My computer is infected with some really nastyware. Noticeable symptoms are pop-ups. Looking around other sites, I think I have a look2me/VX2/ActiveX problem, but I don't really know what that means.
I initially downloaded HJT, Adaware, Spybot, Microsoft Antispyware, and AVG. I then added the VX2 Add-on to adaware and attempted to use the L2mfix, unsuccessfully. So I disabled my internet access, went into safemode, and scanned with everything I have.
Unfortunately, most scans have come up with results, and supposedly fixed problems, but the symptoms are still occurring. Now most scans yield no results. However, the Adaware VX2 add-on, which couldn't fix the problem, created this report: "Posssible new VX2 variant file C:\WINDOWS\system32\u4ru0e99eh.dll". Every time I restart my computer and use the add-on, I get a different filename, which I am unable to modify.
I finally scanned my computer with Spyware Doctor and have received a large list of infections. I can't FIX these infections because the SD I downloaded is not registered.
This is the report:
"Scans (basic information only):
Scan Results:
scan start: 09/11/2005 19:58:32
scan stop: 09/11/2005 20:12:58
scanned items: 112696
found items: 121
found and ignored: 0
tools used: General Scanner, Process Scanner, Hosts scanner, LSP Scanner, Registry Scanner, Browser Defaults, Favorites and ZoneMap Scanner, ActiveX Scanner, Browser Activity Scanner, Disk Scanner
Infection Name Location Risk
Azesearch Toolbar HKCR\AzEntretien.Loader High
Azesearch Toolbar HKCR\AzEntretien.Loader## High
Azesearch Toolbar HKCR\AzEntretien.Loader\CLSID High
Azesearch Toolbar HKCR\AzEntretien.Loader\CLSID## High
Azesearch Toolbar HKCR\AzEntretien.Loader\CurVer High
Azesearch Toolbar HKCR\AzEntretien.Loader\CurVer## High
Azesearch Toolbar HKLM\SOFTWARE\AzEntretienCo High
Azesearch Toolbar HKLM\SOFTWARE\AzEntretienCo## High
Azesearch Toolbar HKLM\SOFTWARE\AzEntretienCo\AzEntretien High
Azesearch Toolbar HKLM\SOFTWARE\AzEntretienCo\AzEntretien## High
Azesearch Toolbar HKLM\SOFTWARE\AzEntretienCo\AzEntretien##skip High
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920} Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}## Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##Contact Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##DisplayName Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##DisplayVersion Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##NoModify Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##NoRemove Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##NoRepair Elevated
I-Search Desktop Search Toolbar HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}##UninstallString Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService## Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##Type Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##Start Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ErrorControl Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ImagePath Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##DisplayName Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ObjectName Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security## Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Security##Security Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum## Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##0 Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##Count Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##NextInstance Elevated
TargetSavers HKCU\Software\tsl2 High
TargetSavers HKCU\Software\tsl2## High
TargetSavers HKCU\Software\tsl2##Tsl2HWND High
7AdPower HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D62A517-E7C6-4E1F-A577-07D4AC549A48} Medium
7AdPower HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D62A517-E7C6-4E1F-A577-07D4AC549A48}\iexplore Medium
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D2DEF3A-F4F1-42EC-AC4F-132E7BA6E292} High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D2DEF3A-F4F1-42EC-AC4F-132E7BA6E292}\iexplore High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A19EF336-01D4-48E6-926A-FE7E1C747AED} High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A19EF336-01D4-48E6-926A-FE7E1C747AED}\iexplore High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4} High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4}\iexplore High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F65B197F-8260-4D52-909A-F70118E646EB} High
Azesearch Toolbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F65B197F-8260-4D52-909A-F70118E646EB}\iexplore High
Common Components for AZE nEtwork HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7BF3304-138B-4DD5-86EE-491BB6A2286C} Medium
Common Components for AZE nEtwork HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D7BF3304-138B-4DD5-86EE-491BB6A2286C}\iexplore Medium
Common Components for WindUpdates HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} Medium
Common Components for WindUpdates HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}\iexplore Medium
ISTbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} High
ISTbar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}\iexplore High
MediaGateway HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} Elevated
MediaGateway HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}\iexplore Elevated
YourSiteBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658} High
YourSiteBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\iexplore High
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\starware[1].css Low
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\yyy65[1].htm High
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\weather_01[1].gif Low
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\laptop[1].swf High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\dating03[1].swf High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\get[1].media High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\laptop[1].rgn High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\pc[1].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\PopupV2A[1].htm High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\get[1].media High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\PopupV2A[4].htm High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\457[1].gif High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\cellphones02[1].swf High
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\weather_01[1].htm Low
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\PopupV2A[4].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\PopupV2A[1].htm High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\banner_728x90_carnival_gun(ipod)[1].swf High
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\hbx[1].js Low
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\internet05[1].rgn High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\PopupV2A[2].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\PopupV2A[4].htm High
Affiliated with Browser Hijackers C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\index[6].htm Elevated
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\v4flash[1].js High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\internet05[1].swf High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\cellphones02[1].rgn High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\PopupV2A[3].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\PopupV2A[3].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\PopupV2A[2].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\dating03[1].rgn High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\PopupV2A[3].htm High
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\PopupV2A[5].htm High
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\orca-screen[1].jpg Medium
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\PopupV2A[1].htm High
Affiliated with Browser Hijackers C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\index[5].htm Elevated
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\PopupV2A[2].htm High
Affiliated with Browser Hijackers C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\index[3].htm Elevated
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\auto02[1].jpg Medium
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\bella18[1].jpg Medium
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\manga[1].jpg Medium
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\PopupV2A[4].htm High
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\002[1].jpg Medium
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\PopupV2A[6].htm High
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\UPKXMT67\get[1].htm High
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OPER4TIV\celbr[1].jpg Medium
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\tombraider-screen[1].jpg Medium
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\GHMZGHER\fantasy[1].jpg Medium
7AdPower C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\send_ocx_sof[1].htm Medium
VX2.Look2Me C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\PopupV2A[1].htm High
Affiliated with Browser Hijackers C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXU3G9UN\index[10].htm Elevated
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Cookies\captain [email]awesome@www.starware[1].txt[/email] Low
Known Bad Sites C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Cookies\captain [email]awesome@landing.domainsponsor[1].txt[/email] High
Starware C:\DOCUME~1\CAPTAI~1\LOCALS~1\Temp\Cookies\captain [email]awesome@h.starware[2].txt[/email] Low
Azesearch Toolbar C:\WINDOWS\azesearch.bmp High
Zestyfind C:\WINDOWS\icont.exe Elevated
SP2Update C:\WINDOWS\teller2.chk High
VX2.Look2Me C:\installer.exe High
TargetSavers C:\Program Files\Common Files\muoz\muozd\class-barrel High
TargetSavers C:\Program Files\Common Files\muoz\muozd\vocabulary High
TargetSavers C:\Program Files\Common Files\muoz\muozp.exe High
I-Search Desktop Search Toolbar C:\RECYCLER\S-1-5-21-4267727553-162614391-1580500317-1006\Dc12.dll Elevated
I-Search Desktop Search Toolbar C:\RECYCLER\S-1-5-21-4267727553-162614391-1580500317-1006\Dc13._ Elevated
ISTbar C:\regular_plugin.exe High
Other Sections:
Copyright © 2003 PC Tools Research Pty Ltd. All rights reserved. Legal Notice "
I also have Finditnt2000xp and Hijack This!, and I can post those results if anyone requires them.
I would be incredibly grateful if someone could please help me out with getting rid of the adware/trojan/spawnofhell
Thanks for your time.
EDIT: I also made sure that all hidden folders were viewable, and all extensions and files were viewable before scanning.