Solved: Cant get rid of PSGUARD Desktop HJ - Hijackthis log attatched

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

eric3316

Thread Starter
Joined
Jul 17, 2005
Messages
3
This program has taken over my desktop. It puts a blue screen on my desktop and in the center reads as follows:
A fatal error in IE has occured at 0028:C0011E36 in VXD VMM(01) +
00010E36. Error was caused by Trojan-Spy.html.Smitfraud.c
*System cannot function in normal mode
Please check your security settings.
*Scan your PC with available antivirus / spyware remover program to fix the problem.

I ran spysweeper, spybot, and lavasoft ad-aware. Spysweeper recognizes it but doesnt get rid of it. Here is my Hijackthis log. Appreciate any help I can get on this to avoid reinstalling XP. Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 12:42:16 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ORB Networks\ORB\Cab\MainRegister\CabDirectory.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\ORB Networks\ORB\ORBServices\OrbMediaService\OrbMediaService.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\ORB Networks\ORB\ORBTV\OrbStreamer\rtspServer.exe
C:\Program Files\ORB Networks\ORB\ORBTV\OrbTVXml\OrbTVXML.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Eric & Melissa\My Documents\downloaded stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: CabDirectory - Orb Networks - C:\Program Files\ORB Networks\ORB\Cab\MainRegister\CabDirectory.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - 3am Labs, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - 3am Labs, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: OrbMediaService - Orb Networks - C:\Program Files\ORB Networks\ORB\ORBServices\OrbMediaService\OrbMediaService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 
Joined
Feb 15, 2004
Messages
12,302
hi, welcome to TSG.

go to add/remove and uninstall p2pnetworking, new.net and psguard, delete their folders form C:\program files.




download this in case new.net screws up your internet connection. LSPfix to repair winsock.

http://cexx.org/lspfix.htm




* Click here to download smitRem.zip.


for W2k & XP

http://noahdfear.geekstogo.com/click counter/click.php?id=1





* Save the file to your desktop.
* Unzip smitRem.zip to extract the two files it contains.
* Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.



* Go here to download CCleaner.


http://www.ccleaner.com/


* Install CCleaner
* Launch CCleaner and look in the upper right corner and click on the "Options" button.
* Click "Advanced" and remove the check by "Only delete files in Windows temp folders older than 48 hours".
* Click OK
* Do not run CCleaner yet. You will run it later in safe mode.




* Download the trial version of Ewido Security Suite.



http://www.ewido.net/en/


* Install ewido.
* During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
* Launch ewido
* It will prompt you to update click the OK button and it will go to the main screen
* On the left side of the main screen click update
* Click on Start and let it update.
* DO NOT run a scan yet. You will do that later in safe mode.



* Click here for info on how to boot to safe mode if you don't already know how.


http://service1.symantec.com/SUPPOR...2001052409420406?OpenDocument&src=sec_doc_nam



* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked"



R3 - Default URLSearchHook is missing
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\RunServices: [p2pnetworking] p2pnetworking.exe




* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.



* Run Ewido:

* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop



* Start Ccleaner and click Run Cleaner


* Go to Control Panel > Internet Options. Click on the Programs tab then
click the "Reset Web Settings" button. Click Apply then OK.



* Next go to Control Panel > Display. Click on the "Desktop" tab then click
the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you
should see an entry checked called something like "Security info" or similar.
If it is there, select that entry and click the "Delete" button. Click OK
then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here


http://www.pandasoftware.com/activescan/


When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!



post another hijack this log, the ewido and active scan logs
 
Joined
Feb 15, 2004
Messages
12,302
oops, I should have told you to disable spysweeper, go to start/run/type msconfig/click ok/click startup and uncheck the box for spysweeper and click ok, you can re-enable it after cleaning up the infections !
 

eric3316

Thread Starter
Joined
Jul 17, 2005
Messages
3
Everything wored like a charm. Thanks for the quick response. VEry thankful for it. Here is the HJT log just to make sure everything looks good.
Logfile of HijackThis v1.99.1
Scan saved at 6:42:26 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ORB Networks\ORB\Cab\MainRegister\CabDirectory.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\ORB Networks\ORB\ORBServices\OrbMediaService\OrbMediaService.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\ORB Networks\ORB\ORBTV\OrbStreamer\rtspServer.exe
C:\Program Files\ORB Networks\ORB\ORBTV\OrbTVXml\OrbTVXML.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eric & Melissa\My Documents\downloaded stuff\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/Home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: CabDirectory - Orb Networks - C:\Program Files\ORB Networks\ORB\Cab\MainRegister\CabDirectory.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - 3am Labs, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - 3am Labs, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: OrbMediaService - Orb Networks - C:\Program Files\ORB Networks\ORB\ORBServices\OrbMediaService\OrbMediaService.exe

and the scan report:

+ Created on: 5:07:21 PM, 7/17/2005
+ Report-Checksum: 85D54F84

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKU\S-1-5-21-370030131-3186773635-3883207141-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04079851-5845-4DEA-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKU\S-1-5-21-370030131-3186773635-3883207141-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-370030131-3186773635-3883207141-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-370030131-3186773635-3883207141-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Ne : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.418:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.444:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.445:C:\Documents and Settings\Eric & Melissa\Application Data\Mozilla\Firefox\Profiles\inva4xyj.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\Incomplete\CORRUPT-0-Webroot SpySweeper v4.0.3 Build 405.zip/Setup.exe -> Worm.VB.an : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\Incomplete\CORRUPT-0-Webroot SpySweeper v4.0.3 Build 405.zip/FILE.VBS -> Worm.Gedza : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\Local Settings\Temp\jfgudk.exe -> TrojanDownloader.IstBar.jn : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\My Documents\downloaded stuff\NORTON 2005 - SystemWorks + Internet Security + Ghost 9.0 + GoBack + ALL KEYGENS.rar/NORTON 2005 - SystemWorks + Internet Security + Ghost 9.0 + GoBack + ALL KEYGENS\Norton Internet Security 2005\KEY-GENERATOR NIS 2005\NIS 2005 - Keygen SSG.exe -> TrojanDropper.Delf.fd : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\My Documents\downloaded stuff\NORTON 2005 - SystemWorks + Internet Security + Ghost 9.0 + GoBack + ALL KEYGENS.rar/NORTON 2005 - SystemWorks + Internet Security + Ghost 9.0 + GoBack + ALL KEYGENS\NORTON KEY-GENERATORS\KeyGens Norton 2005\NIS 2005 - Keygen SSG.exe -> TrojanDropper.Delf.fd : Cleaned with backup
C:\Documents and Settings\Eric & Melissa\My Documents\Real One Player Plus 9.0 full+ login crack\RealOne.Player.and.iQfx3.and.vTuner.Plus.v4.0 ( OK! ).zip/RealOne.Player.and.iQfx3.and.vTuner.Plus.v4.0/RealOnePlayer.exe -> Backdoor.Optix.Pro.o : Cleaned with backup
C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL_tobedeleted -> Spyware.MyWay : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\system32\init32ym.exe -> TrojanDownloader.Small.aou : Cleaned with backup
C:\WINDOWS\system32\rebates.exe/rebates.exe -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\system32\rebates.exe/toolbar.exe -> Trojan.Crypt.e : Cleaned with backup


::Report End

I ran the online virus checker and delete the item it said it couldnt which were:

Incident Status Location

Adware:adware/myway No disinfected C:\PROGRAM FILES\MyWay
Adware:adware/wupd No disinfected C:\PROGRAM FILES\winupdate
Adware:adware/savenow No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MAGNET


Thanks again!!!
 
Joined
Feb 15, 2004
Messages
12,302
well done!

clean log.




you should now turn off system restore to flush out the bad restore points and
then re-enable it and make a new clean restore point.


How to turn off system restore

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam


http://support.microsoft.com/default.aspx?scid=kb;[LN];310405



here's some free tools to keep you from getting infected in the future.


to stop reinfection get these two tools, spywareguard and spywareblaster
from

www.javacoolsoftware.com


get the hosts file from here.

put it into :


Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC
Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\ETC
Win 98\ME = C:\WINDOWS

http://www.mvps.org/winhelp2002/hosts.htm


ie-spyad.Puts over 5000 sites in your restricted zone so you'll be protected

when you visit innocent-looking sites that aren't actually innocent at all.

https://netfiles.uiuc.edu/ehowes/www/resource.htm


prevX: it stops spyware

http://www.prevx.com/prevxhome.asp


Use spybot's immunize button and use spywareblaster' enable
protection once you update it. you can put spybot's hosts file into
your own and lock it.



I would also suggest switching to Mozilla's firefox browser, it's safer, has a built in pop up blocker, blocks cookies and adds.

http://www.mozilla.org/


Read here to see how to tighten your security:

http://forums.techguy.org/t208517.html


A good overall guide for firewalls, anti-virus, and anti-trojans as well as
regular spyware cleaners.

http://www.firewallguide.com/anti-trojan.htm



you can mark your own thread solved through thread tools at the top of
the page.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Members online

Top