Ok, followed all directions as you said. There was a file that I could not locate in HijackThis..."O4 - HKCU\..\Run: [Aloo] "C:\Program Files\ewrc\rose.exe" -vt mt".
Other than that here are my logs...
smitRem © log file
version 2.7
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 11/26/2005
The current time is: 15:29:22.34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
Security Toolbar
~~~ Shortcuts ~~~
Online Security Center.url
~~~ Favorites ~~~
~~~ system32 folder ~~~
1024 dir
ncompat.tlb
nvctrl.exe
~~~ Icons in System32 ~~~
ts.ico
ot.ico
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
SpyAxeFix © by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 11/26/2005
The current time is: 15:39:15.00
spyaxe directory present
spyaxe uninstaller present
Starting spyaxe uninstaller
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Error, Cannot find a process with an image name of spyaxe.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Killing PID 1732 'explorer.exe'
Killing PID 1732 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003
[email protected]Error, Cannot find a process with an image name of rundll32.exe
svchosts.dll present
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:23:38 PM, 11/26/2005
+ Report-Checksum: D60370BC
+ Scan result:
:mozilla.18:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Findwhat : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.296:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.350:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.351:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.395:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.396:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.397:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.398:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.452:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.492:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.493:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.494:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.498:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.499:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.500:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.538:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.539:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.575:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.576:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.577:C:\Documents and Settings\Will\Application Data\Mozilla\Firefox\Profiles\x8dr96n8.Will\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP103\A0028230.dll -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP103\A0028231.exe -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP104\A0028532.DLL -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP107\A0028804.dll -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP109\A0029844.exe -> Spyware.MediaTickets : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP110\A0030350.exe -> Spyware.MediaTickets : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP113\A0030677.dll -> Adware.SpySheriff : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP117\A0031684.exe -> Not-A-Virus.Hoax.Renos.b : Cleaned with backup
C:\System Volume Information\_restore{EA956626-FEE5-42D2-AF39-E6BD363429F2}\RP117\A0031692.EXE -> TrojanDownloader.Zlob.bj : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 3:23:12 PM, on 11/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Will\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: HomepageBHO - {7caf96a2-c556-460a-988e-76fc7895d284} - C:\WINDOWS\system32\hp9F40.tmp (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [SFPrnmon] C:\PROGRA~1\Simply\Cheymon.exe
O4 - HKLM\..\Run: [CBWUser] "C:\Program Files\Simply\CBWUser.exe"
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [Fellowes Proxy] C:\WINDOWS\System32\r3proxy.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [dEn] C:\documents and settings\will\local settings\temp\dEn.exe
O4 - HKLM\..\Run: [YHGSovI] c:\documents and settings\will\local settings\temp\YHGSovI.exe
O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s
O4 - HKLM\..\Run: [SpyFighterMonitor] "C:\Program Files\SpyFighter\SpyFighter.exe" monitor
O4 - HKLM\..\Run: [SpyFighterUpdate] "C:\Program Files\SpyFighter\AutoUpdate.exe" silent
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1132633144\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com...kup/qdiagcc.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.av.a...83/mcinsctl.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.c...utocomplete.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.av.a...,20/mcgdmgr.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLACSD.EXE
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: CBWAttn - ACCPAC International, Inc. - C:\PROGRA~1\Simply\CBWAttn.exe
O23 - Service: CBWHost - ACCPAC International, Inc. - C:\PROGRA~1\Simply\CBWHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe