Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

terrible problems! [RESOLVED]


  • This topic is locked This topic is locked

#1
kishan

kishan

    Member

  • Member
  • PipPip
  • 34 posts
hello tehre, computer just absalutly messed up.. ehars the hijack log...
PLEASE HELP ME REMOVE ALL THIS RUBBISH :tazz:


Logfile of HijackThis v1.99.1
Scan saved at 20:30:34, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\V-Tech UK\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://www.akzupxdzw...fLtO3qAbTj.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi kishan and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.

1. If you haven't logged in go to Geeks to Go and do so. Then proceed to item a.

If you already have logged in, go directly to item a.
  • Click on My Controls at the top right hand corner of the window.
  • In the left hand column, click "View Topics"
  • If you click on the title of your post, you will be taken there
2. Also, while at the My Controls page, check the box to the right of your post and then scroll down.
.Where it says "unsubscribe" click the pull-down menu and select "immediate email notification"

3. Please DELETE your current HJT program from its present location.

4. Download and run the following HijackThis autoinstall program from Here . Please choose the default location of C:\Program Files\ as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Run HijackThis
  • Click SCAN and SAVE LOG. (a notepad window will open with the log in it when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')
  • POST the log into this thread using 'Add Reply' (Ctrl-V to 'paste')

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER


Regards,

Trevuren

  • 0

#3
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Logfile of HijackThis v1.99.1
Scan saved at 21:37:50, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\GlobalSCAPE\CuteFTP Professional\cuteftppro.exe
C:\Program Files\GlobalSCAPE\CuteFTP Professional\ftpte.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.akzupxdzw...fLtO3qAbTj.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#4
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
You have a LOP infection that often comes together with Messenger Plus. To remove it we will try the simple way first.

1. Go to Add/Remove programs. Double click on "Messenger Plus!" (or click on Remove)

2. The "Messenger Plus! - Setup" is now displayed. Click on the Uninstall button. Note: options displayed on the first screen are not related to the sponsor program.

3. The sponsor screen is now displayed (if you don't see it, search for it in your Task Bar). To prove that someone is currently reading the screen, you have to type the code that is displayed. Once you enter the code, press Uninstall.

4. If you entered the code properly, the program will ask you to confirm that you want to uninstall. You must answer "Yes" to this question, else, you won't have another chance of uninstalling.

5. To complete the uninstallation, follow the instructions that are displayed (the first one is to close all your Internet Explorer windows, that's very important). When everything is complete, REBOOT your computer.

Regards,

Trevuren

  • 0

#5
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
it said you must confirm i did, and it closed, thats it nothing else happend.

also, i dont have abackground...

no display settings

and a lot of other spyware

please advise
  • 0

#6
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Please reboot your system and post a fresh HJT log for review. I have to see what happened.

Regards,

Trevuren

  • 0

#7
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Logfile of HijackThis v1.99.1
Scan saved at 22:07:33, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://www.akzupxdzw...AhpozaVaPj/819v

1EpNBCAJdxAfLtO3qAbTj.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} -

C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -

C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility]

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround

Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program

Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive

Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program

Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec

Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton

SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]

C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus!

3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch

Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH

Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program

Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program

Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton

SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE

CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe

-quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe"

/background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton

SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program

Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program

Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program

Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program

Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program

Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program

Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} -

C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -

{4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program

Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -

C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -

{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F}

- C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 -

{CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth

Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper -

{68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper -

{68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper -

{E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper -

{E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -

http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient

Class) -

http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -

http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) -

http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} -

http://66.117.37.13/dba1865.exe
O17 -

HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}:

NameServer = 194.168.8.100,192.168.0.1
O17 -

HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}:

NameServer = 194.168.8.100,192.168.0.1
O17 -

HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}:

NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB -

C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner

- C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common

Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program

Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation

- C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec

Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) -

Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec

Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner -

C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton

SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -

C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec

Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -

C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation -

C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program

Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#8
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
You inadvertantly posted your log in double space format which is very difficult to analyze. Would you please report the log in single space format.

To remove the double spacing in your log, please do the following:
  • Please go to Start >> Run... and type notepad.exe
  • Hit OK.
  • Now go to Format and uncheck WordWrap.
  • Close Notepad.

Regards,

Trevuren

  • 0

#9
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Logfile of HijackThis v1.99.1
Scan saved at 22:16:49, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.akzupxdzw...fLtO3qAbTj.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#10
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
1. Please download and run the following program Lop Uninstaller

2. Reboot your system

3. Post a fresh HJT log for review.

Regards,

Trevuren

  • 0

Advertisements


#11
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Logfile of HijackThis v1.99.1
Scan saved at 22:34:52, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.blazefind.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.flingstone.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchbarcash.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#12
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Please run the following program:
  • Please download WinHelp2002's DelDomains by right-clicking on the following link, and choosing "Save Target As": DelDomains.inf to your Desktop
    http://www.mvps.org/.../DelDomains.inf

  • Then go to the desktop, right click on DelDomains.inf, and choose Install. You may not see any noticeable changes or prompts; this is normal.
  • Then please restart your computer, and post a new HijackThis log.
Regards,

Trevuren

  • 0

#13
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Logfile of HijackThis v1.99.1
Scan saved at 22:46:53, on 25/09/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\mnmsrvc.exe
C:\mysql\bin\mysqld-nt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\vsnpt513.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicks...earch.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicks...earch.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicks...earch.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R3 - Default URLSearchHook is missing
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\System32\hpD5D2.tmp (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Creative MediaSource Go] C:\Program Files\Creative\MediaSource\GO\CTCMSGo.exe /SCB
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Norton Disk Doctor.lnk = C:\Program Files\Norton SystemWorks\Norton Utilities\NDD32.EXE
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: LimeWire 4.2.6 Pro.lnk = C:\Program Files\LimeWire\LimeWire 4.2.6 Pro\LimeWire.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0527.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.cartoon-f...ayx_vp3_mp3.cab
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1FDE2EED-0CFD-45A8-8041-20C0C2B6C09B}: NameServer = 194.168.8.100,192.168.0.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PostgreSQL Database Server (PostgreSQL) - Unknown owner - C:\Program Files\PostgreSQL\8.0-beta2-dev3\bin\pg_ctl.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#14
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
You have 2 major infections going on at the same time one of which is an About:Blank infection which we are tackling first.

Your system is infected with a variant of the About:Blank infection.
  • First we must STOP, and Disable a bad Added Service
    • Click Start>Run and type in: services.msc
    • Click OK
    • In the Services window find: Workstation NetLogon Service
    • Select/highlight and right click the entry, and choose: Properties
    • On the General tab, under Service Status click the Stop button
    • Beside: Startup Type, in the drop menu, select: Disabled
    • Click Apply, then OK
  • Download CWShredder
    Click check for updates. Do not use it yet.

  • Download Aboutbuster 5
    Unzip the file to its own folder (C:\AB) Do not use it yet.

  • Download: HomeSearchfix. Unzip it to your desktop. Do not use it yet.

  • Download Killbox
    Choose save as to your desktop. Unzip the file. Do not use it yet.

    Take care: some files can be hidden, so first go to start > control panel > folder options > view (tab) > mark “show hidden files en extensions >OK

    Please print out these directions for in safe mode you will have to be disconnected from the internet. You should entirely disconnect (UNPLUG) from the internet!!!

  • Reboot your system into safe mode for all OS

  • Close all windows and open HijackThis.
    • Click "scan only” in the main window
    • Put a checkmark beside the following entries and click “FIX checked”.

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hnxdn.dll/sp.html#37049
      R3 - Default URLSearchHook is missing
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [atluy32.exe] C:\WINDOWS\system32\atluy32.exe
      O4 - HKLM\..\Run: [d3zh32.exe] C:\WINDOWS\system32\d3zh32.exe
      O4 - HKLM\..\Run: [SNPT513] C:\WINDOWS\vsnpt513.exe
      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O9 - Extra button: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {68F794C1-10A7-4728-B9CE-B3415501D474} - (no file) (HKCU)
      O9 - Extra button: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E3FC288B-AAC5-4721-972B-D249A3F92C32} - (no file) (HKCU)
      O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1865.exe
      O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addeg32.exe (file missing)
  • Run CWShredder and choose FIX

  • Start AboutBuster and press START, and then OK. The program will start scanning.

  • Doubleclick HomeSearchfix.reg to merge the info to the registry. You will be prompted to accept the merge, answer YES.

  • Start Killbox
    • Place a checkmark next to [x] Delete On Reboot.
    • Highlight the following list and Copy it (Ctrl+C) to the windows clipboard.

      C:\WINDOWS\vsnpt513.exe
      C:\WINDOWS\hnxdn.dll
      C:\Program Files\Winamp\winampa.exe
      C:\WINDOWS\system32\atluy32.exe
      C:\WINDOWS\system32\d3zh32.exe
      C:\WINDOWS\web\related.htm
      C:\WINDOWS\system32\addeg32.exe

    • Back in Killbox, go > file > paste from clipboard,
    • Click the red highlighted X button and click yes to the prompt when all the files have been pasted.
    • Then click OK
    • Exit Killbox and Reboot your PC.
  • After the reboot, Start AboutBuster AGAIN and scan AGAIN.

  • Clean temporary files:
    • Go > start > run and type cleanmgr and OK
    • Scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files and Recycle Bin are the only things checked.
    • Click OK to remove those files.
    • Click Yes to confirm deletion.
  • Reboot your system into normal mode.

  • Download Ewido scan
    • Check for updates.
    • Let it do a full run.
    • Copy the log. Past it to a blank Notepad file and save it to post here.
  • Finally, run HijackThis, click SCAN, produce a LOG and POST it and the EWIDOscan log in this thread for review.
Regards,

Trevuren

  • 0

#15
kishan

kishan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 13:12:07, 26/09/2005
+ Report-Checksum: C91BA66A

+ Scan result:

HKLM\SOFTWARE\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\CashBack -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{05BCCFDC-9678-9095-77E8-18289DB38257} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{145E6FB1-1256-44ed-A336-8BBA43373BE6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{18ECE89C-2542-91DE-E39B-39C5120593D7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{59411F8E-CF6C-7B7A-F0C0-DB33873458BD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8138EE4F-2AC5-6CBF-E88D-A0A94EE71F0C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{96EEA21B-4AA3-4627-EA0A-176241DBD1A4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A4913EBE-69AB-7C2E-EA16-13F6C5E79E14} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A52FA47B-BA50-C6CB-6B02-1F30CC46D589} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A72CAEB7-7E44-7941-564B-A741D28B01DB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AAC3A456-1DE9-F1B9-912D-E57B58C8E083} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B599C57E-113A-4488-A5E9-BC552C4F1152} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B78A202C-9FF5-481D-3E8C-0877C167707F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BE5DCDBC-54D3-95EA-B258-2D53BD817431} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CBD8F541-0C17-2308-CE59-19ACBB1E7CB6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1B10CDC-1975-EC0C-C522-2571525E92CF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F4BF9913-CC48-121B-F8DE-11BD3C45410F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FC92C3DE-F786-C2A4-4565-359ECF140E14} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\ImgConv.clsImgConv -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Classes\ImgConv.clsImgConv\Clsid -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F} -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2DDD90D6-F153-4EA7-A324-4B2D83D1027E} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{4D6CED50-D6AE-40DA-B87F-235593FC1F28} -> Spyware.NavExcel : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{68831D00-169E-4FEB-89B9-E099DF439321} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{15E7D23B-736E-46FA-BFFD-CBEC4126BEFD} -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F} -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{209B1CEA-8B2E-4596-9B35-A4A7DB611EB2} -> Spyware.NavExcel : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516C2E3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{7C9E9A74-1922-409E-AB46-E48784336C3A} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\IEagent -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\387 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\saie -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\sais -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchUpgrader -> Spyware.KeenValue : Cleaned with backup
HKLM\SOFTWARE\SearchUpgrader\{7EE60CF1-2DFF-41B5-91C9-9C1C518053FC} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1123561945-789336058-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1123561945-789336058-1343024091-1003\Software\NavExcel Ltd -> Spyware.NavExcel : Cleaned with backup
HKU\S-1-5-21-1123561945-789336058-1343024091-1003\Software\NavExcel Ltd\NavExcel Search Toolbar -> Spyware.NavExcel : Cleaned with backup
HKU\S-1-5-21-1123561945-789336058-1343024091-1003\Software\saie -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-1123561945-789336058-1343024091-1003\Software\sais -> Spyware.180Solutions : Cleaned with backup
:mozilla.23:C:\Documents and Settings\V-Tech UK\Application Data\Mozilla\Firefox\Profiles\58yajn4s.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.24:C:\Documents and Settings\V-Tech UK\Application Data\Mozilla\Firefox\Profiles\58yajn4s.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.26:C:\Documents and Settings\V-Tech UK\Application Data\Mozilla\Firefox\Profiles\58yajn4s.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.27:C:\Documents and Settings\V-Tech UK\Application Data\Mozilla\Firefox\Profiles\58yajn4s.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.37:C:\Documents and Settings\V-Tech UK\Application Data\Mozilla\Firefox\Profiles\58yajn4s.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@lop[2].txt -> Spyware.Cookie.Lop : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@paycounter[2].txt -> Spyware.Cookie.Paycounter : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@spinbox[2].txt -> Spyware.Cookie.Spinbox : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech uk@xxxcounter[2].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Cookies\v-tech [email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\2004.02.09_invoice2go.2.0.build.5.0.4.loader-tsrh\invoicereg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\2004.02.09_invoice2go.2.0.build.5.0.4.loader-tsrh.zip/invoicereg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\corkb100.exe/F0000014.DAT -> TrojanDownloader.Small.Go : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\Invoice2go_v2.0_build_5.0.4\invoicereg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\mt29B6rJo1h\invoiceReg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Documents and Settings\V-Tech UK\Desktop\mt29B6rJo1h.zip/invoiceReg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Program Files\C2Media\Setup.exe -> Spyware.Lop : Cleaned with backup
C:\Program Files\Invoice2go\invoiceReg.exe -> Trojan.Small.cr : Cleaned with backup
C:\Program Files\SearchRelevancy -> Spyware.Relevance : Cleaned with backup
C:\Program Files\SearchRelevancy\SearchRelevancy.xml -> Spyware.Relevance : Cleaned with backup
C:\Program Files\SearchRelevancy\uninstall.exe -> Spyware.Relevance : Cleaned with backup
C:\Program Files\WebSpecials\uninst.exe -> Spyware.WebSpecial : Cleaned with backup
C:\WINDOWS\a3kebook.ini:hkydcm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\abagw.log:kodgra -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\AC3API.INI:stwpye -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\AC3API.INI:zhdev -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Active Setup Log.BAK:atbgtq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Active Setup Log.BAK:boliaz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Active Setup Log.BAK:deiolm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Active Setup Log.BAK:hfgexl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:brgrjd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:czusns -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:illxns -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Active Setup Log.txt:vpgynn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\acvne.txt:djdtlk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\acvne.txt:enwhnf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\addyv.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyv.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\adlss.log:zgqrrv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\aezqw.dat:jxunqb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aezqw.dat:lugvto -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\aezqw.dat:nqzehx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\afcda.log:sullvt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\afges.txt:bldchd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\afges.txt:upwnuj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\afges.txt:vknyfv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\afges.txt:vsmxhu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\afges.txt:xqtokp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\agcte.log:ztuqqv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\agsjb.txt:iowawy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\agsjb.txt:vmhrmc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aioce.log:ruedkg -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ajndp.log:ikdwui -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ajsxl.log:arbyyp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ajsxl.log:cxnssl -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ajsxl.log:luerqd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ajsxl.log:nmawge -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ajsxl.log:saniuz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\akyce.dat:acwbos -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\alemm.dat:vxbipy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\alemm.dat:ybibgk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\alzaq.dat:ktynwk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\alzaq.dat:mxtuis -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\amgaj.dat:ixkrae -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\aoeli.log:fxezcc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aouli.log:duvyxs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aouli.log:nxuvji -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\aovej.log:dtqtqm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aovej.log:pywfen -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\atlsx.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsx.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\atltg.dll:cpmeki -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\avxwa.txt:vujgtw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\axgpt.dat:ivgsty -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\axmsv.dat:ssudaa -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\axnyw.dat:fqhgqw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\axnyw.dat:knupaf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ayewf.dat:bzhwcs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ayewf.dat:zoeqdl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aysct.log:rpwefn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\azckk.log:whhbvk -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\azopj.dat:taabec -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\azopj.dat:uwokec -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\azopj.dat:xjzltg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\azopj.dat:yqzfft -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\azplq.dat:hsbpci -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\baahd.txt:cgozxp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\baahd.txt:cqnuen -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\bcnev.txt:atmuel -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bcnev.txt:qkkrnj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bcnev.txt:rrskhd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bcquu.dat:djhkkv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bdpfx.dat:azjepa -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bdpfx.dat:uzhesr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bdpfx.dat:wxzove -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\belev.dat:cektbj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bfdic.txt:szujrk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bfdic.txt:wjzpfy -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bhamh.log:cgatij -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bhamh.log:mtifzf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bhamh.log:uxdydt -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\biblx.dat:blklag -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\biifc.txt:gkvmsf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\biifc.txt:kxndzt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\biifc.txt:lsnwln -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bivyb.txt:dvisui -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bivyb.txt:vwvffc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bjiuw.dat:eubttp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bjiuw.dat:nhsycu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bjiuw.dat:swimyv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bjiuw.dat:twegcs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bkboq.dat:npypye -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bkboq.dat:oxgshm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bklls.txt:liutza -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bklls.txt:oxgshm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bldch.txt:owaxws -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bldch.txt:uyqvoo -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bldch.txt:wvtyvz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:bphnyj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:dzeoxc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:mxxmwv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:svuggu -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\bncbm.txt:einytl -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bncbm.txt:zqrddz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bnppw.txt:hwedqc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bnppw.txt:snqran -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bnppw.txt:stmohv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\boawa.dat:mnjygt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bootstat.dat:kxarty -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bootstat.dat:uuven -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bootstat.dat:vjcdvu -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\bpkgj.txt:eotdae -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bqddp.log:jvmfnl -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\bqgnt.dat:xpmqcg -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\brcih.dat:kgjwcp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\brcih.dat:wjflvv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\brcrs.txt:cytfvi -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\brcrs.txt:ntsvpl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\brrxe.log:clfrza -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\brrxe.log:ieggek -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\brrxe.log:nzxbre -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\brrxe.log:wgibej -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bsvdd.txt:xyxpcj -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\bvjpx.txt:dgbjwz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bvjpx.txt:fudiso -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bvjpx.txt:umiuhg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bxebd.log:hgaphu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bxebd.log:hliwri -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bxebd.log:kzxbwv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\bzoxd.dat:pkgcsy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cgngz.txt:nkxdwn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cgngz.txt:snxiyo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ckurx.txt:gliqyx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ckurx.txt:zmhsnd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ckwoz.log:ftllnv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\clock.avi:afrtgn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\clock.avi:lninay -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\clock.avi:nnbzjq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\clock.avi:psfscv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\clock.avi:rnaxhn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\clock.avi:siuizn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\clyon.txt:cxqrmt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\clyon.txt:pwdoks -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cmdlx.log:hcqina -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\cmdlx.log:rbtqcb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cmfnf.log:limnby -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\cmwka.log:hxvbed -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cnlkc.txt:kumewe -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\cnlkc.txt:plvtkp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cnqvp.txt:axaecx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cobxl.log:iwirin -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cobxl.log:rltxy -> TrojanDownloader.Agent.jb : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:gkvrxx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:hyhwjj -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:lveuie -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:rbsrpb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:udyxtc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:uyieov -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\COM+.log:hlnges -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\comsetup.log:hsyxfg -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\comsetup.log:jfdvym -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\comsetup.log:ldtiqc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\comsetup.log:zxwsdk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\control.ini:zcpcex -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\control.ini:zylizi -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cpjgj.log:lrdozk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\crae.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crae.