Spyware? Need some professional help! 2nd computer.

Here is the HJT logfile:


Logfile of HijackThis v1.99.1
Scan saved at 11:41:08 AM, on 7/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\rrmkmn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
c:\program files\mcafee.com\vso\mcmnhdlr.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rrmkmn.exe reg_run
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\oybcbcp.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)

Comments

  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited July 2005
    Download rkfiles.zip
    http://skads.org/special/rkfiles.zip
    Unzip the contents to a permanent folder.

    Reboot your computer into Safe Mode


    Doubleclick rkfiles.bat
    It will scan for a while, so please be patient.
    Wait till the DOS window closes and reboot back to normal mode.

    Post the contents of C:\log.txt in your next reply.
  • edited July 2005
    here is the contents of C:\log.txt:


    C:\Documents and Settings\Compaq_Owner\Desktop\rkfiles

    PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
    Files Found in system Folder............
    C:\WINDOWS\system32\dfrg.msc: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAwGpEc213

    Files Found in all users startup Folder............
    Files Found in all users windows Folder............
    C:\WINDOWS\ru.exe: UPX!
    Finished
    bye
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited July 2005
    Please make sure that you can VIEW ALL HIDDEN FILES.

    Place a checkmark next to these entries, close all browsers and windows, and have HijackThis fix them by clicking Fix Checked:

    O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rrmkmn.exe reg_run
    O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\oybcbcp.dll
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)


    Reboot your computer into SAFE MODE

    Then delete these files or directories (Do not be concerned if they do not exist):

    C:\WINDOWS\cfgmgr52.dll
    C:\WINDOWS\system32\rrmkmn.exe
    C:\WINDOWS\system32\oybcbcp.dll
    C:\WINDOWS\svcproc.exe
    C:\WINDOWS\ru.exe


    Reboot your computer to go back to normal mode and post a new log.
  • edited July 2005
    alright it wouldn't let me delete C:\WINDOWS\system32\rrmkmn.exe, and here is my latest HJT file:


    Logfile of HijackThis v1.99.1
    Scan saved at 5:07:57 PM, on 7/12/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\BullsEye Network\bin\bargains.exe
    C:\Program Files\NaviSearch\bin\nls.exe
    C:\WINDOWS\system32\rrmkmn.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\ornu\nslo.exe
    C:\WINDOWS\system32\w?crtupd.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.exactsearch.net/sidesearch
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\system32\nvms.dll
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\system32\mscb.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
    O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
    O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
    O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rrmkmn.exe reg_run
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Srro] C:\Program Files\ornu\nslo.exe
    O4 - HKCU\..\Run: [Skmmjpex] C:\WINDOWS\system32\w?crtupd.exe
    O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
    O20 - Winlogon Notify: App Paths - C:\WINDOWS\system32\escapi.dll
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited July 2005
    Your latest log shows several new infections that weren't there before.

    Please download FindQoologic from here:
    http://forums.net-integration.net/index.php?act=Attach&type=post&id=134981
    Save it to the desktop and run Find-Qoologic2.bat. This will generate a log file; please post the entire contents of the log file here for me to see.



    Run Hijackthis. Click on "Open the Misc Tools section". Next click on "Open uninstall manager".
    Press the button 'save list'. It will open a Notepad file. Place the content of that file here in your in your next post.
  • edited July 2005
    that link doesnt work any longer..
  • edited July 2005
    ok here you...


    PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
    some examples are MRT.EXE NTDLL.DLL.
    »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    * web-nex C:\WINDOWS\JJKAK.DLL
    »»»»»»»»»»»»»»»»»»»»»»»» Packed files »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    * aspack C:\WINDOWS\System32\PPVQV.DAT
    * aspack C:\WINDOWS\System32\BBOCORM.EXE
    * aspack C:\WINDOWS\System32\MRT.EXE
    * aspack C:\WINDOWS\System32\RRMKMN.EXE
    * aspack C:\WINDOWS\System32\REDIT.CPL
    »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    * exe C:\docume~1\alluse~1\startm~1\programs\startup\NNTD.EXE

    »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

    (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

    Global Startup:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    .
    ..
    desktop.ini
    Kodak EasyShare software.lnk
    nntd.exe

    User Startup:
    C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup
    .
    ..
    Connection Manager.lnk
    desktop.ini




    Ad-Aware SE Personal
    Adobe Acrobat - Reader 6.0.2 Update
    Adobe Reader 6.0.1
    Agere Systems PCI Soft Modem
    AOL Instant Messenger
    CardRd81
    CCHelp
    CCScore
    CR2
    ESSAdpt
    ESSANUP
    ESSBrwr
    ESSCAM
    ESSCDBK
    ESScore
    ESSCT
    ESSgui
    ESShelp
    ESSini
    ESSPCD
    ESSPDock
    ESSSONIC
    ESSTUTOR
    ESSvpaht
    ESSvpot
    HijackThis 1.99.1
    HLPCCTR
    HLPIndex
    HLPPDOCK
    HLPRFO
    hp deskjet 656c series (Remove only)
    Intel(R) Extreme Graphics Driver
    InterVideo WinDVD Player
    iTunes
    Java 2 Runtime Environment, SE v1.4.2_03
    Kodak EasyShare software
    KSU
    Macromedia Shockwave Player
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB886903)
    Microsoft Office Standard Edition 2003
    Microsoft Picture It! Express 7.0
    Microsoft Plus! Dancer LE
    Microsoft Plus! Digital Media Edition Installer
    Microsoft Plus! Photo Story 2 LE
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Works 7.0
    Mozilla Firefox (1.0.4)
    MSN Messenger 7.0
    neXBC 5.0
    Notifier
    OIN
    OTtBP
    OTtBPSDK
    PCDLNCH
    PC-Doctor for Windows
    PS2
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QuickTime
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB903235)
    SFR
    SFR2
    Spybot - Search & Destroy 1.4
    SpywareBlaster v3.4
    Update for Windows XP (KB898461)
    VCAMCEN
    VPRINTOL
    WavePad Uninstall
    Windows Installer 3.1 (KB893803)
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB834707
    Windows XP Hotfix - KB867282
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890047
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB890923
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Windows XP Hotfix - KB893086
    WinPcap 3.1 beta4
    XLink Kai Evolution 7
  • Buckeye_SamBuckeye_Sam Columbus, Ohio
    edited July 2005
    Download the Pocket Killbox.

    Unzip the contents of KillBox.zip to a convenient location and then double-click on KillBox.exe to launch the program.
    • Highlight the lines below and press the Ctrl key and the C key at the same time to copy them to the clipboard:


        C:\WINDOWS\JJKAK.DLL
        C:\WINDOWS\System32\PPVQV.DAT
        C:\WINDOWS\System32\BBOCORM.EXE
        C:\WINDOWS\System32\RRMKMN.EXE
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NNTD.EXE

      [*]Now go to the Killbox application and click on the File menu and then the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you dropdown that box you should see the rest of them. Make sure that they are all there.
      [*]Click on the Delete on Reboot option and then click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

      Your system will reboot now.



      After rebooting please post a new hijackthis log and a new findqoologic log.
    • edited July 2005
      ok here are the 2 log files:



      Logfile of HijackThis v1.99.1
      Scan saved at 6:37:14 PM, on 7/12/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\ornu\nslo.exe
      C:\WINDOWS\system32\w?crtupd.exe
      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      C:\WINDOWS\system32\drivers\KodakCCS.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rrmkmn.exe reg_run
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Srro] C:\Program Files\ornu\nslo.exe
      O4 - HKCU\..\Run: [Skmmjpex] C:\WINDOWS\system32\w?crtupd.exe
      O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
      O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
      O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
      O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
      O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\escapi.dll
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
      O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)





      PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
      some examples are MRT.EXE NTDLL.DLL.
      »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      »»»»»»»»»»»»»»»»»»»»»»»» Packed files »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

      * aspack C:\WINDOWS\System32\MRT.EXE
      * aspack C:\WINDOWS\System32\REDIT.CPL
      »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


      »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»»

      (fstarts by IMM - test ver. 0.001) NOT using address check -- 0x7c90df5e

      Global Startup:
      C:\Documents and Settings\All Users\Start Menu\Programs\Startup
      .
      ..
      desktop.ini
      Kodak EasyShare software.lnk

      User Startup:
      C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup
      .
      ..
      Connection Manager.lnk
      desktop.ini
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      Please make sure that you can VIEW ALL HIDDEN FILES.

      Place a checkmark next to these entries, close all browsers and windows, and have HijackThis fix them by clicking Fix Checked:

      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\rrmkmn.exe reg_run
      O4 - HKCU\..\Run: [Srro] C:\Program Files\ornu\nslo.exe
      O4 - HKCU\..\Run: [Skmmjpex] C:\WINDOWS\system32\w?crtupd.exe
      O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\escapi.dll
      O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)


      Reboot your computer into SAFE MODE

      Then delete these files or directories (Do not be concerned if they do not exist):

      C:\Program Files\ornu\nslo.exe
      C:\WINDOWS\system32\w?crtupd.exe
      C:\WINDOWS\system32\escapi.dll


      Reboot your computer to go back to normal mode.




      Please run at least two of these online scans.
      Make sure they are set to clean automatically

      Panda Virus Scan

      Bit Defender

      TrendMicro Housecall

      There will be files that these scans will not remove. Please include that information in your next post.


      Reboot and post a new hijackthis log and the info from your virus scans.
    • edited July 2005
      here are the latest log files:


      Logfile of HijackThis v1.99.1
      Scan saved at 9:05:15 PM, on 7/12/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      C:\WINDOWS\system32\drivers\KodakCCS.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
      O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
      O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
      O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
      O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\escapi.dll
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
      O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)





      Incident Status Location

      Adware:Adware/PurityScan No disinfected Windows Registry
      Adware:Adware/Sqwire No disinfected C:\WINDOWS\system32\tsuninst.exe
      Adware:Adware/SideFind No disinfected Windows Registry
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\guard.tmp
      Adware:Adware/WUpd No disinfected C:\Program Files\windows adservice
      Adware:Adware/Coupons No disinfected Windows Registry
      Adware:Adware/Beginto No disinfected C:\WINDOWS\system32\cache32_rtneg?
      Adware:Adware/Kingporn No disinfected C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\ExtractDLL.dll
      Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Compaq_Owner\Application Data\sskknwrd.dll
      Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\Compaq_Owner\Favorites\1111\1111.url
      Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Sskcwrd.dll
      Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Sskknwrd.dll
      Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Sskuknwrd.dll
      Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\Compaq_Owner\Favorites\1111\1111.url
      Spyware:Spyware/SafeSurf No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\ExtractDLL.dll
      Adware:Adware/Look2Me No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\upd207.exe
      Adware:Adware/Transponder No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\8LUVKDEN\DrPMon[1].dll
      Adware:Adware/Look2Me No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\GD8Z4Z8J\upd206[1].exe
      Adware:Adware/Look2Me No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\I9WJ0NIB\upd207[1].exe
      Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Ssk.log
      Adware:Adware/Coupons No disinfected C:\WINDOWS\cpbrkpie.ocx
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system\UpdInst.exe
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\guard.tmp
      Spyware:Spyware/SafeSurf No disinfected C:\WINDOWS\system32\InstallerV3.exe
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\mqxml.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsc2F.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsd24.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsg3C.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsn36.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nso2A.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nss18.dll
      Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsy1E.dll
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\rcchost.dll
      Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\redit.cpl
      Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\rrueuoi.dll
      Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\Shex.exe
      Adware:Adware/Sqwire No disinfected C:\WINDOWS\system32\tsuninst.exe
      Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\uunrn.dll
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\system32\whnetmgr.dll
      Adware:Adware/ConsumerAlertSystemNo disinfected C:\WINDOWS\Temp\cassetup.exe
      Adware:Adware/AdBehavior No disinfected C:\WINDOWS\Temp\f5688671.exe
      Spyware:Spyware/Overpro No disinfected C:\WINDOWS\Temp\nsdtmp09.dll
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\45QVC5ER\webservice[6].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\45QVC5ER\webservice[8].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\45QVC5ER\webservice[9].htm
      Adware:Adware/ConsumerAlertSystemNo disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\C52RKHQ3\cassetup[2].exe
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\C52RKHQ3\webservice[3].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\C52RKHQ3\webservice[4].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[10].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[2].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[3].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[4].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[6].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[8].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\CT6JKP2V\webservice[9].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G1EJGL2R\webservice[10].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G1EJGL2R\webservice[4].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G1EJGL2R\webservice[5].htm
      Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\G1EJGL2R\webservice[9].htm
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\Temp\upd206.exe
      Adware:Adware/Look2Me No disinfected C:\WINDOWS\Temp\upd207.exe
    • Buckeye_SamBuckeye_Sam Columbus, Ohio
      edited July 2005
      We're making progress, but still some work to be done. And I see something new that we'll have to address.


      Please download, install, and run Cleanup 4.0
      This will remove all of your temp files.
      http://cleanup.stevengould.org/


      =========


      Download the Pocket Killbox.

      Unzip the contents of KillBox.zip to a convenient location and then double-click on KillBox.exe to launch the program.
      • Highlight the lines below and press the Ctrl key and the C key at the same time to copy them to the clipboard:


          C:\WINDOWS\system32\tsuninst.exe
          C:\Documents and Settings\Compaq_Owner\Application Data\sskknwrd.dll
          C:\Documents and Settings\Compaq_Owner\Favorites\1111\1111.url
          C:\Documents and Settings\Compaq_Owner\Application Data\Sskcwrd.dll
          C:\Documents and Settings\Compaq_Owner\Application Data\Sskknwrd.dll
          C:\Documents and Settings\Compaq_Owner\Application Data\Sskuknwrd.dll
          C:\WINDOWS\cpbrkpie.ocx
          C:\WINDOWS\system\UpdInst.exe
          C:\WINDOWS\system32\InstallerV3.exe
          C:\WINDOWS\system32\mqxml.dll
          C:\WINDOWS\system32\nsc2F.dll
          C:\WINDOWS\system32\nsd24.dll
          C:\WINDOWS\system32\nsg3C.dll
          C:\WINDOWS\system32\nsn36.dll
          C:\WINDOWS\system32\nso2A.dll
          C:\WINDOWS\system32\nss18.dll
          C:\WINDOWS\system32\nsy1E.dll
          C:\WINDOWS\system32\rcchost.dll
          C:\WINDOWS\system32\redit.cpl
          C:\WINDOWS\system32\rrueuoi.dll
          C:\WINDOWS\system32\Shex.exe
          C:\WINDOWS\system32\tsuninst.exe
          C:\WINDOWS\system32\uunrn.dll
          C:\WINDOWS\system32\whnetmgr.dll

        [*]Now go to the Killbox application and click on the File menu and then the Paste from Clipboard menu item. In the Full Path of File to Delete box you should see the first file. If you dropdown that box you should see the rest of them. Make sure that they are all there.
        [*]Click on the Delete on Reboot option and then click on the red circle with a white 'X' in to to delete the files. Killbox will tell you that all listed files will be deleted on next reboot, click YES. When it asks if you would like to Reboot now, click YES. If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

        Your system will reboot now.


        ===========


        Download L2mfix from one of these two locations:

        http://www.atribune.org/downloads/l2mfix.exe
        http://www.downloads.subratam.org/l2mfix.exe

        Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

        IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
      • edited July 2005
        here is the log



        L2MFIX find log 1.03
        These are the registry keys present
        **********************************************************************************
        Winlogon/notify:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Controls Folder]
        "Asynchronous"=dword:00000000
        "DllName"="C:\\WINDOWS\\system32\\djsapi.dll"
        "Impersonate"=dword:00000000
        "Logon"="WinLogon"
        "Logoff"="WinLogoff"
        "Shutdown"="WinShutdown"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        **********************************************************************************
        useragent:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "{138AAEB3-628B-934D-1F96-02B6C4A4E3ED}"=""

        **********************************************************************************
        Shell Extension key:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
        "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
        "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
        "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
        "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
        "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
        "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
        "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
        "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
        "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
        "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
        "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
        "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
        "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
        "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
        "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
        "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
        "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
        "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
        "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
        "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
        "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
        "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
        "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
        "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
        "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
        "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
        "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
        "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
        "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
        "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
        "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
        "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
        "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
        "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
        "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
        "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
        "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
        "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
        "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
        "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
        "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
        "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
        "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
        "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
        "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
        "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
        "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
        "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
        "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
        "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
        "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
        "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
        "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
        "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
        "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
        "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
        "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
        "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
        "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
        "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
        "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
        "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
        "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
        "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
        "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
        "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
        "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
        "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
        "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
        "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
        "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
        "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
        "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
        "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
        "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
        "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
        "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
        "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
        "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
        "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
        "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
        "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
        "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
        "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
        "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
        "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
        "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
        "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
        "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
        "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
        "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
        "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
        "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
        "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
        "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
        "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
        "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
        "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
        "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
        "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
        "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
        "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
        "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
        "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
        "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
        "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
        "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
        "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
        "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
        "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
        "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
        "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
        "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
        "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
        "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
        "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
        "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
        "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
        "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
        "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
        "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
        "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
        "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
        "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
        "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
        "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
        "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
        "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
        "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
        "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
        "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
        "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
        "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
        "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
        "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
        "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
        "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
        "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
        "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
        "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
        "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
        "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
        "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
        "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
        "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
        "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
        "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
        "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
        "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
        "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
        "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
        "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
        "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
        "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
        "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
        "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
        "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
        "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
        "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
        "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
        "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
        "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
        "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
        "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
        "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
        "{00020D75-0000-0000-C000-000000000046}"="Microsoft Office Outlook Desktop Icon Handler"
        "{0006F045-0000-0000-C000-000000000046}"="Microsoft Office Outlook Custom Icon Handler"
        "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
        "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}"="SampleView"
        "{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
        "{e57ce731-33e8-4c51-8354-bb4de9d215d1}"="Universal Plug and Play Devices"
        "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
        "{7AFF04D1-6742-46C3-9BE2-20751D7A543B}"=""
        "{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}"=""
        "{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}"=""

        **********************************************************************************
        HKEY ROOT CLASSIDS:
        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{7AFF04D1-6742-46C3-9BE2-20751D7A543B}]
        @=""
        "IDEx"="ST"

        [HKEY_CLASSES_ROOT\CLSID\{7AFF04D1-6742-46C3-9BE2-20751D7A543B}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{7AFF04D1-6742-46C3-9BE2-20751D7A543B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{7AFF04D1-6742-46C3-9BE2-20751D7A543B}\InprocServer32]
        @="C:\\WINDOWS\\system32\\rzutetab.dll"
        "ThreadingModel"="Apartment"

        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}\InprocServer32]
        @="C:\\WINDOWS\\system32\\hZl.dll"
        "ThreadingModel"="Apartment"

        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}\InprocServer32]
        @="C:\\WINDOWS\\system32\\kpdfr.dll"
        "ThreadingModel"="Apartment"

        **********************************************************************************
        Files Found are not all bad files:

        C:\WINDOWS\SYSTEM32\
        browseui.dll Mon May 2 2005 4:52:34p A.... 1,019,904 996.00 K
        cdfview.dll Mon May 2 2005 4:52:34p A.... 151,040 147.50 K
        cdm.dll Thu May 26 2005 4:16:24a A.... 75,544 73.77 K
        cofview.dll Mon Jul 11 2005 5:07:56p ..S.R 417,792 408.00 K
        cwtsrvps.dll Mon Jul 11 2005 5:08:00p ..S.R 417,792 408.00 K
        djsapi.dll Thu Jul 14 2005 2:11:10p ..S.R 417,792 408.00 K
        drrawex.dll Tue Jul 12 2005 4:29:20p ..S.R 417,792 408.00 K
        escapi.dll Mon Jul 11 2005 9:38:26p ..S.R 417,792 408.00 K
        hhsetup.dll Thu May 26 2005 10:04:28p A.... 41,472 40.50 K
        icm32.dll Tue Jun 28 2005 9:46:00p A.... 254,976 249.00 K
        iepeers.dll Mon May 2 2005 4:52:34p A.... 250,880 245.00 K
        inseng.dll Mon May 2 2005 4:52:34p A.... 96,256 94.00 K
        itircl.dll Thu May 26 2005 10:04:28p A.... 155,136 151.50 K
        itss.dll Thu May 26 2005 10:04:28p A.... 137,216 134.00 K
        iuengine.dll Thu May 26 2005 4:16:24a A.... 198,424 193.77 K
        ixked.dll Tue Jul 12 2005 3:54:30p ..S.R 417,792 408.00 K
        kmdfr.dll Tue Jul 12 2005 6:35:46p ..S.R 417,792 408.00 K
        kndit142.dll Mon Jul 11 2005 7:24:58p ..S.R 417,792 408.00 K
        kodit142.dll Mon Jul 11 2005 7:24:54p ..S.R 417,792 408.00 K
        kpdfr.dll Thu Jul 14 2005 3:36:46p ..S.R 417,792 408.00 K
        ldhsvc.dll Thu Jul 14 2005 7:39:18a ..S.R 417,792 408.00 K
        mgdtctm.dll Mon Jul 11 2005 8:31:26p ..S.R 417,792 408.00 K
        mocorier.dll Mon Jul 11 2005 8:31:30p ..S.R 417,792 408.00 K
        mscms.dll Tue Jun 28 2005 9:46:00p A.... 74,240 72.50 K
        mshtml.dll Mon May 2 2005 4:52:36p A.... 3,012,608 2.87 M
        mshtmled.dll Mon May 2 2005 4:52:36p A.... 448,512 438.00 K
        msi.dll Wed May 4 2005 2:45:32p A.... 2,890,240 2.75 M
        msrating.dll Mon May 2 2005 4:52:36p A.... 146,432 143.00 K
        pngfilt.dll Mon May 2 2005 4:52:36p A.... 39,424 38.50 K
        redtrsha.dll Sat Jun 25 2005 1:43:32p A.... 417,792 408.00 K
        rzutetab.dll Mon Jul 11 2005 11:56:50a A.... 417,792 408.00 K
        shdocvw.dll Mon May 2 2005 4:52:36p A.... 1,483,776 1.41 M
        shlwapi.dll Mon May 2 2005 4:52:36p A.... 473,600 462.50 K
        urlmon.dll Mon May 2 2005 4:52:36p A.... 607,744 593.50 K
        weidx.dll Mon Jul 11 2005 12:04:56p ..S.R 417,792 408.00 K
        wininet.dll Mon May 2 2005 4:52:36p A.... 657,920 642.50 K
        wnvdmoe2.dll Mon Jul 11 2005 4:41:04p ..S.R 417,792 408.00 K
        wpfapi.dll Mon Jul 11 2005 6:09:54p ..S.R 417,792 408.00 K
        wuapi.dll Thu May 26 2005 4:16:30a A.... 465,176 454.27 K
        wuaueng.dll Thu May 26 2005 4:16:30a A.... 1,343,768 1.28 M
        wuaueng1.dll Thu May 26 2005 4:16:30a A.... 194,328 189.77 K
        wucltui.dll Thu May 26 2005 4:16:30a A.... 127,256 124.27 K
        wups.dll Thu May 26 2005 4:16:30a A.... 41,240 40.27 K
        wups2.dll Thu May 26 2005 4:16:30a A.... 18,200 17.77 K
        wuweb.dll Thu May 26 2005 4:16:30a A.... 173,536 169.47 K
        wwploc.dll Mon Jul 11 2005 12:04:52p ..S.R 417,792 408.00 K
        wxashext.dll Mon Jul 11 2005 6:09:58p ..S.R 417,792 408.00 K
        wxwfax.dll Mon Jul 11 2005 4:41:10p ..S.R 417,792 408.00 K
        xpsp3res.dll Mon May 16 2005 8:25:36p ..... 15,360 15.00 K

        49 items found: 49 files (19 H/S), 0 directories.
        Total of file sizes: 23,367,840 bytes 22.29 M
        Locate .tmp files:

        C:\WINDOWS\SYSTEM32\
        guard.tmp Thu Jul 14 2005 3:28:02p A.... 0 0.00 K

        1 item found: 1 file, 0 directories.
        Total of file sizes: 0 bytes 0.00 K
        **********************************************************************************
        Directory Listing of system files:
        Volume in drive C is Clem and Charlene
        Volume Serial Number is 4418-82B5

        Directory of C:\WINDOWS\System32

        07/14/2005 03:36 PM 417,792 kpdfr.dll
        07/14/2005 02:11 PM 417,792 djsapi.dll
        07/14/2005 07:39 AM 417,792 ldhsvc.dll
        07/12/2005 06:35 PM 417,792 kmdfr.dll
        07/12/2005 04:47 PM <DIR> dllcache
        07/12/2005 04:29 PM 417,792 drrawex.dll
        07/12/2005 03:54 PM 417,792 IXKED.DLL
        07/11/2005 09:38 PM 417,792 escapi.dll
        07/11/2005 08:31 PM 417,792 mocorier.dll
        07/11/2005 08:31 PM 417,792 mgdtctm.dll
        07/11/2005 07:24 PM 417,792 kndit142.dll
        07/11/2005 07:24 PM 417,792 kodit142.dll
        07/11/2005 06:09 PM 417,792 wxashext.dll
        07/11/2005 06:09 PM 417,792 wpfapi.dll
        07/11/2005 05:07 PM 417,792 cWtsrvps.dll
        07/11/2005 05:07 PM 417,792 cofview.dll
        07/11/2005 04:41 PM 417,792 wxwfax.dll
        07/11/2005 04:41 PM 417,792 wnvdmoe2.dll
        07/11/2005 12:04 PM 417,792 weidx.dll
        07/11/2005 12:04 PM 417,792 wwploc.dll
        08/09/2004 01:49 AM <DIR> Microsoft
        19 File(s) 7,938,048 bytes
        2 Dir(s) 72,433,041,408 bytes free
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        Close any programs you have open since this step requires a reboot.

        From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

        IMPORTANT: Do NOT run any other files in the l2mfix folder until you are asked to do so!
      • edited July 2005
        alright here are the logfiles:

        =======================


        L2Mfix 1.03a

        Running From:
        C:\Documents and Settings\Compaq_Owner\Desktop\Spyware tools\l2mfix



        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-NI) ALLOW Read BUILTIN\Users
        (ID-IO) ALLOW Read BUILTIN\Users
        (ID-NI) ALLOW Full access BUILTIN\Administrators
        (ID-IO) ALLOW Full access BUILTIN\Administrators
        (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access CREATOR OWNER



        Setting registry permissions:


        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!


        Denying C(CI) access for predefined group "Administrators"
        - adding new ACCESS DENY entry


        Registry Permissions set too:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (CI) DENY --C
        BUILTIN\Administrators
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-NI) ALLOW Read BUILTIN\Users
        (ID-IO) ALLOW Read BUILTIN\Users
        (ID-NI) ALLOW Full access BUILTIN\Administrators
        (ID-IO) ALLOW Full access BUILTIN\Administrators
        (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access CREATOR OWNER



        Setting up for Reboot


        Starting Reboot!

        C:\Documents and Settings\Compaq_Owner\Desktop\Spyware tools\l2mfix
        System Rebooted!

        Running From:
        C:\Documents and Settings\Compaq_Owner\Desktop\Spyware tools\l2mfix

        killing explorer and rundll32.exe

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1252 'explorer.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1412 'rundll32.exe'

        Scanning First Pass. Please Wait!

        First Pass Completed

        Second Pass Scanning

        Second pass Completed!
        Backing Up: C:\WINDOWS\system32\cofview.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\cofview.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\cWtsrvps.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\cWtsrvps.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\djsapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\djsapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\drrawex.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\drrawex.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\escapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\escapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\IXKED.DLL
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\IXKED.DLL
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kgdkaz.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kgdkaz.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kmdfr.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kmdfr.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kndit142.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kndit142.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kodit142.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\kodit142.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\ldhsvc.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\ldhsvc.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\mgdtctm.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\mgdtctm.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\mocorier.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\mocorier.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\rzutetab.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\rzutetab.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\siimeng.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\siimeng.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\weidx.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\weidx.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wnvdmoe2.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wnvdmoe2.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wpfapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wpfapi.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wwploc.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wwploc.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wxashext.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wxashext.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wxwfax.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\wxwfax.dll
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\guard.tmp
        1 file(s) copied.
        Backing Up: C:\WINDOWS\system32\guard.tmp
        1 file(s) copied.
        deleting: C:\WINDOWS\system32\cofview.dll
        Successfully Deleted: C:\WINDOWS\system32\cofview.dll
        deleting: C:\WINDOWS\system32\cofview.dll
        Successfully Deleted: C:\WINDOWS\system32\cofview.dll
        deleting: C:\WINDOWS\system32\cWtsrvps.dll
        Successfully Deleted: C:\WINDOWS\system32\cWtsrvps.dll
        deleting: C:\WINDOWS\system32\cWtsrvps.dll
        Successfully Deleted: C:\WINDOWS\system32\cWtsrvps.dll
        deleting: C:\WINDOWS\system32\djsapi.dll
        Successfully Deleted: C:\WINDOWS\system32\djsapi.dll
        deleting: C:\WINDOWS\system32\djsapi.dll
        Successfully Deleted: C:\WINDOWS\system32\djsapi.dll
        deleting: C:\WINDOWS\system32\drrawex.dll
        Successfully Deleted: C:\WINDOWS\system32\drrawex.dll
        deleting: C:\WINDOWS\system32\drrawex.dll
        Successfully Deleted: C:\WINDOWS\system32\drrawex.dll
        deleting: C:\WINDOWS\system32\escapi.dll
        Successfully Deleted: C:\WINDOWS\system32\escapi.dll
        deleting: C:\WINDOWS\system32\escapi.dll
        Successfully Deleted: C:\WINDOWS\system32\escapi.dll
        deleting: C:\WINDOWS\system32\IXKED.DLL
        Successfully Deleted: C:\WINDOWS\system32\IXKED.DLL
        deleting: C:\WINDOWS\system32\IXKED.DLL
        Successfully Deleted: C:\WINDOWS\system32\IXKED.DLL
        deleting: C:\WINDOWS\system32\kgdkaz.dll
        Successfully Deleted: C:\WINDOWS\system32\kgdkaz.dll
        deleting: C:\WINDOWS\system32\kgdkaz.dll
        Successfully Deleted: C:\WINDOWS\system32\kgdkaz.dll
        deleting: C:\WINDOWS\system32\kmdfr.dll
        Successfully Deleted: C:\WINDOWS\system32\kmdfr.dll
        deleting: C:\WINDOWS\system32\kmdfr.dll
        Successfully Deleted: C:\WINDOWS\system32\kmdfr.dll
        deleting: C:\WINDOWS\system32\kndit142.dll
        Successfully Deleted: C:\WINDOWS\system32\kndit142.dll
        deleting: C:\WINDOWS\system32\kndit142.dll
        Successfully Deleted: C:\WINDOWS\system32\kndit142.dll
        deleting: C:\WINDOWS\system32\kodit142.dll
        Successfully Deleted: C:\WINDOWS\system32\kodit142.dll
        deleting: C:\WINDOWS\system32\kodit142.dll
        Successfully Deleted: C:\WINDOWS\system32\kodit142.dll
        deleting: C:\WINDOWS\system32\ldhsvc.dll
        Successfully Deleted: C:\WINDOWS\system32\ldhsvc.dll
        deleting: C:\WINDOWS\system32\ldhsvc.dll
        Successfully Deleted: C:\WINDOWS\system32\ldhsvc.dll
        deleting: C:\WINDOWS\system32\mgdtctm.dll
        Successfully Deleted: C:\WINDOWS\system32\mgdtctm.dll
        deleting: C:\WINDOWS\system32\mgdtctm.dll
        Successfully Deleted: C:\WINDOWS\system32\mgdtctm.dll
        deleting: C:\WINDOWS\system32\mocorier.dll
        Successfully Deleted: C:\WINDOWS\system32\mocorier.dll
        deleting: C:\WINDOWS\system32\mocorier.dll
        Successfully Deleted: C:\WINDOWS\system32\mocorier.dll
        deleting: C:\WINDOWS\system32\rzutetab.dll
        Successfully Deleted: C:\WINDOWS\system32\rzutetab.dll
        deleting: C:\WINDOWS\system32\rzutetab.dll
        Successfully Deleted: C:\WINDOWS\system32\rzutetab.dll
        deleting: C:\WINDOWS\system32\siimeng.dll
        Successfully Deleted: C:\WINDOWS\system32\siimeng.dll
        deleting: C:\WINDOWS\system32\siimeng.dll
        Successfully Deleted: C:\WINDOWS\system32\siimeng.dll
        deleting: C:\WINDOWS\system32\weidx.dll
        Successfully Deleted: C:\WINDOWS\system32\weidx.dll
        deleting: C:\WINDOWS\system32\weidx.dll
        Successfully Deleted: C:\WINDOWS\system32\weidx.dll
        deleting: C:\WINDOWS\system32\wnvdmoe2.dll
        Successfully Deleted: C:\WINDOWS\system32\wnvdmoe2.dll
        deleting: C:\WINDOWS\system32\wnvdmoe2.dll
        Successfully Deleted: C:\WINDOWS\system32\wnvdmoe2.dll
        deleting: C:\WINDOWS\system32\wpfapi.dll
        Successfully Deleted: C:\WINDOWS\system32\wpfapi.dll
        deleting: C:\WINDOWS\system32\wpfapi.dll
        Successfully Deleted: C:\WINDOWS\system32\wpfapi.dll
        deleting: C:\WINDOWS\system32\wwploc.dll
        Successfully Deleted: C:\WINDOWS\system32\wwploc.dll
        deleting: C:\WINDOWS\system32\wwploc.dll
        Successfully Deleted: C:\WINDOWS\system32\wwploc.dll
        deleting: C:\WINDOWS\system32\wxashext.dll
        Successfully Deleted: C:\WINDOWS\system32\wxashext.dll
        deleting: C:\WINDOWS\system32\wxashext.dll
        Successfully Deleted: C:\WINDOWS\system32\wxashext.dll
        deleting: C:\WINDOWS\system32\wxwfax.dll
        Successfully Deleted: C:\WINDOWS\system32\wxwfax.dll
        deleting: C:\WINDOWS\system32\wxwfax.dll
        Successfully Deleted: C:\WINDOWS\system32\wxwfax.dll
        deleting: C:\WINDOWS\system32\guard.tmp
        Successfully Deleted: C:\WINDOWS\system32\guard.tmp
        deleting: C:\WINDOWS\system32\guard.tmp
        Successfully Deleted: C:\WINDOWS\system32\guard.tmp

        Desktop.ini sucessfully removed

        Zipping up files for submission:
        adding: cofview.dll (164 bytes security) (deflated 48%)
        adding: cWtsrvps.dll (164 bytes security) (deflated 48%)
        adding: djsapi.dll (164 bytes security) (deflated 48%)
        adding: drrawex.dll (164 bytes security) (deflated 48%)
        adding: escapi.dll (164 bytes security) (deflated 48%)
        adding: IXKED.DLL (164 bytes security) (deflated 48%)
        adding: kgdkaz.dll (164 bytes security) (deflated 48%)
        adding: kmdfr.dll (164 bytes security) (deflated 48%)
        adding: kndit142.dll (164 bytes security) (deflated 48%)
        adding: kodit142.dll (164 bytes security) (deflated 48%)
        adding: ldhsvc.dll (164 bytes security) (deflated 48%)
        adding: mgdtctm.dll (164 bytes security) (deflated 48%)
        adding: mocorier.dll (164 bytes security) (deflated 48%)
        adding: rzutetab.dll (164 bytes security) (deflated 48%)
        adding: siimeng.dll (164 bytes security) (deflated 48%)
        adding: weidx.dll (164 bytes security) (deflated 48%)
        adding: wnvdmoe2.dll (164 bytes security) (deflated 48%)
        adding: wpfapi.dll (164 bytes security) (deflated 48%)
        adding: wwploc.dll (164 bytes security) (deflated 48%)
        adding: wxashext.dll (164 bytes security) (deflated 48%)
        adding: wxwfax.dll (164 bytes security) (deflated 48%)
        adding: guard.tmp (164 bytes security) (deflated 48%)
        adding: clear.reg (164 bytes security) (deflated 46%)
        adding: echo.reg (164 bytes security) (deflated 12%)
        adding: desktop.ini (164 bytes security) (deflated 14%)
        adding: direct.txt (164 bytes security) (stored 0%)
        adding: lo2.txt (164 bytes security) (deflated 88%)
        adding: readme.txt (164 bytes security) (deflated 49%)
        adding: report.txt (164 bytes security) (deflated 67%)
        adding: test.txt (164 bytes security) (deflated 89%)
        adding: test2.txt (164 bytes security) (deflated 27%)
        adding: test3.txt (164 bytes security) (deflated 27%)
        adding: test5.txt (164 bytes security) (deflated 27%)
        adding: xfind.txt (164 bytes security) (deflated 86%)
        adding: backregs/7AFF04D1-6742-46C3-9BE2-20751D7A543B.reg (164 bytes security) (deflated 69%)
        adding: backregs/A4A6FE75-DEAF-475C-AFC5-8D65964F57B6.reg (164 bytes security) (deflated 70%)
        adding: backregs/FB6D81AD-D691-4BD5-8938-C1C8BE9652E8.reg (164 bytes security) (deflated 70%)
        adding: backregs/shell.reg (164 bytes security) (deflated 73%)

        Restoring Registry Permissions:


        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!


        Revoking access for predefined group "Administrators"
        Inherited ACE can not be revoked here!
        Inherited ACE can not be revoked here!


        Registry permissions set too:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-NI) ALLOW Read BUILTIN\Users
        (ID-IO) ALLOW Read BUILTIN\Users
        (ID-NI) ALLOW Full access BUILTIN\Administrators
        (ID-IO) ALLOW Full access BUILTIN\Administrators
        (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
        (ID-IO) ALLOW Full access CREATOR OWNER


        Restoring Sedebugprivilege:

        Granting SeDebugPrivilege to Administrators ... successful

        deleting local copy: cofview.dll
        deleting local copy: cofview.dll
        deleting local copy: cWtsrvps.dll
        deleting local copy: cWtsrvps.dll
        deleting local copy: djsapi.dll
        deleting local copy: djsapi.dll
        deleting local copy: drrawex.dll
        deleting local copy: drrawex.dll
        deleting local copy: escapi.dll
        deleting local copy: escapi.dll
        deleting local copy: IXKED.DLL
        deleting local copy: IXKED.DLL
        deleting local copy: kgdkaz.dll
        deleting local copy: kgdkaz.dll
        deleting local copy: kmdfr.dll
        deleting local copy: kmdfr.dll
        deleting local copy: kndit142.dll
        deleting local copy: kndit142.dll
        deleting local copy: kodit142.dll
        deleting local copy: kodit142.dll
        deleting local copy: ldhsvc.dll
        deleting local copy: ldhsvc.dll
        deleting local copy: mgdtctm.dll
        deleting local copy: mgdtctm.dll
        deleting local copy: mocorier.dll
        deleting local copy: mocorier.dll
        deleting local copy: rzutetab.dll
        deleting local copy: rzutetab.dll
        deleting local copy: siimeng.dll
        deleting local copy: siimeng.dll
        deleting local copy: weidx.dll
        deleting local copy: weidx.dll
        deleting local copy: wnvdmoe2.dll
        deleting local copy: wnvdmoe2.dll
        deleting local copy: wpfapi.dll
        deleting local copy: wpfapi.dll
        deleting local copy: wwploc.dll
        deleting local copy: wwploc.dll
        deleting local copy: wxashext.dll
        deleting local copy: wxashext.dll
        deleting local copy: wxwfax.dll
        deleting local copy: wxwfax.dll
        deleting local copy: guard.tmp
        deleting local copy: guard.tmp

        The following Is the Current Export of the Winlogon notify key:
        ****************************************************************************
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001


        The following are the files found:
        ****************************************************************************
        C:\WINDOWS\system32\cofview.dll
        C:\WINDOWS\system32\cofview.dll
        C:\WINDOWS\system32\cWtsrvps.dll
        C:\WINDOWS\system32\cWtsrvps.dll
        C:\WINDOWS\system32\djsapi.dll
        C:\WINDOWS\system32\djsapi.dll
        C:\WINDOWS\system32\drrawex.dll
        C:\WINDOWS\system32\drrawex.dll
        C:\WINDOWS\system32\escapi.dll
        C:\WINDOWS\system32\escapi.dll
        C:\WINDOWS\system32\IXKED.DLL
        C:\WINDOWS\system32\IXKED.DLL
        C:\WINDOWS\system32\kgdkaz.dll
        C:\WINDOWS\system32\kgdkaz.dll
        C:\WINDOWS\system32\kmdfr.dll
        C:\WINDOWS\system32\kmdfr.dll
        C:\WINDOWS\system32\kndit142.dll
        C:\WINDOWS\system32\kndit142.dll
        C:\WINDOWS\system32\kodit142.dll
        C:\WINDOWS\system32\kodit142.dll
        C:\WINDOWS\system32\ldhsvc.dll
        C:\WINDOWS\system32\ldhsvc.dll
        C:\WINDOWS\system32\mgdtctm.dll
        C:\WINDOWS\system32\mgdtctm.dll
        C:\WINDOWS\system32\mocorier.dll
        C:\WINDOWS\system32\mocorier.dll
        C:\WINDOWS\system32\rzutetab.dll
        C:\WINDOWS\system32\rzutetab.dll
        C:\WINDOWS\system32\siimeng.dll
        C:\WINDOWS\system32\siimeng.dll
        C:\WINDOWS\system32\weidx.dll
        C:\WINDOWS\system32\weidx.dll
        C:\WINDOWS\system32\wnvdmoe2.dll
        C:\WINDOWS\system32\wnvdmoe2.dll
        C:\WINDOWS\system32\wpfapi.dll
        C:\WINDOWS\system32\wpfapi.dll
        C:\WINDOWS\system32\wwploc.dll
        C:\WINDOWS\system32\wwploc.dll
        C:\WINDOWS\system32\wxashext.dll
        C:\WINDOWS\system32\wxashext.dll
        C:\WINDOWS\system32\wxwfax.dll
        C:\WINDOWS\system32\wxwfax.dll
        C:\WINDOWS\system32\guard.tmp
        C:\WINDOWS\system32\guard.tmp

        Registry Entries that were Deleted:
        Please verify that the listing looks ok.
        If there was something deleted wrongly there are backups in the backreg folder.
        ****************************************************************************
        REGEDIT4

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{7AFF04D1-6742-46C3-9BE2-20751D7A543B}"=-
        "{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}"=-
        "{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}"=-
        [-HKEY_CLASSES_ROOT\CLSID\{7AFF04D1-6742-46C3-9BE2-20751D7A543B}]
        [-HKEY_CLASSES_ROOT\CLSID\{A4A6FE75-DEAF-475C-AFC5-8D65964F57B6}]
        [-HKEY_CLASSES_ROOT\CLSID\{FB6D81AD-D691-4BD5-8938-C1C8BE9652E8}]
        REGEDIT4

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "SV1"=""
        ****************************************************************************
        Desktop.ini Contents:
        ****************************************************************************
        [.ShellClassInfo]
        CLSID={645FF040-5081-101B-9F08-00AA002F954E}
        <IDone>{30DFC174-0D94-4616-85D1-B825A9C0900E}</IDone>
        <IDtwo>DS3</IDtwo>
        <VERSION>200</VERSION>
        ****************************************************************************


        ========================


        Logfile of HijackThis v1.99.1
        Scan saved at 1:57:47 PM, on 7/15/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\windows\system\hpsysdrv.exe
        C:\WINDOWS\system32\igfxtray.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\PROGRA~1\mcafee.com\agent\mcagent.exe
        C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
        C:\WINDOWS\system32\drivers\KodakCCS.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
        O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
        O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
        O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
        O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
        O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
        O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
        O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
        O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing)
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        Click Start -> Run -> (type) services.msc

        Scroll down and find the service called System Startup Service When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows.


        Run Hijackthis and click on Open the Misc Tools section -> Delete an NT Service
        Copy and paste this into the text box and click OK.

        SvcProc



        Reboot and post a new hijackthis log. Let me know how things feel on your end.
      • edited July 2005
        wouldn't let me delete SvcProc, because it was not found...and here is my latest HJT logfile:



        Logfile of HijackThis v1.99.1
        Scan saved at 1:18:17 PM, on 7/17/2005
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        C:\windows\system\hpsysdrv.exe
        C:\WINDOWS\system32\igfxtray.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\PROGRA~1\mcafee.com\agent\mcagent.exe
        C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
        C:\WINDOWS\system32\drivers\KodakCCS.exe
        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Documents and Settings\Compaq_Owner\Desktop\Spyware tools\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
        O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
        O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
        O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Startup: Connection Manager.lnk = C:\Program Files\BellSouth\Connection Manager\CManager.exe
        O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - http://66.223.94.62:63274/smsx.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
        O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
        O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
        O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
      • Buckeye_SamBuckeye_Sam Columbus, Ohio
        edited July 2005
        Your log looks clean to me.

        Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
        1. Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point left over from what we have just cleaned.

          You can find instructions on how to enable and reenable system restore here:

          Managing Windows Millenium System Restore

          or

          Windows XP System Restore Guide

          Renable system restore with instructions from tutorial above

        2. Make your Internet Explorer more secure - This can be done by following these simple instructions:
          1. From within Internet Explorer click on the Tools menu and then click on Options.
          2. Click once on the Security tab
          3. Click once on the Internet icon so it becomes highlighted.
          4. Click once on the Custom Level button.
            1. Change the Download signed ActiveX controls to Prompt
            2. Change the Download unsigned ActiveX controls to Disable
            3. Change the Initialize and script ActiveX controls not marked as safe to Disable
            4. Change the Installation of desktop items to Prompt
            5. Change the Launching programs and files in an IFRAME to Prompt
            6. Change the Navigate sub-frames across different domains to Prompt
            7. When all these settings have been made, click on the OK button.
            8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
          5. Next press the Apply button and then the OK to exit the Internet Properties page.

        3. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

          See this link for a listing of some online & their stand-alone antivirus programs:

          Virus, Spyware, and Malware Protection and Removal Resources

        4. Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

        5. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

          For a tutorial on Firewalls and a listing of some available ones see the link below:

          Understanding and Using Firewalls

        6. Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

        7. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

          A tutorial on installing & using this product can be found here:

          Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

        8. Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

          A tutorial on installing & using this product can be found here:

          Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

        9. Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

          A tutorial on installing & using this product can be found here:

          Using SpywareBlaster to protect your computer from Spyware and Malware

        10. Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
        Follow this list and your potential for being infected again will reduce dramatically.
      • edited July 2005
        Thanks Buckeye_Sam for your help means a lot!
      This discussion has been closed.