwj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\diwjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\dqxf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\dqxfndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\dtuj.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\dxi.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\dxindw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\eak.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\earzl.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\earzlndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\eby.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ebyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ecp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ecpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\eebo.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\eeboaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\eetu.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\eezoam.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\eezoamndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\efi.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\efindw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\elogvyt.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\elogvytndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\epx30102ndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\epx30103.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\epx30104.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\epx30105.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\epx30106.exe -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\system32\erc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ezaape.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ezaapendw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ezmay.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ezmayndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\falt.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\faltndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\femtu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\femtundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\fhqg.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\fpk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\fpkndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\FQ20.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\FU20.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\FY20.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\fyfsp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\fyfspndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gafntfm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gcxd.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gcxdndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ggm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ggmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ghvkhqv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ghvkhqvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gkohb.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\gmkcsp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\grbaw.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\grbawndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gruzpm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gruzpmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gty.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gtyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\guk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gukndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gxv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\gxvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\gzfq.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\hbsetup.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hbtplug.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\hdmkg.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hdmkgndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hffsri.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hffsrindw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hfjbb.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\hfjbbaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hgjv.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\hiec.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hiecndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hlcilp.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\hmx.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hmxndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hnnw.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hnnwndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hoewfa.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hoewfandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\hqumwaf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\hqumwafndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ibikju.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ibikjuaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\idx.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\idxndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ieewk.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ieewkaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ilm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ilmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\istq.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\istqndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\iuocoyn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\iwb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\iwbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ixxpromn.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\iyn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\iynndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\iyv6mon.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\izwxiv.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\jahxb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\jahxbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\jjhm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\jjhmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\jkp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\jkpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\jmrhqvd.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\jmzr.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\jmzrndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\jndohm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\jndohmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kbb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kbbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kbvvmgp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kbvvmgpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kcdhe220.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kdgmed.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kdgmedndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kedru1.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ketrndw301lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kfnrxh.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kfnrxhndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kfp.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\khdur.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kldne.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kmgbqph.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kmgbqphndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\knbu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\knbundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ksdhe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ksdhu.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ksuo.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ksuondw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ksymgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kuzmz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kuzmzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\kvdhe.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kvdycc.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\kzb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\kzbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lbc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lbcndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lcih.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lcihndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ldz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ldzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lgf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lgfndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lgwsrn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lgwsrnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\loplnlp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\loplnlpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lvh.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lvhndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lzbiuu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\lzbiuundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\lzbkscin.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mca.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mcandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mcdsu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mcdsundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mfhgrcoi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mfvcrt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mgzuc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mgzucndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mjc70.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mjyurct.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\mkajtk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mkajtkndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mmhfrx.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mmhfrxndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\moltus40.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mpsystem.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mrdcpkv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mrdcpkvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\muy.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\muyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mvvcp71.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mwaghny.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\mwaghnyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\mwpbde40.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\myiqtz32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mzrdim.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\namsevt.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nbc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nbcndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ndhrhrs.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ndhrhrsndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ndiemps.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ndiempsaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nfiqkz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nfiqkzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nhc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nhcndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nlrv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nlrvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nndlgn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nndlgnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nnf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nnmsmgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nrb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nrbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nttman.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nws.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nwsndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nwwu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\nwwundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\nxtman.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\oebxjhn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\oebxjhnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ofskkrb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ofskkrbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\okdylrx.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\okdylrxndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ominxj.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\omnlew.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\omnlewndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\omrkz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\omrkzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\onzbztg.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\onzbztgndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\oukkw.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ozureho.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ozurehoaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\pbgnqz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\pbgnqzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\pgohfzz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\pgohfzzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\pkggmq.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\pkggmqndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ptisdecd.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\qcjqchf.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qcjqchfndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qdqhtm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qdqhtmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qghjoaeg06.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\qlgxn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qlgxnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qmad.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qmadndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qrhjo.exe -> TrojanDownloader.Lastad.r : Cleaned with backup
C:\WINDOWS\system32\qshc.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qshcndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qtkalyb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qtkalybndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qtpxxnt.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\qtpxxntndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\qwfpej.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\qwfpejaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with
  • 0

#9
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Part 2 of the Ewido log:

C:\WINDOWS\system32\rcgdctx.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rcgdctxndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rdcdll.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rdixzz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rdixzzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rEsauto.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rfca.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\rhw.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rhwndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rivylv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rivylvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rJsmans.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rkgdctxndw30102lib.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rOsrad.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rpu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rpundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rQsdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\rttud.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rttudndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rvg.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rvgndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\rzbtqmv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\rzbtqmvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\scqru.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\scqrundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\sfyecif.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\shkkr.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\shkkrndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\sioui.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\sKfrdm.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\smjbk.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\spnbmn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\spnbmnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\sqdyj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\sqdyjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\srv.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\srvndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\suziiwj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\suziiwjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\sxyqmp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\sxyqmpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\synomsh.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\synomshndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tbcqj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tbcqjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tcl.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tclndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tkgczxk.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tkgczxkndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tkyj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tkyjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tmu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tmundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\toump.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\toumpndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\tvh.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\tvs.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\tyij.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\tyijndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\uieduh.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\uieduhndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\utl.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\uxdfya.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\uxdfyandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\vaj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\vajndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\vasoaxr.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\vasoaxrndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\velrrm.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\vhdoda.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\vhdodandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\von.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\vonndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\vziek.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\vziekndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wbm.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wbmndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wcpasf.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wdy.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wdyndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wdyqmu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wfcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wgrd.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\whth.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\whthndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\WinStat11.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\WinStat12.dll -> Spyware.Winsta : Cleaned with backup
C:\WINDOWS\system32\wppsrcwp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wvfazyz.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wvfazyzndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wvqmvj.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wvqmvjndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wvznbl.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wvznblndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wws.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\wwsndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\wxmlm.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\wxpsrcwp.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\wynpq.exe -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xakhndw30102lib.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\xcbwm.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\xddnsu.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\xddnsundw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xfsp.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\xfspndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xjggs.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\xQctsrv.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\xrn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\xrnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xtfpqxe.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\xtfpqxendw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xvkh.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\xvkhndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\xynndw30102lib.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ybh.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\ygyekoi.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\yij.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\yijndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\yjim.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\yjimndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\yjyhjuo.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\yjyhjuondw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ypoaxrw.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\yuake.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\yuakendw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ywqkjb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ywqkjbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\yxlx.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\yxlxaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zba.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\zbandw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zcmw.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\zidclqn.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\zidclqnndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zpnjwo.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\zpnjwondw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zqegokbndw30102lib.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\zregokb.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\zregokbndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zrq.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\zrqndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\ztob.exe -> TrojanDownloader.Lastad.n : Cleaned with backup
C:\WINDOWS\system32\ztobndw30102lib.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\system32\zyrqadi.exe -> TrojanDownloader.Lastad.p : Cleaned with backup
C:\WINDOWS\system32\zyrqadiaeg05.dll -> TrojanDownloader.Lastad.h : Cleaned with backup
C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Cleaned with backup
C:\WINDOWS\thin-143-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\ypkqgdyp.exe -> Spyware.BookedSpace : Cleaned with backup


::Report End
  • 0

#10
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
And the Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 6:20:31 PM, on 8/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Valued Customer\My Documents\Software Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [Kill-Pop-Ups.com] C:\Documents and Settings\Valued Customer\Desktop\program.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [7F8P3Fi] wmptok.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0614] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ojrpon.exe reg_run
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe"
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [tempx] C:\WINDOWS\System32\tempx.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative....ClientNoMFC.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



Thnaks so much for taking the time on this. Someone on BigSoccer.com recommended this site to me. I only wished I had known about this the last time my PC got infected and I ended up reformatting the hard drive...
  • 0

Advertisements


#11
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Ok since there was alot of infections run it again.

Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

Open Ewido again
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Reboot and Post the report Ewido made and a new Hijackthis log here in a reply.
  • 0

#12
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Well, this latest log certainly looks much better. The Ewido log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:05:00 PM, 8/8/2005
+ Report-Checksum: 4BE104B9

+ Scan result:

No infected objects found.


::Report End

Certainly look slike good news there. My HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:07:32 PM, on 8/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Valued Customer\My Documents\Software Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [Kill-Pop-Ups.com] C:\Documents and Settings\Valued Customer\Desktop\program.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [7F8P3Fi] wmptok.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0614] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ojrpon.exe reg_run
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe"
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [tempx] C:\WINDOWS\System32\tempx.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative....ClientNoMFC.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I hope we're close on this. Boy, you guys are heaven sent, for sure..
  • 0

#13
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
1. Make sure your PC is set to show all hidden files and folders go here for instructions on how to do this. http://www.xtra.co.n...1916458,00.html

2. Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

3. While in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1
O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\System32\winupdtl.exe
O4 - HKLM\..\Run: [CSV7P70] C:\Program Files\CSBB\CSV7P070.exe
O4 - HKLM\..\Run: [Kill-Pop-Ups.com] C:\Documents and Settings\Valued Customer\Desktop\program.exe
O4 - HKLM\..\Run: [PSoft1] C:\WINDOWS\System32\psoft1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [7F8P3Fi] wmptok.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0614] "C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\ojrpon.exe reg_run
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0802] "C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe"
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [tempx] C:\WINDOWS\System32\tempx.exe
O15 - Trusted Zone: http://www.neededware.com

4. Delete the folders. (if present)

C:\Program Files\CSBB
C:\Program Files\Common Files\tsa\

5. Delete the files. (if present)

C:\WINDOWS\System32\winupdtl.exe
C:\Documents and Settings\Valued Customer\Desktop\program.exe
C:\WINDOWS\System32\psoft1.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\cfgmgr52.dll
C:\WINDOWS\System32\exp
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5LP_0001_0614NetInstaller.exe
C:\WINDOWS\System32\ojrpon.exe
C:\DOCUMENTS AND SETTINGS\MOM\DESKTOP\WFI.exe
C:\WINDOWS\System32\tempx.exe

These files might either be found in C:\ C:\Windows or C:\Windows\System32 if found delete.

wmptok.exe
AUNPS2.DLL
E6F1873B.DLL

6. Reboot and post a new Hijackthis log here in a reply.
  • 0

#14
wayne_cramp

wayne_cramp

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Done and done. The current HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 9:23:27 PM, on 8/8/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Belkin\Nostromo\nost_LM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Valued Customer\My Documents\Software Downloads\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HOTLLAMA Update Check.lnk = C:\Program Files\HOTLLAMA MEDIA\Player\WiseUpdt.exe
O4 - Global Startup: Loadout Manager.lnk = C:\Program Files\Belkin\Nostromo\nost_LM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative....ClientNoMFC.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

I hope this has done it.

Two of the items you said to fix in the initial Hijack this did not appear when I ran it. They were:

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://69.28.210.175/media/1

O15 - Trusted Zone: http://www.neededware.com
  • 0

#15
therock247uk

therock247uk

    Expert

  • Expert
  • 14,671 posts
  • MVP
Fix this in Hijackthis.

O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx

Then Your log is clean :tazz:

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.

Credit to PGPhantom for canned speech.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP