Trojan.LowZones lsasss.exe

2»

Comments

  • MsJessicaDzMsJessicaDz Dallas, TX
    edited April 2007
    RR, extra.txt file not being created??? here is the Main.txt below - Jessica

    *****************************************
    Deckard's System Scanner v20070318.32
    Run by newtemp on 2007-04-04 at 12:51:42
    Computer is in Normal Mode.



    -- HijackThis (run as newtemp.exe)

    Logfile of HijackThis v1.99.1
    Scan saved at 12:51:44 PM, on 4/4/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\PDFCreatorMessages.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    C:\WINDOWS\system32\NWTRAY.EXE
    C:\WINDOWS\system32\PELMICED.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\CASIO\Photo Loader\Plauto.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\msiexec.exe
    C:\Documents and Settings\newtemp\Desktop\dss.exe
    C:\HJT\newtemp.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
    O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {4BEF854E-6531-40D8-825E-5228A12861F3} (pwrUpl2 Class) - https://hks.thruinc.net/Components/PowerUpload.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173983420608
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\PDFCreatorMessages.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


    -- Files created between 2007-03-04 and 2007-04-04

    2007-04-03 11:50:37 0 d
    C:\WINDOWS\system32\Softartisans<SOFTAR~1>
    2007-04-02 17:19:53 0 d
    C:\Program Files\Microsoft IntelliPoint<MIFB84~1>
    2007-04-02 10:05:14 0 d
    C:\WINDOWS\system32\ActiveScan<ACTIVE~1>
    2007-03-30 17:20:46 0 d
    C:\poweredge<POWERE~1>
    2007-03-23 15:15:22 32768 --a
    C:\WINDOWS\NOTEDAD.EXE
    2007-03-19 16:53:00 4212 ---h
    C:\WINDOWS\system32\zllictbl.dat
    2007-03-19 16:52:37 75512 --a
    C:\WINDOWS\zllsputility.exe<ZLLSPU~1.EXE>
    2007-03-19 16:52:05 1087216 --a
    C:\WINDOWS\system32\zpeng24.dll
    2007-03-19 16:52:05 0 d
    C:\WINDOWS\system32\ZoneLabs
    2007-03-19 16:50:55 0 d
    C:\WINDOWS\Internet Logs<INTERN~1>
    2007-03-19 12:55:25 0 d
    C:\Documents and Settings\All Users\Application Data\Kaspersky Lab<KASPER~1>
    2007-03-19 12:55:23 0 d
    C:\WINDOWS\system32\Kaspersky Lab<KASPER~1>
    2007-03-19 12:32:08 0 d
    C:\Program Files\CCleaner
    2007-03-19 09:08:49 0 d
    C:\HJT
    2007-03-15 10:15:43 0 d
    C:\Documents and Settings\newtemp\Application Data\Lavasoft
    2007-03-15 10:15:14 0 d
    C:\Program Files\Lavasoft
    2007-03-15 09:35:29 0 d
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy<SPYBOT~1>
    2007-03-15 09:08:42 3968 --a
    C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-03-15 08:59:47 0 d
    C:\VundoFix Backups<VUNDOF~1>
    2007-03-15 08:55:31 0 d--h
    C:\WINDOWS\PIF
    2007-03-15 08:47:51 0 d
    C:\Documents and Settings\newtemp\DoctorWeb<DOCTOR~1>
    2007-03-08 09:31:42 0 d
    C:\temp
    2007-03-07 09:06:58 0 d
    C:\Program Files\KODAK
    2007-03-07 09:02:49 0 d
    C:\Program Files\CASIO
    2007-03-06 13:42:57 0 d
    C:\WINDOWS\system32\bak


    -- Find3M Report

    2007-04-04 12:47:09 0 d
    C:\Documents and Settings\newtemp\Application Data\MailWasherPro<MAILWA~1>
    2007-04-02 11:11:39 0 d
    C:\Program Files\Messenger<MESSEN~1>
    2007-04-02 11:11:38 0 d
    C:\Program Files\MailWasher<MAILWA~1>
    2007-04-02 11:11:04 0 d
    C:\Program Files\Google
    2007-04-02 11:09:43 0 d
    C:\Program Files\Common Files\Autodesk Shared<AUTODE~1>
    2007-03-07 09:54:08 0 d--h
    C:\Program Files\InstallShield Installation Information<INSTAL~1>
    2007-03-01 17:50:31 0 d
    C:\Program Files\EOrganizer<EORGAN~1>
    2007-03-01 14:24:09 0 d
    C:\Program Files\spanner
    2007-02-28 10:52:58 0 d
    C:\Documents and Settings\newtemp\Application Data\Snapfish
    2007-02-23 17:34:26 0 d
    C:\Documents and Settings\newtemp\Application Data\Microsoft<MICROS~1>
    2007-02-16 13:54:56 1129232 --a
    C:\WINDOWS\system32\FM20.DLL
    2007-02-15 14:50:36 0 d
    C:\Program Files\AutoCAD 2005<AUTOCA~1>
    2007-01-30 11:43:05 1168 --a
    C:\WINDOWS\mozver.dat
    2007-01-23 15:03:08 193080 --a
    C:\WINDOWS\Label9
    2007-01-23 15:03:07 108 --a
    C:\WINDOWS\Label7
    2007-01-23 15:03:07 28 --a
    C:\WINDOWS\Label10


    -- Registry Dump


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
    "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    "IESet"="IExplorer.dll .dbt"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
    "PDFCreatorClient"="C:\\Program Files\\JawsSystems\\Jaws PDF Creator\\PDFClient.exe"
    "NWTRAY"="NWTRAY.EXE"
    "Mouse Suite 98 Daemon"="PELMICED.EXE"
    "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    "IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
    "IESet"="IExplorer.dll .dbt"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
    "IESet"="IExplorer.dll .dbt"


    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
    "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "IESet"="IExplorer.dll .dbt"

    [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
    Source REG_SZ http://sopadre.com/_images/bottom_bg_beach.jpg

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0



    -- End of Deckard's System Scanner: finished at 2007-04-04 at 12:52:04
  • Rahina-RescueRahina-Rescue Finland
    edited April 2007
    Part of the fix may require you to be in Safe Mode, which will not allow you to access the internet, or my instructions! I Suggest you print these Instructions out.

    Go to Start » Run » type in: regedit » OK.
    • On the leftside, click to highlight My Computer at the top.
    • Go up to File » Export
      Make sure in that window there is a tick next to "All" under Export Branch.
      Leave the "Save As Type" as "Registration Files".
      Under "Filename" put RegBackup.
    • Choose to save it to C:\
    • Click Save and then go to File » Exit.
    This is so the registry can be restored to this point if we need it. It may take a minute.

    _________________________________

    Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Open notepad and copy and paste next present in the quotebox below in it:
    (don't forget to copy and paste REGEDIT4)
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runservices]
    "IESet"=-

    [HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
    "IESet"=-

    Save this as fix.reg Choose to save as all files and place it on your desktop.

    Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

    Now boot in normal mode.
    _________________________________

    Please download the OTMoveIt.
    • Save it to your desktop.
    • Please double-click OTMoveIt.exe to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

      C:\WINDOWS\SYSTEM32\IExplorer.dll

    • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
    • Click the red Moveit! button.
    • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
    • Close OTMoveIt
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

    _________________________________

    Download ATF-Cleaner by Atribune to your desktop.

    Do NOT run it yet.

    Run ATF Cleaner Under Main choose: Select All
    Click the Empty Selected button.