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\crnnh.dat:rxgfxv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\csbbg.dat:azvdej -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\csbbg.dat:judekm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\csbbg.dat:lszoaw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\csbbg.dat:ynpnhv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K1.CDF:eemnkn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\CTDV10K1.CDF:hoesfp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K1.CDF:lswjoh -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\CTDV10K1.CDF:nacfad -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K1.CDF:syevck -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K2.CDF:cgvjsx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\CTDV10K2.CDF:nioazv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K2.CDF:snqran -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDV10K2.CDF:ynceph -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:dtrbdh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:enlfvq -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:nlmvxt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:qiwjsd -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:saoigu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:sdhiya -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:txvzpa -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\CTDVAUDY.CDF:vbsho -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\ctirp.txt:aowyzz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\cujqu.log:lqofrk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\cyrmn.log:sppdbj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\czenr.dat:fupzdx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\czenr.dat:kzxbwv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\czenr.dat:qohtbf -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\czenr.dat:waalgz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\czezi.log:xihaox -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\czxcn.txt:ceklnc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\czxcn.txt:pbkyjj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bk.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bk.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\d3di32.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3di32.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\d3ko32.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ko32.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\d3sd32.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sd32.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dahtx.txt:fbulco -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dahtx.txt:kugaoi -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dahtx.txt:nfoots -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dahtx.txt:xjzgux -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\davye.log:ibxfyx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\davye.log:xvifgi -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dbnbw.log:pfpghz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dbnbw.log:vevqpn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dbnbw.log:wsewrg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dbqsz.log:duzgqs -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dbqsz.log:fygtvd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ddcrr.log:ztcics -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ddmxo.txt:suvjfw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\desktop.ini:abqsbz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\desktop.ini:bniuoq -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\desktop.ini:ehujsg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\desktop.ini:entuuj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\desktop.ini:ijowmf -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\desktop.ini:otojti -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\desktop.ini:qjafqa -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\desktop.ini:qoujss -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\DEVREG.DLL:oovkpt -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dgekc.dat:fggbmz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dgekc.dat:hghlbk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dgekc.dat:rtnveu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dgnco.dat:ytrfyq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dhbrd.dat:vlgsom -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\dhbrd.dat:wndzwm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\DHCPUPG.LOG:dqqyyu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dhjdm.log:yhrogk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dilfd.txt:qujsss -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dirdb.txt:rlgzqe -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\DirectX.log:bfopsn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DirectX.log:gmfbsd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DirectX.log:gtdize -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DirectX.log:iindzy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DirectX.log:mhjydj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DirectX.log:pixups -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\DirectX.log:ytnywq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\djnkx.log:ajgibj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dkzel.txt:arpjjf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dlzjw.txt:tkynvt -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dmayu.txt:bwogwl -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\dnivk.dat:sshpdq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dnljn.txt:gbmkrz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\lsp_.dll -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SahHtml_.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHUninstall_.exe -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WEBInstaller.dll -> Adware.SAHA : Cleaned with backup
C:\WINDOWS\DtcInstall.log:hposth -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\DtcInstall.log:jyuua -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\DtcInstall.log:zodhwx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dtifa.txt:nuqxyf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\duxww.dat:dqufcm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\duxww.dat:facext -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\duxww.dat:lssufs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\duxww.dat:ytfylb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\duxww.dat:zwlxpq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dvisu.dat:rowmqh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dxmsz.log:vrekwx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dxmsz.log:zzfddc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dyhas.dat:dtlhzc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\dyhas.dat:modewx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\dyhas.dat:qwxgdv -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\dyhas.dat:tnbira -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ealje.dat:ssyqym -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ebcyc.log:ofpbnr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ebcyc.log:sizxnj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ebcyc.log:ugyuny -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ebcyc.log:zsamjh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\eblqo.txt:nmipiz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\eblqo.txt:rxecjb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\eblqo.txt:xbujzv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\eblqo.txt:ympoug -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ebujr.txt:fporyh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\edxwd.dat:qmvoto -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\edxwd.dat:rvnvjc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\edxwd.dat:skssdj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\eefff.dat:fnsukb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\eefff.dat:hghgiu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\eefff.dat:pjadnl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\egmkj.dat:iksjhv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ehgnv.log:qqwfaw -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\ehgnv.log:rhyipw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ehgnv.log:xmvrbb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\enmak.dat:fsgcll -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\enmak.dat:kiqojh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\enmak.dat:pngeve -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\enmak.dat:upgwkf -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\etlss.txt:zjizhp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\explorer.scf:jzqyal -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\explorer.scf:obqjre -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\explorer.scf:rafovh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\explorer.scf:zcderg -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\eyfvq.log:uilqtf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\failx.dat:skbfkr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fatjg.log:cbbbdr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fatjg.log:nbdvnq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FaxSetup.log:bzmac -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\FaxSetup.log:xsqhfn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FaxSetup.log:ybcmle -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fceea.txt:gaxkqt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fcqwa.log:cmwkae -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fcuai.txt:aipluz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fcuai.txt:jogidm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fddtq.txt:zbppsv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:bzimcv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:guioto -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:kaxupj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:mxmgji -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:opyttf -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:pxlxuq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fedov.log:ggdohg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fedov.log:vnoqcg -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\femvi.dat:skigus -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fexpf.dat:czvisc -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\fexpf.dat:yqsbah -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fflxa.dat:uizdxt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fhltf.dat:ejsizw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fhltf.dat:qhnubj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fhltf.dat:rqlpcs -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fjaym.log:klblou -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fjhzb.log:rianbh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fktfl.txt:awfgva -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fktfl.txt:nvesdd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fltdi.txt:hhyeue -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\flwxp.dat:fwogfn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fmleb.txt:twylxk -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fmleb.txt:zkulsc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fnfqe.dat:jbssvr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\foted.dat:lpiqsn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\foted.dat:qorxwn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fpytb.log:nvqwyq -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\fqwnk.txt:nxgiew -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\fqzzm.log:jpjkyx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\frjjj.dat:mjhejt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\FRONTPG.INI:qcurnh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fsdjh.dat:fkzjle -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fsljv.log:ejcujs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fsljv.log:rikory -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fsljv.log:sjfdta -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fsljv.log:vfiock -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fvveb.txt:easidz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fvveb.txt:oqmkjt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fwkfg.txt:kkxink -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fwvdz.dat:gqfqmd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fwvdz.dat:pmcuir -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fyvsw.txt:hsiftx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fyvsw.txt:ioxoru -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\fzeif.dat:gqxclg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fzeif.dat:pcfnff -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fzeif.dat:pcvbzu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\fztmh.txt:gkrjxl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fztmh.txt:imvhcb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gadvr.log:yuhrxc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gadvr.log:ztbknh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gbtgy.log:fdoquo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gcvpn.dat:zlkozv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gegjb.txt:ruswzm -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gegjb.txt:yrihnj -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ggavq.txt:hicsxn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gglzx.txt:waqyji -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ggwbd.log:kerrqr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ggwbd.log:xegvoz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ghkhc.txt:jvkcuw -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gizpf.log:alsggo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gizpf.log:gwjzub -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gizpf.log:okhwdj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjmtx.dat:bqcqsi -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gjmtx.dat:cejest -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gjmtx.dat:elucwb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjmtx.dat:krqmtr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjmtx.dat:obiels -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gjmtx.dat:sjfdta -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjswa.log:tmdlaq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjzjj.txt:cwdpwz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gjzjj.txt:ewycws -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gjzjj.txt:zwbewe -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gkqym.txt:tagyze -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gntgg.dat:edzyvu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gntgg.dat:wxjhqc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gntgx.txt:kkxink -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gntgx.txt:lbyebp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:darxwu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:etlssl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:hxbmsf -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:hywcpa -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:xekdxf -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:yprzvp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\goriy.txt:gzrfal -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\goriy.txt:rdxnno -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\goriy.txt:sfnsye -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\goriy.txt:urasvb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\goriy.txt:xmfqqd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\goriy.txt:zlxhyx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gqsxx.txt:cgtpdo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:madode -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gskwn.dat:jeiapr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gskwn.dat:kgfyao -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gskwn.dat:svbzdf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gtpjc.log:pvucrm -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gvmqx.log:bphlsh -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\gvmqx.log:rmqmsh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gvmrp.txt:hwnhmw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gvtpi.dat:loadya -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gvtpi.dat:vhecxr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gwdom.log:kwtfxp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gxkgk.log:dgljak -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gxkgk.log:pcohar -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\gyifa.log:wuwxuv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gyzwu.dat:knbaus -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hagio.log:xpwpso -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hagio.log:yyamqu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hawyh.log:duuiqy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hawyh.log:hczmuc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\haxjc.log:cntfou -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hbyvp.txt:gicihr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hbyvp.txt:kpwbkj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hbyvp.txt:pqpvuz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hcfbo.dat:adrzwe -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hcfbo.dat:ihwcbr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hcfbo.dat:ouewsa -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hdavh.txt:axapir -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hdavh.txt:tyluct -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hdkti.dat:yjzswo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hdkti.dat:zjunbu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hdrjx.log:lzdzee -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hetlv.dat:cqooeu -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hetlv.dat:myuddr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hftmu.log:fgnwyz -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hftmu.log:lzdzee -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hftmu.log:rjfawe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hghgi.txt:fzeifc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hghlb.log:jkxgyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hghlb.log:rksgqy -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hghlb.log:sogkfg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hh.exe:rnjeoi -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\hh.exe:yugjol -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\hhlgm.log:ozjdmo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hhvab.log:mjkzkq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hhvab.log:remgva -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hiakj.txt:aipiwt -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hiakj.txt:frvgma -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\hiakj.txt:jbfbcl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hiakj.txt:pnploy -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hiakj.txt:yhfbaj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hjqfm.txt:fkcmnb -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hjqfm.txt:fvwzfc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hjqfm.txt:jfflyk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hjqfm.txt:zatqgq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hjvvv.log:ccpoen -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hkwdf.log:cyxysu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hldib.log:ywonhe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hlgvv.dat:jcxtqj -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hlgvv.dat:mylkgu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hlnpl.log:ebuwkx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hmmgy.dat:amdfeo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hmmgy.dat:dirdbt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hmmgy.dat:qwhsbp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\honwu.txt:ezvpiw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\honwu.txt:lvipyv -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hpinfo.lnk:bdpzkt -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hpinfo.lnk:gygyts -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\hpinfo.lnk:perdmh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hpinfo.lnk:qztskw -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hpinfo.lnk:uakrgy -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hpoxr.dat:bjorux -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\hpoxr.dat:xbfbni -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hrfiy.log:lghlar -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\hrtkn.dat:dwactx -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\htafd.txt:rhbmsp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\htoph.dat:iejqgk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\htoph.dat:pnyktf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\huhka.log:jiurvz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\huhka.log:snnkgy -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\hxvbe.log:uwqmpn -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iajrl.dat:bjiuww -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iajrl.dat:mblypg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iajrl.dat:qhywrh -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iajrl.dat:vicidd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iarkv.dat:pjrioa -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ibbdm.txt:icpmhp -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ibbdm.txt:mauxii -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ibbdm.txt:rvzoqn -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ibbdm.txt:wltihn -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\ibbdm.txt:zyjdmf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ibptc.log:ecedrq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\icbhy.txt:ikkoqk -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\icbhy.txt:imlnct -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\icbzq.txt:agjdps -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Icoadb32.dat:gfpwra -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\Icoadb32.dat:htwovf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Icoadb32.dat:kztldb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Icoadb32.dat:wmlzkd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\icxcv.log:tnrpfi -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepyy.dat:damyfd -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iepyy.dat:fuxspy -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\iepyy.dat:iflfdp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepyy.dat:jzcqoh -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iepyy.dat:xfpqgq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepyy.dat:zuotpp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\ieua.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieua.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\igdlx.log:afvmlo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\igdlx.log:dwfrrb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\igdlx.log:lgjvzl -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\igvpj.log:pxhvia -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iidhm.txt:ukassp -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iiemb.txt:bxekfz -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iiemb.txt:iyajcl -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iiemb.txt:tffrfq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iis6.log:bcokwn -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iis6.log:piloaq -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iis6.log:wterdo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ijfwy.dat:pnyafg -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iljft.txt:ioqfhq -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iljft.txt:wxmlyr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\imsins.log:bauwir -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\imsins.log:ggwesr -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\incfz.log:gaxdis -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\incfz.log:irwkln -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\incfz.log:qvynbh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ioqfh.txt:oqwqsc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\Isdbg.ini:vmwivl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Isdbg.ini:zbijdc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\iueql.dat:hmrmej -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\iueql.dat:iarkvx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iygde.dat:abjpqi -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\izimj.txt:gjajxe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\izimj.txt:nfsakh -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\izwjf.dat:bsopox -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\izwjf.dat:pgupwl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\izwjf.dat:ubfbkc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\izwjf.dat:ygojvc -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:joqtvr -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:kguibd -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:nmbchs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:nzfgfi -> Backdoor.Small.dc : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:ptpwyy -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\JAUTOEXP.INI:xnilwo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxr.dll:ryetqo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxr.dll:yypfyp -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\jbcqt.txt:fngopv -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\jbcqt.txt:gylfej -> TrojanDownloader.Agent.ap : Cleaned with backup
C:\WINDOWS\j
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP