This just won't end! :twisted:
Here are the logs:
1) HJT
2) Ewido
3) Find_qoologic - I did not have any of the log files that you mentioned C:\log.txt , C:\win.txt or C:\start.txt. But there was a log file that was in the folder - file.txt so I included that one. Let me know if you think I did it incorrectly or need to run it again.
Thanks
Logfile of HijackThis v1.99.1
Scan saved at 10:34:11 PM, on 8/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Citvirus\scae2nls.exe
C:\WINDOWS\System32\dfrpsvcs.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\UAService7.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Kodak\KODAK Picture Transfer Software\pts.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{CC8C8F4F-F2E8-404B-A43D-5CC57876A008} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: XBTP07618 - {2296428D-C133-4928-B76A-A200FF409572} - C:\PROGRA~1\FREEPR~1\freeprod.dll
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\ylthpdta.dll (file missing)
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\System32\nsf5B.dll (file missing)
O3 - Toolbar: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Freeprod Toolbar\freeprod.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [qbet] C:\WINDOWS\qbet.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Io02RRM3V] atrivs.exe
O4 - HKCU\..\Run: [kbdsp] C:\WINDOWS\System32\kbdsp.exe
O4 - Startup: Compaq Organize.lnk = ?
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: KODAK Picture Transfer Software.lnk = ?
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4561/mcfscan.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\System32\UAService7.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:06:37 PM, 8/26/2005
+ Report-Checksum: BA38DC62
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\PopOops2.PopOops\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\SWLAD1.SWLAD\Clsid -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9} -> Spyware.AdDestroyer : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52} -> Spyware.AdDestroyer : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\raui.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@rotator.adjuggler[2].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/iemui.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/nbdenb32.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/nbwdev.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/nkrsda.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/onpdx32.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/pzlstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/rPsapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/sNfrcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/ufiime.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/uoiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\l2mfix\backup.zip/guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\nsh_105.exe -> Spyware.Downloadware : Cleaned with backup
C:\Program Files\180searchassistant\salm.exe -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Cas\Client\casclient.exe -> Spyware.CASClient : Cleaned with backup
C:\Program Files\CasStub\casstub.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\Program Files\Media Access\MediaAccC.dll -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Media Access\MediaAccess.exe -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Media Access\MediaAccK.exe -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Media Gateway\MediaGateway.exe -> Spyware.WinAD : Cleaned with backup
C:\RECYCLER\NPROTECT\00009092 -> Spyware.180Solutions : Cleaned with backup
C:\RECYCLER\NPROTECT\00009098 -> Spyware.180Solutions : Cleaned with backup
C:\RECYCLER\NPROTECT\00009111 -> Spyware.CASClient : Cleaned with backup
C:\RECYCLER\NPROTECT\00009117 -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\RECYCLER\NPROTECT\00009339.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00009603.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00009604.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00009639.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\RECYCLER\NPROTECT\00009643.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\RECYCLER\NPROTECT\00009690.EXE -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00009705.EXE -> Adware.BetterInternet : Cleaned with backup
C:\RECYCLER\NPROTECT\00009813.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00009823.DLL -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00009833.dll -> Spyware.EliteBar : Cleaned with backup
C:\RECYCLER\NPROTECT\00009834.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00009869.cab/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\RECYCLER\NPROTECT\00009875.dll -> Spyware.180Solutions : Cleaned with backup
C:\RECYCLER\NPROTECT\00009941.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010037.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00010256.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00010259.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010300.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00010303.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010379.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00010380.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010468.DLL -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010552.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00010553.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010591.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010592.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010593.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010594.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010595.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010596.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010597.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010598.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010599.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010600.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/iemui.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/nbdenb32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/nbwdev.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/nkrsda.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/onpdx32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/pzlstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/rPsapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/sNfrcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/ufiime.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010601.zip/uoiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/iemui.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/nbdenb32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/nbwdev.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/nkrsda.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/onpdx32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/pzlstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/rPsapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/sNfrcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/ufiime.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/uoiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010603.zip/guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/iemui.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/nbdenb32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/nbwdev.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/nkrsda.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/onpdx32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/pzlstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/rPsapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/sNfrcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/ufiime.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/uoiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010606.zip/guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/iemui.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/nbdenb32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/nbwdev.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/nkrsda.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/onpdx32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/pzlstore.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/rPsapi32.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/sNfrcdlg.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/ufiime.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/uoiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010608.zip/guard.tmp -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010804.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010805.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010806.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010807.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010808.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010809.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010810.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010811.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010812.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00010813.dll -> Spyware.Look2Me : Cleaned with backup
C:\RECYCLER\NPROTECT\00011060.exe -> Trojan.Agent.gp : Cleaned with backup
C:\RECYCLER\NPROTECT\00011095.exe -> Trojan.Agent.gp : Cleaned with backup
C:\Temp\Installer.exe -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\etb\nt_hide63.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\pokapoka63.exe -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\etb\xud_63.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\nqhpozgaz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system\eiicupd.exe -> TrojanDownloader.Small.ayh : Cleaned with backup
C:\WINDOWS\system32\adlinstallwin32.exe -> Spyware.Downloadware : Cleaned with backup
C:\WINDOWS\system32\daxmqox.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\system32\exp.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\system32\halpum.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\WINDOWS\system32\ikgsv.dll -> TrojanDownloader.Qoologic.t : Cleaned with backup
C:\WINDOWS\system32\lanbrup.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\MTE2ODM6ODoxNg.exe -> Spyware.ISearch : Cleaned with backup
C:\WINDOWS\system32\nkyicuy.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\WINDOWS\system32\nsf5B.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\Pop1A.exe -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\system32\PSof1.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\system32\redit.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\tnddd.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\uci.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\wintask.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\system32\wugky.dat -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\WINDOWS\system32\ygqfgx.exe -> Trojan.Agent.gp : Cleaned with backup
C:\WINDOWS\system32\ylthpdta.dll -> Spyware.SafeSurfing : Cleaned with backup
::Report End
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
some examples are MRT.EXE NTDLL.DLL.
»»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
* web-nex C:\WINDOWS\MNRZV.DLL
»»»»»»»»»»»»»»»»»»»»»»»» Packed files »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
* UPX! C:\WINDOWS\System32\MC-110~1.EXE
* UPX! C:\WINDOWS\DEL.TMP
* UPX! C:\WINDOWS\RMAGEN~1.DLL
* UPX! C:\WINDOWS\TSC.EXE
* UPX! C:\WINDOWS\VSAPI32.DLL
* aspack C:\WINDOWS\AUREXKB.EHU
* aspack C:\WINDOWS\VSAPI32.DLL
* ASProtect C:\WINDOWS\AUREXKB.EHU
»»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»
(fstarts by IMM - test ver. 0.001) NOT using address check -- 0x77f75fae
Global Startup:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
.
..
Compaq Connections.lnk
desktop.ini
KODAK Picture Transfer Software.lnk
KODAK Software Updater.lnk
Microsoft Office.lnk
Quicken Scheduled Updates.lnk
User Startup:
C:\Documents and Settings\Owner\Start Menu\Programs\Startup
.
..
Compaq Organize.lnk
desktop.ini
spamsubtract.lnk