    If you use Firefox browser Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    Please Post a Fresh Hijackthislogfile in your next reply.
  • MsJessicaDzMsJessicaDz Dallas, TX
    edited April 2007
    Just recieved Symantic Notice:
    12131421a{1}.exe
    Downloader Virus
    Left alone
    Location C:\Documents and Settings\newtemp\Local Settings\Temporary Internet Files\Content.IE5\SA5BXPKC\

    ***************************************

    OTMoveIt

    File/Folder C:\WINDOWS\SYSTEM32\IExplorer.dll not found.

    Created on 04/05/2007 11:55:36

    ***************************************
    Logfile of HijackThis v1.99.1
    Scan saved at 11:59:37 AM, on 4/5/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\PDFCreatorMessages.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    C:\WINDOWS\system32\NWTRAY.EXE
    C:\WINDOWS\system32\PELMICED.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\CASIO\Photo Loader\Plauto.exe
    C:\WINDOWS\notepad.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\HJT\HijackThis.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
    O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {4BEF854E-6531-40D8-825E-5228A12861F3} (pwrUpl2 Class) - https://hks.thruinc.net/Components/PowerUpload.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173983420608
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\PDFCreatorMessages.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  • Rahina-RescueRahina-Rescue Finland
    edited April 2007
    Hello There.

    Are you sure that you did The regfix Correct?

    That did not seem to work :( Please let me know if there's something you did not do or you did not understand.

    Now Please run Panda's ActiveScan You will need to use Internet Explorer to run it.

    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    o If it wants to install an ActiveX component allow it
    o It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    o When download is complete, click on My Computer to start the scan
    o When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.


    Post the contents of the ActiveScan report
  • MsJessicaDzMsJessicaDz Dallas, TX
    edited April 2007
    I ran fix.reg 2 times - first time it said it could not find a file. So I went thru the steps again and it said it worked - added to regestry.

    Will run Panda now.
  • MsJessicaDzMsJessicaDz Dallas, TX
    edited April 2007
    Panda did not find anything. :D

    PC seems to be running well - just concerned w/those Virus Notices from Symantic?
  • Rahina-RescueRahina-Rescue Finland
    edited April 2007
    Ok, But your Hijackthislogfile is not clean yet :(, please give me some time to write instructions. Thank you for your patience. :)
  • Rahina-RescueRahina-Rescue Finland
    edited April 2007
    Sorry For the Long Delay Getting to this post ( My bad ) I'm sorry :O

    Let me know if you still require assistance :)
  • MsJessicaDzMsJessicaDz Dallas, TX
    edited April 2007
    Here's a new HTLog - Please check it out and lead me to the path free from virus filled pc's. Thanks, Jessica
    ********************************************

    Logfile of HijackThis v1.99.1
    Scan saved at 8:42:45 AM, on 4/17/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\PDFCreatorMessages.exe
    C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    C:\WINDOWS\system32\NWTRAY.EXE
    C:\WINDOWS\system32\PELMICED.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\CASIO\Photo Loader\Plauto.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
    O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
    O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
    O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {4BEF854E-6531-40D8-825E-5228A12861F3} (pwrUpl2 Class) - https://hks.thruinc.net/Components/PowerUpload.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173983420608
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\PDFCreatorMessages.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  • Rahina-RescueRahina-Rescue Finland
    edited April 2007
    We have to get rid of that Stubborn IESET.

    There are several stages to removing the PWS-Bluedit Password Stealer that has infected your system, so please print out this page so you can refer to it during the fix.

    Please download DAFT and save it to your Desktop:
    • Double-click the daft.exe icon. Read the disclaimer and click OK.
    • Click on the Scan button.
    • Place a checkmark next to the following entries if they are shown after the scan:

    .bat
    .ini
    .reg
    .txt
    • Click the Fix button.
    • Re-scan and save a logfile to your Desktop. By default, it will save as daft.txt
    • I'll need that log later.
    If everything is ok again, it should display the "all associations ok message"

    ________________________________________________

    Please open Notepad. Now copy the contents of the code box below into Notepad by highlighting all the text starting from "@echo off", and pressing CTRL and C at the same time.
    @echo off
    if exist %WINDIR%\NOTEDAD.EXE del %WINDIR%\NOTEDAD.EXE /f /q /a:h /a:a
    if exist %WINDIR%\SYSTEM32\NOTEDAD.EXE del %WINDIR%\SYSTEM32\NOTEDAD.EXE /f /q /a:h /a:a

    if exist %WINDIR%\MP43.EXE del %WINDIR%\MP43.EXE /f /q /a:h /a:a
    if exist %WINDIR%\SYSTEM32\MP43.EXE del %WINDIR%\SYSTEM32\MP43.EXE /f /q /a:h /a:a

    if exist %WINDIR%\DC10.EXE del %WINDIR%\DC10.EXE /f /q /a:h /a:a
    if exist %WINDIR%\SYSTEM32\DC10.EXE del %WINDIR%\SYSTEM32\DC10.EXE /f /q /a:h /a:a

    if exist %WINDIR%\IExplorer.dll del %WINDIR%\IExplorer.dll /f /q /a:h /a:a
    if exist %WINDIR%\SYSTEM32\IExplorer.dll del %WINDIR%\SYSTEM32\IExplorer.dll /f /q /a:h /a:a

    if exist %WINDIR%\2.exe del %WINDIR%\2.exe /f /q /a:h /a:a
    if exist %WINDIR%\SYSTEM32\2.exe del %WINDIR%\SYSTEM32\2.exe /f /q /a:h /a:a

    reg delete HCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run /v IESet /f
    reg delete HCU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run /v IESet /f
    reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v IESet /f
    reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v IESet /f
    reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices /v IESet /f
    reg delete HKCR\.dbt /f
    reg delete HKCR\DBTFILE /f
    reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dbt /f

    reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG\OpenWithList /v b /f
    reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt\OpenWithList /v c /f

    Switch to Notepad and press CTRL and V at the same time, or choosing Paste from the Edit Menu.

    Now save the the Notepad file as FixPWS.bat to your Desktop.

    ________________________________________________


    Please reboot into Safe Mode. Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Once in safe mode, please locate FixPWS.bat and double click it to run the file.

    A command window will open briefly then close. This is quite normal.

    When the command window has closed, please Reboot your computer.

    Please download Deckard's System Scanner (DSS) and save it to your Desktop.
    • Close all other windows before proceeding.
    • Double-click on dss.exe and follow the prompts.
    • When it has finished, DSS will open two Notepad files: main.txt and extra.txt
    • Use Save As to save both Notepad files to your Desktop and post them in your next reply.
    Note:A copy of these files can be found in you root drive, usually C:\Deckard\System Scanner\

    If you already have DSS on your system, please follow the instructions below:

    Please run Deckard's System Scanner (DSS) again. This time it will only produce a single Notepad file; main.txt, please copy and paste the contents in your next reply.
    Note:A copy of this file can be found in you root drive, usually C:\Deckard\System Scanner\main.txt

    Now please post the following logs in your next reply:

      [*]daft.txt
      [*]DSS logs main.txt and extra.txt


      Let me know how things are running now ;)
    • MsJessicaDzMsJessicaDz Dallas, TX
      edited April 2007
      Here are the requested logs... PC seems to be running alright - I did run Spybot earlier today and here's it's log as well.

      **********************************************************
      --- Spybot Report generated: 2007-04-17 11:18 ---

      Smitfraud-C.Toolbar888: Settings (Registry key, fixed)
      HKEY_USERS\S-1-5-21-1757981266-854245398-2111378339-1006\Software\Microsoft\aldd

      Smitfraud-C.Toolbar888: Settings (Registry key, fixed)
      HKEY_LOCAL_MACHINE\SOFTWARE\Araf15

      AdRevolver: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      BlueStreak: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      TagASaurus: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      AdRevolver: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      Advertising.com: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      Avenue A, Inc.: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      FastClick: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      CasaleMedia: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      DoubleClick: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)
      MediaPlex: Tracking cookie (Internet Explorer: newtemp) (Cookie, fixed)

      **********************************************************


      DAFT Log saved on 2007-04-17 14:04:57
      .scr - AutoCADScriptFile - shell\open\command - "C:\WINDOWS\notepad.exe" "%1"

      ********************************************

      Deckard's System Scanner v20070318.32
      Run by newtemp on 2007-04-17 at 14:18:14
      Computer is in Normal Mode.



      -- HijackThis (run as newtemp.exe)

      Logfile of HijackThis v1.99.1
      Scan saved at 2:18:22 PM, on 4/17/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
      C:\WINDOWS\system32\PDFCreatorMessages.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
      C:\WINDOWS\system32\NWTRAY.EXE
      C:\WINDOWS\system32\PELMICED.EXE
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Microsoft IntelliPoint\point32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      C:\Program Files\CASIO\Photo Loader\Plauto.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\newtemp\Desktop\dss.exe
      C:\HJT\newtemp.exe

      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
      O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
      O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
      O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
      O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
      O16 - DPF: {4BEF854E-6531-40D8-825E-5228A12861F3} (pwrUpl2 Class) - https://hks.thruinc.net/Components/PowerUpload.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173983420608
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
      O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\PDFCreatorMessages.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


      -- Files created between 2007-03-17 and 2007-04-17

      2007-04-10 08:40:45 0 d
      C:\Program Files\Citrix
      2007-04-05 11:41:12 56284840 --a
      C:\regbackup.reg<REGBAC~1.REG>
      2007-04-03 11:50:37 0 d
      C:\WINDOWS\system32\Softartisans<SOFTAR~1>
      2007-04-02 17:19:53 0 d
      C:\Program Files\Microsoft IntelliPoint<MIFB84~1>
      2007-04-02 10:05:14 0 d
      C:\WINDOWS\system32\ActiveScan<ACTIVE~1>
      2007-03-30 17:20:46 0 d
      C:\poweredge<POWERE~1>
      2007-03-19 16:53:00 4212 ---h
      C:\WINDOWS\system32\zllictbl.dat
      2007-03-19 16:52:37 75512 --a
      C:\WINDOWS\zllsputility.exe<ZLLSPU~1.EXE>
      2007-03-19 16:52:05 1087216 --a
      C:\WINDOWS\system32\zpeng24.dll
      2007-03-19 16:52:05 0 d
      C:\WINDOWS\system32\ZoneLabs
      2007-03-19 16:50:55 0 d
      C:\WINDOWS\Internet Logs<INTERN~1>
      2007-03-19 12:55:25 0 d
      C:\Documents and Settings\All Users\Application Data\Kaspersky Lab<KASPER~1>
      2007-03-19 12:55:23 0 d
      C:\WINDOWS\system32\Kaspersky Lab<KASPER~1>
      2007-03-19 12:32:08 0 d
      C:\Program Files\CCleaner
      2007-03-19 09:08:49 0 d
      C:\HJT


      -- Find3M Report

      2007-04-17 09:31:49 0 d
      C:\Documents and Settings\newtemp\Application Data\MailWasherPro<MAILWA~1>
      2007-04-05 13:57:57 0 d
      C:\Program Files\Messenger<MESSEN~1>
      2007-04-05 13:57:56 0 d
      C:\Program Files\MailWasher<MAILWA~1>
      2007-04-05 13:57:09 0 d
      C:\Program Files\Google
      2007-04-05 13:54:00 0 d
      C:\Program Files\Common Files\Autodesk Shared<AUTODE~1>
      2007-04-05 13:50:16 0 d
      C:\Documents and Settings\newtemp\Application Data\Microsoft<MICROS~1>
      2007-03-15 10:15:43 0 d
      C:\Documents and Settings\newtemp\Application Data\Lavasoft
      2007-03-15 10:15:14 0 d
      C:\Program Files\Lavasoft
      2007-03-07 09:54:08 0 d--h
      C:\Program Files\InstallShield Installation Information<INSTAL~1>
      2007-03-07 09:06:58 0 d
      C:\Program Files\KODAK
      2007-03-07 09:06:30 0 d
      C:\Program Files\CASIO
      2007-03-01 17:50:31 0 d
      C:\Program Files\EOrganizer<EORGAN~1>
      2007-03-01 14:24:09 0 d
      C:\Program Files\spanner
      2007-02-28 10:52:58 0 d
      C:\Documents and Settings\newtemp\Application Data\Snapfish
      2007-02-16 13:54:56 1129232 --a
      C:\WINDOWS\system32\FM20.DLL
      2007-01-30 11:43:05 1168 --a
      C:\WINDOWS\mozver.dat
      2007-01-23 15:03:08 193080 --a
      C:\WINDOWS\Label9
      2007-01-23 15:03:07 108 --a
      C:\WINDOWS\Label7
      2007-01-23 15:03:07 28 --a
      C:\WINDOWS\Label10


      -- Registry Dump


      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
      "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
      "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
      "PDFCreatorClient"="C:\\Program Files\\JawsSystems\\Jaws PDF Creator\\PDFClient.exe"
      "NWTRAY"="NWTRAY.EXE"
      "Mouse Suite 98 Daemon"="PELMICED.EXE"
      "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
      "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
      "IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
      "IESet"="IExplorer.dll .dbt"


      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
      "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
      "IESet"="IExplorer.dll .dbt"

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
      Source REG_SZ http://sopadre.com/_images/bottom_bg_beach.jpg

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
      HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
      LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
      NetworkService REG_MULTI_SZ DnsCache\0\0
      DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
      rpcss REG_MULTI_SZ RpcSs\0\0
      imgsvc REG_MULTI_SZ StiSvc\0\0
      termsvcs REG_MULTI_SZ TermService\0\0



      -- End of Deckard's System Scanner: finished at 2007-04-17 at 14:18:44
    • Rahina-RescueRahina-Rescue Finland
      edited April 2007
      Part of the fix may require you to be in Safe Mode, which will not allow you to access the internet, or my instructions! I Suggest you print these Instructions out.

      Go to Start » Run » type in: regedit » OK.
      • On the leftside, click to highlight My Computer at the top.
      • Go up to File » Export
        Make sure in that window there is a tick next to "All" under Export Branch.
        Leave the "Save As Type" as "Registration Files".
        Under "Filename" put RegBackup.
      • Choose to save it to C:\
      • Click Save and then go to File » Exit.
      This is so the registry can be restored to this point if we need it. It may take a minute.

      ________________________________________________

      Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

      Open notepad and copy and paste next present in the quotebox below in it:
      (don't forget to copy and paste REGEDIT4)
      REGEDIT4

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runservices]
      "IESet"=-

      [HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
      "IESet"=-

      Save this as fix.reg Choose to save as all files and place it on your desktop.

      Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

      ________________________________________________

      Please open HiJackThis and scan. Check the boxes next to the entrie listed below

      O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt

      Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis

      Now Boot into Normal Mode And Post A Fresh Hijackthislogfile. :)

      Thanks.
    • MsJessicaDzMsJessicaDz Dallas, TX
      edited April 2007
      Sorry for the delay, been busy here at work. Here's the latest HJTLog. Hope things are looking good. . . :)

      Logfile of HijackThis v1.99.1
      Scan saved at 8:53:51 AM, on 4/23/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
      C:\WINDOWS\system32\PDFCreatorMessages.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
      C:\WINDOWS\system32\NWTRAY.EXE
      C:\WINDOWS\system32\PELMICED.EXE
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Microsoft IntelliPoint\point32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      C:\Program Files\CASIO\Photo Loader\Plauto.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\HJT\HijackThis.exe

      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
      O4 - HKLM\..\Run: [PDFCreatorClient] C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
      O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
      O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
      O16 - DPF: {4BEF854E-6531-40D8-825E-5228A12861F3} (pwrUpl2 Class) - https://hks.thruinc.net/Components/PowerUpload.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173983420608
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
      O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\PDFCreatorMessages.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    • Rahina-RescueRahina-Rescue Finland
      edited April 2007
      Hello MsJessicaDz :)

      Your Hijackthis logfile is.... CLEAN!!

      to ensure there's nothing hiding, please run the following Online scanner.

      Please run Panda's ActiveScan You will need to use Internet Explorer to run it.
      • Once you are on the Panda site click the Scan your PC button
      • A new window will open...click the Check Now button
      • Enter your Country
      • Enter your State/Province
      • Enter your e-mail address and click send
      • Select either Home User or Company
      • Click the big Scan Now button
      o If it wants to install an ActiveX component allow it
      o It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
      o When download is complete, click on My Computer to start the scan
      o When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

      Post the contents of the ActiveScan report

      Let me know how things are running :)
    • MsJessicaDzMsJessicaDz Dallas, TX
      edited April 2007
      Okay see below Panda Report - Just cookies, nothing bad - right???? I hope. PC seems to be running good.


      *****************************************

      Activescan.txt
      Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@2o7[2].txt
      Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@ads.pointroll[2].txt
      Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@as-eu.falkag[2].txt
      Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@as-us.falkag[1].txt
      Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@atwola[1].txt
      Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@bs.serving-sys[2].txt
      Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@burstnet[2].txt
      Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@citi.bridgetrack[2].txt
      Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@overture[1].txt
      Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@perf.overture[1].txt
      Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@questionmarket[2].txt
      Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@realmedia[1].txt
      Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@serving-sys[2].txt
      Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@trafficmp[1].txt
      Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@tribalfusion[1].txt
      Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\newtemp\Cookies\newtemp@www.burstbeacon[1].txt
    • Rahina-RescueRahina-Rescue Finland
      edited April 2007
      Only Cookies, they are harmless :)

      Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
      • Disable and Enable System Restore.
      If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

      You can find instructions on how to enable and reenable system restore here:

      Managing Windows Millenium System Restore
        Windows XP System Restore Guide

        Reenable system restore with instructions from tutorial above

        [*]Make your Internet Explorer more secure - This can be done by following these simple instructions:
        [*]From within Internet Explorer click on the Tools menu and then click on Options.
        [*]Click once on the Security tab
        [*]Click once on the Internet icon so it becomes highlighted.
        [*]Click once on the Custom Level button.
        1. Change the Download signed ActiveX controls to Prompt
        2. Change the Download unsigned ActiveX controls to Disable
        3. Change the Initialize and script ActiveX controls not marked as safe to Disable
        4. Change the Installation of desktop items to Prompt
        5. Change the Launching programs and files in an IFRAME to Prompt
        6. Change the Navigate sub-frames across different domains to Prompt
        7. When all these settings have been made, click on the OK button.
        8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
        [*]Next press the Apply button and then the OK to exit the Internet Properties page.
        • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

          See this link for a listing of some online & their stand-alone antivirus programs:

          Virus, Spyware, and Malware Protection and Removal Resources
        • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
        • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

          For a tutorial on Firewalls and a listing of some available ones see the link below:

          Understanding and Using Firewalls
        • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
        • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

          A tutorial on installing & using this product can be found here:

          Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
        • Install AVG Anti-Spyware - Install and download AVG Anti-Spyware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

          A tutorial on installing & using this product can be found here:

          Using AVG Anti-Spyware to remove Spyware, Malware, & Hijackers from Your Computer
        • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

          A tutorial on installing & using this product can be found here:

          Using SpywareBlaster to protect your computer from Spyware and Malware
        • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
        Follow this list and your potential for being infected again will reduce dramatically.

        here are some additional utilities that will enhance your safety
        • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
        • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
        • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
        • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
          Using Winpatrol to protect your computer from malicious software
        Let me know if you still receive problems :)
      Sign In or Register to comment.