Unsolved

This post is more than 5 years old

94 Posts

14103

October 20th, 2006 17:00

serious MIRAR problem on laptop

I’m having a serious problem with this on my laptop. This new MIRAR thing is stuck on my computer. I get nonstop popups and the IE closes by itself sometimes when there are too many popups. I deleted as much as I could from the add/remove option, but that didn’t help. I deleted MIRAR but it came back after I restarted the computer and everytime I open IE, it says it “cannot open” and under that phrase it gives a url to the mirar website or something like that. This message comes in a red box where the only option you have is to select “ok.” And also, all my icons on my desktop are highlighted for some reason. It’s like when you click an icon once and the the icon is highlighted blue. That’s how all my icons are. Also the popups come without me even opening IE. As long as the internet connection is working, the popups come automatically. I new icon on my desktop was added called “Tagasauras.” I deleted this. Here’s my hijackthis log:
Thanks for helping

Logfile of HijackThis v1.99.1
Scan saved at 1:59:43 PM, on 10/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\UHJhdmVlbiBLYXJ1bmFuaWRoaQ\command.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Veoh\VeohClientService.exe
C:\WINDOWS\jcfeuxz.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe
C:\Program Files\Dell Photo AIO Printer 944\memcard.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1158186795\ee\aolsoftware.exe
C:\WINDOWS\v1201.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\WINDOWS\jcfeuxzA.exe
C:\WINDOWS\cfg32.exe
C:\WINDOWS\sys02199520322-1.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\dfndrff_e33.exe
C:\kybrdff_e33.exe
C:\nwnmff_e33.exe
C:\WINDOWS\elitepop06.exe
C:\windows\system32\oodsregj.exe
C:\WINDOWS\ms0620322-11995.exe
C:\Program Files\webHancer\Programs\whagent.exe
C:\WINDOWS\Duce6.exe
C:\Program Files\Common Files\{B880C5BE-0724-1033-0609-060323060001}\Update.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\PSDream\PSDream.exe
C:\Program Files\CMFibula\CMFibula.exe
C:\PROGRA~1\COMMON~1\uimq\uimqm.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\COMMON~1\uimq\uimqa.exe
C:\WINDOWS\cfg32a.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\COMMON~1\YSTEM3~1\ping.exe
C:\WINDOWS\?dobe\??chost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.espn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\duomo.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,oqvqyjt.exe
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll
O2 - BHO: (no name) - {C44B8DE4-492E-61F1-7362-187495A779C3} - C:\WINDOWS\system32\jstrt.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O2 - BHO: (no name) - {D8C420CB-598C-4F8E-994F-554E6E9644E3} - C:\Program Files\Messenger\horecow.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcdmon.exe] "C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 944\memcard.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1158186795\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [jcfeuxzA] C:\WINDOWS\jcfeuxzA.exe
O4 - HKLM\..\Run: [unk1a8ba] RUNDLL32.EXE w14b3289.dll,n 0061a8b40000000314b3289
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [sys02199520322-1] C:\WINDOWS\sys02199520322-1.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_e33.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e33.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e33.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\rwinppes.exe ELT001
O4 - HKLM\..\Run: [1pop06apelt2] C:\WINDOWS\elitepop06.exe
O4 - HKLM\..\Run: [{0C-C5-5B-BE-ZN}] C:\windows\system32\oodsregj.exe ELT001
O4 - HKLM\..\Run: [ms0620322-11995] C:\WINDOWS\ms0620322-11995.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
O4 - HKCU\..\Run: [uimq] C:\PROGRA~1\COMMON~1\uimq\uimqm.exe
O4 - HKCU\..\Run: [Tair] "C:\PROGRA~1\COMMON~1\YSTEM3~1\ping.exe" -vt yazb
O4 - HKCU\..\Run: [Ndbtugya] C:\WINDOWS\?dobe\??chost.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\TIELT001.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\rwinppes.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154470619722
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156538806531
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - C:\Program Files\Batty2\Batty2.dll
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: mdc - C:\WINDOWS\SYSTEM32\SsoWindows.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\mmxml.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AEGIS SecureConnect Service (AEGIS SecureConnect) - Meetinghouse Data Communications - C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UHJhdmVlbiBLYXJ1bmFuaWRoaQ\command.exe
O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Veoh Client Service - Veoh Networks, Inc. - C:\Program Files\Veoh\VeohClientService.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\jcfeuxz.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

10.4K Posts

October 23rd, 2006 13:00

kvpp

Wow, that's quite a collection of Malware you have there. It will take a few runs at this to remove it all.
I need to know if you are willing to stick with me on this?
If you are, then lets begin.

Re Run Hijackthis
  • At the Main window select " Open the misc tool section"
    Then select " Open uninstall manager"
    Then " save list" and save it to your desktop
Copy and paste that list as a reply to this thread
 
bamajim   Graduate of Malware Removal University




94 Posts

October 23rd, 2006 15:00

Hey thanks for helping me out. I actually deleted some of the malware using hijack this. I had the Morwill search malware a year and a half ago so I have had experience with hijack. I'm not sure, but I think I removed the Mirar, but the popups keep coming and the icons on my desktop are still highlighted blue. Anyway, here is the list:

2006 FIFA World Cup (TM) Demo
944plc32
ABBYY FineReader 6.0 Sprint
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0.1
Adobe Shockwave Player
AEGIS SecureConnect
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Connectivity Services
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
ATI Catalyst Control Center
ATI Display Driver
BitTorrent 4.26.0
Broadcom Management Programs
Conexant HDA D110 MDC V.92 Modem
Consumer Complete Care Services Agreement
Corel Photo Album 6
Dell Digital Jukebox Driver
Dell Game Console
Dell Media Experience
Dell Photo AIO Printer 944
Dell Support 3.1
Digital Content Portal
Digital Line Detect
DMX Update
Documentation & Support Launcher
EducateU
ELIcon
FEAR Extraction Point SP Demo
FIFA 07 Demo
Games, Music, & Photos Launcher
Google Desktop
Google Toolbar for Internet Explorer
Google Video Player
High Definition Audio Driver Package - KB835221
HijackThis 1.99.1
Hitman 2: Silent Assassin
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Intel(R) PROSet/Wireless Software
IpWins
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
LimeWire PRO 4.12.3
LiveUpdate 3.0 (Symantec Corporation)
Madden NFL TM 2002
mCore
MCU
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
mIWA
mLogView
mMHouse
Modem Helper
Mozilla Firefox (1.5)
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB925672)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
mWlsSafe
mWMI
mXML
mZConfig
Need for Speed™ Most Wanted PC Demo
NetWaiting
Network Monitor
NHL06 DL PC Demo
PowerDVD 5.7
Qualxserve Service Agreement
QuickSet
QuickTime
RealPlayer
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925486)
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Synaptics Pointing Device Driver
TopSpin Demo
tupac_screensaver
TVUPlayer 2.2.0
Unreal Tournament 2004 Demo
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908521)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Veoh
Viewpoint Media Player
WebCyberCoach 3.2 Dell
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10
Windows Overlay Components
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859

10.4K Posts

October 23rd, 2006 17:00


kvpp

Try not to delete anything else please. There are certain infections that if you kill with Hijackthis before I can eliminate their file paths it will make them harder to locate and kill. And if they are not removed in the right order, they will just reload. Thanks.

First Go to Add/Remove Programs (Click Start->>Control Panel Add/Remove programs)
And uninstall the following
  • IpWins
    Network Monitor
    Windows Overlay Components

Close Add/Remove Programs

Next

1. Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
  • Under "Your computers Security"
    Click change status on Resident shield to inactive
    Click Update now (next to last update)
    After the update loads
    Under Automatic updates Uncheck download and install updates automatically(recommended)
    (you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tab
  • Under How to act? Set default action for detected malwareTo Quarantine
    Under how to scan All boxes should be checked
    Under Possibly unwanted software All boxes should be checked
    Under reports Select Automatically generate report after every scan
    Uncheck Only if threats were found
    Under what to scan Scan every file should be highlited
Exit AVG(But do not run it yet)

2. Please download Brute Force Uninstaller to your desktop.

  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C: ) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As" ) in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter
4. Run AVG Anti-Spyware
  • Click scanner
    Select Complete system scan
Once the scan finishes
  • Select Apply all actions (The items found will be quarantined)
    Click save report as (Another window will open)
    Save it to your desktop
    (By default It will be saved in the AVG folder as)
    C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG

5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.

  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon user posted imageand select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
  • Double click the report-scan txt. you saved to your desktop
    It will open in Notepad
    Copy and paste that report as a reply to this thread
Your reply should include
  • a fresh hijackthis log
    your report_scan.txt from AVG
    bamajim   Graduate of Malware Removal University
     






    94 Posts

    October 24th, 2006 19:00

    Part 3 AVG Scan log:

    :mozilla.18:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
    C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
    :mozilla.165:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.64:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.66:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.67:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.68:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.70:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.98:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.88:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\LocalService\Cookies\system@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@overture[2].txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.113:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.114:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.115:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned.
    :mozilla.89:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.90:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.91:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.122:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.123:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.124:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.126:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.118:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.119:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@media.top-banners[1].txt -> TrackingCookie.Top-banners : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.101:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.102:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@ac2.valuead[1].txt -> TrackingCookie.Valuead : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.138:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.139:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
    C:\dfndrff_e33.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\nwnmff_e33.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005095.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005191.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006036.exe -> Trojan.VB.atp : Cleaned with backup (quarantined).
    C:\WINDOWS\elitepop06.exe -> Trojan.VB.atp : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP40\A0004925.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP40\A0004926.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006042.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006043.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\WINDOWS\109uninst.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\WINDOWS\uni_7eh.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\About CNET Networks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\All RSS feeds.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\All Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\CNET TV.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Compare Prices.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Contact Us.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Firefox plugin.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Free MP3s.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Help Center.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOC Email Checker 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOC MP3 Finder 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOC Master Shutdown 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOC Web Finder 5.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOC Web Spider 5.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOT Journaler 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JOpt.SDK - route optimization library 1.0.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPBHomeSolutions I 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPBHomeTime 2.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEE Email Utility Lite 5.3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG 2000 Compressor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG 2000 Dropper 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Image Enhancer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Imager 2.2.2.29.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Japery 1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Lossless Resave plug-in for Photoshop 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Lossless Rotator 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Recovery 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Viewer 0.12 build 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEG Wizard for Photoshop 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEGCompress 2.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEGCrops 0.7.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPEGCruncher Desktop 2.0.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPG 4 Email 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPG File Sizer 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPGCube 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPGReader 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPGallery Image Gallery Creator 3.0 build 580.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPSViewer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPTorrent 2.01 2.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPTorrent Light 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPhotoBrush Pro 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JPlayer 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JProbe Profiler Freeware 5.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JProfiler 4.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JProxy 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JR Directory Printer 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JR Screen Ruler 1.4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JR Split File 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JR Split File Pro 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JRelaxTimer 1.0.001.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JS Virtual Piano 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JS-DUC 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSCAPE Secure FTP Server 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSCruncher Pro 3 build 150.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSPMaker 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSQLConnect 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSQLMapper 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSS Clock Sync 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).

    94 Posts

    October 24th, 2006 19:00

    Part 4 AVG Scan log:

    C:\Documents and Settings\Praveen Karunanidhi\Complete\JScreenFix 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JScreenPrint 0.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JScript 5.6 Security Patch for Windows 2000 and XP MS03-008.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JScript 5.6 Security Patch for Windows MS03-008.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSearch Builder 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSecureConnect 2.21.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JSetup Professional 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JShopper 1.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JShowBuilder 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JT Maps 2005 1.3.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTB FlexReport 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTM - Java Tree Menu 3.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTY Painter 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTerm 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTier Internet News Server 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JTroll 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JUnitConv 1.0.001.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JUpload Applet 0.79.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JVC Everio Utility 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JVPoker Classic 1.4.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JVW Popup Maker and DHTML Ad Generator 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JWTM (Web Tree Menu) 1.1.003.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JWinSvc 1.3.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JX Ovulation Calendar 1.1.76.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JXHTMLedit 4.0.005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JXMLPad 3.4 FC.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JXOpen 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoBryxz 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoKenPo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoKenPo 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Job Tracker 1.05.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Job Tracker 3.01.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Job Tracker Professional 1.0.29.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Job-Finder Minder 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Job2C 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobBlade for Oracle 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobCost Controller for Excel 2.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobFish 2004 build 621.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobPro Central 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobPro Central 4.0v2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobQuest 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobSeeker 2.1.1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobTabs 2006 3 build 1133.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JobTrakLite 1.52.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jobber Computer Plus 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joc History Eraser 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jock Desk 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JodakoWM Wireless Messenger 04.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joe Galaxy Mayacal Edition 2006.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joe Galaxy.NET 2005v12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joel 228 Dreams and Visions Logbook 1.5.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joes 3-D Scavenger Hunt 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joes MySpace Editor 1.4.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joga.com Companion 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joh Man's 0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Deere American Farmer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Deere American Farmer 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Gould Hummingbirds 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Kerry for President NewsReader 1.0.2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Muir's Steep Trails 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Peterson Pictures Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John Singer Sargent Screensaver 4.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\John's Bingo 1.88.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Johnny Depp Screensaver 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Johnny Herbert's Grand Prix World Champions demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Join (Merge) Text Files 7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Join Me 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Join Split Convert Video 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joiner 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Operations Typhoon Rising Jakarta Siege map .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Operations Typhoon Rising multiplayer patch 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Operations Typhoon Rising patch 1.1.0.16.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Operations Typhoon Rising patch 1.3.1.15.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Operations Typhoon Rising updated multiplayer demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joint Task Force single-player demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joke Sleuth 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joke411 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joker's Quest 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JollyPaintbook 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JollyPairs 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JollySnake 1.0.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoltIP 1.06b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jonathon Rossi BattleShips 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JongPuzzle 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jonny the Homicidal Maniac .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joomlaspan Chitika eMiniMalls module Stable.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joomlaspan Google AdSense Module 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joox Voting Toolbar 3.1.19.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jor's Opera Setup 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jordan Smith's Easy Icon Maker 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joseki for Windows 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Josh's World .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joshs Video of the Month Toolbar 4.5.65.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joshua's ChordTutor for Guitar 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jot+ Notes 3.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JotMe Primo 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JotSmart 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JotSmart Pro 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journal Bar 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journal Macro 1.84.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journal Protected 2.3.18.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journal Tracker 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JournalX 2.1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journey Master 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Journyx Timesheet 7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).

    94 Posts

    October 24th, 2006 19:00

    Part 5 AVG scan log:

    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jovian 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joy Mobile Manager for Siemens 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joy RingTone Converter 1.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joy To The World (Joy Online) 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoyceCD 3.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JoyiStar WebShop 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joystick Remote for Winamp 3.1b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Joystick-To-Mouse 2.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jpeg Fixer 0.96.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jpeg2000 SDK 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JpegSizer 4.0a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jpg Animated Slide Show 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jr. Architect 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jr. Doctor 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jr. Firefighter 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jr. Scientist 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jr. Vet 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jshock 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jubler 2.9.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jude Law Screensaver 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Judicial Offense Tracker 2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Judo Scoreboard Deluxe 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Judy's Kitchen 2003 1.0.59.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juerguistaz Script 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juggle (OS X) 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juice 2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juiced final demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juicy Business Cards 1.10.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juke 3.8.7.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeANator Digital Jukebox 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeBox 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeBx 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeJam 8.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeTrax - The Jukebox Printing Press 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jukebox Pro 1.0.68.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JukeboxHero.ca 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JulDate 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Julia Explorer 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Julia O' Matic 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Julia Stiles -E Screensaver 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Julia's Time Adventures - Back to the Roaring 20s .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JuliaShapes 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Julius 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jumble Solve 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jump Shot Basketball 5.55.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jump Teddy 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jump Zampoli 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JumpBack 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JumpKeys 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JumpStart 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JumpVault Backup Software 3.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jumpin Jehosaphat WP 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jumpstart-it 2.0.1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jumpwel 5.05.005.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Animated Windows Screensaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Balls 1.2.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Cats 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Heart 1.7.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Heart 1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Heart Family Edition 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Queens DT 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Queens WP 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Stalker WP 1.00.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Storm 3.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Waterfall Animated Screensavers 3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jungle Waterfall Animated Wallpapers 3.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Junior Icon Editor 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juniper Practice Tests from Boson 4.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Junk Food Fruits Puzzle 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Junk Mail Remover 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Junk-Out 1.14.0048.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JunkSweep 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JunkWarden for Outlook Express 2.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jupiter 3D ScreenSaver 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jupiter Grid 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jurassic Park Operation Genesis .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jurassic Park and The Lost World Theme 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jurassic Pinball 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jurgen 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jurtle 1.8.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Another Analog Clock 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Another Tetris Clone 1.2b.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just BASIC 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Bar Codes 1.3.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Bar Codes CL 1.0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Buttons 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Cause demo .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Checking 3.06.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Like Heaven Trailer .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Money 1.11.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Shoot The Thing 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Sudoku - Professional Edition 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Sudoku 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Tabs 2.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Wallpaper 3.1a.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just Watching 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Just WebMail 1.9.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustAddCommerce 5.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustCad 6.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustClick 1.2 build 1390.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustCursors 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustHTML Editor 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustInbox 4.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustLDAP 4.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustRemoteIT 1.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustRip'n'Burn 2.1.24.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustStartIt 0.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustUrls 5.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustZipIt 102.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustaCal 1.2.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Justbackup 1.5.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JustbackupPro 1.5.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Justice Force of America 2 (Freedom Force) patch .zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Justin Timberlake Screensaver 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juvenile Data 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juz 'Amma Player 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Juzt-Reboot SW 7.61D.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jv16 PowerTools 1.4.1.238.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jv16 PowerTools 2005 1.5.1.31.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JvCrypt 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jvider 1.6.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jvw FTP Client 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jvw File & Folder Hider 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jvw History Eraser 1.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Jyve 0.8.9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\JzChat 1.12.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\New layout.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\PC Games.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Privacy policy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Recover password.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).

    94 Posts

    October 24th, 2006 19:00

    I couldn't fit everything in one post. I couldn't even fit the AVG scan log in one post. Here's part of the AVG scan log:

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 4:17:55 PM 10/24/2006

    + Scan result:



    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\stub_sca4.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004876.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004877.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004878.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004879.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004880.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005433.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\cfg32p.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\cfg32r.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\cfg32s.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\msnrtfoa.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\nnapyypq.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\rrqongbh.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINDOWS\xgskskzm.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\hijackthis\backups\backup-20061021-135035-523.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Adware.BookedSpace : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Adware.BookedSpace : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BookedSpace.Extension.5 -> Adware.BookedSpace : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Adware.BookedSpace : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\Program Files\Batty2\Batty2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
    C:\Program Files\Batty2\Batty2.exe -> Adware.CASClient : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006074.exe -> Adware.CASClient : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\BattyRun2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP40\A0004921.dll -> Adware.Comet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005245.dll -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005246.exe -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\WINDOWS\UHJhdmVlbiBLYXJ1bmFuaWRoaQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\WINDOWS\UHJhdmVlbiBLYXJ1bmFuaWRoaQ\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
    HKU\S-1-5-21-3027019530-2377796245-1203868405-1006\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
    HKU\S-1-5-21-3027019530-2377796245-1203868405-1006\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
    C:\Installer4.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004887.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\lokrn11n.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\mmxml.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006046.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
    C:\WINDOWS\elitesix.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
    C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mit4C.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mit4C.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mitCF.tmp.cab/NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mitCF.tmp/NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mitD3.tmp.cab/NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\mitD3.tmp/NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP38\A0004904.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP38\A0004905.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005432.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005455.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005473.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\WinDmy.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\hijackthis\backups\backup-20061021-135035-627.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\hijackthis\backups\backup-20061021-140833-264.dll -> Adware.Mirar : Cleaned with backup (quarantined).
    C:\Program Files\filesubmit\tupacskr.exe\NNWDAC638.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003410.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003422.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003423.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003424.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003425.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP14\A0003427.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\KBBar.KBBarBand -> Adware.PowerStrip : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\KBBar.KBBarBand.1 -> Adware.PowerStrip : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CLSID -> Adware.PowerStrip : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CurVer -> Adware.PowerStrip : Cleaned with backup (quarantined).
    C:\Program Files\PrintView\printhook030.dll -> Adware.PrintView : Cleaned with backup (quarantined).
    C:\Program Files\PrintView\pvmodule.exe -> Adware.PrintView : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005096.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0005850.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006073.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\WINDOWS\rk.exe -> Adware.Relevant : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005098.exe -> Adware.RK : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006044.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\WINDOWS\876056.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\WINDOWS\MirarSetup_876057.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\{3880C5BE-0724-1033-0609-060323060001}\MyToolBar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\{B880C5BE-0724-1033-0609-060323060001}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\{B880C5BE-0724-1033-0609-060323060001}\services.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Deskbar -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Deskbar\deskbar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Deskbar\inst.bat -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004883.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005172.dll -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\deskbar.exe -> Adware.Softomate : Cleaned with backup (quarantined).
    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned with backup (quarantined).
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned with backup (quarantined).
    HKU\S-1-5-21-3027019530-2377796245-1203868405-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8B28872-3324-4CD2-8AA3-7D555C872D96} -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\i291.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004886.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005459.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005460.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005461.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005464.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005335.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\license.txt -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\readme.txt -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\sporder.dll -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\webhdll.dll -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\whagent.exe -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\whagent.ini -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\whiehlpr.dll -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\Program Files\webHancer\Programs\whinstaller.exe -> Adware.Webhancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005338.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005339.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj.1 -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj\CurVer -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\webhancer -> Adware.WebHancer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\webhancer\CC -> Adware.WebHancer : Cleaned with backup (quarantined).

    94 Posts

    October 24th, 2006 19:00

    Here's my new HJT log and the scan log
    HJT log:

    Logfile of HijackThis v1.99.1
    Scan saved at 4:31:30 PM, on 10/24/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Veoh\VeohClientService.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\NetWaiting\netWaiting.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\Program Files\PSCastor\PSCastor.exe
    C:\Program Files\Common Files\AOL\1158186795\ee\aolsoftware.exe
    C:\Program Files\CMIntex\CMIntex.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.espn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\duomo.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,oqvqyjt.exe
    O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
    O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL (file missing)
    O2 - BHO: (no name) - {D8C420CB-598C-4F8E-994F-554E6E9644E3} - C:\Program Files\Messenger\horecow.dll (file missing)
    O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
    O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22.dll' missing
    O11 - Options group: [INTERNATIONAL] International*
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.mmohsix.com
    O15 - Trusted Zone: http://click.getmirar.com (HKLM)
    O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
    O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154470619722
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156538806531
    O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
    O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: mdc - C:\WINDOWS\SYSTEM32\SsoWindows.dll
    O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\mmxml.dll (file missing)
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
    O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\lokrn11n.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AEGIS SecureConnect Service (AEGIS SecureConnect) - Meetinghouse Data Communications - C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Veoh Client Service - Veoh Networks, Inc. - C:\Program Files\Veoh\VeohClientService.exe
    O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\jcfeuxz.exe (file missing)
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    94 Posts

    October 24th, 2006 19:00

    Part 2 AVG Scan log:

    HKLM\SOFTWARE\webhancer\ESO -> Adware.WebHancer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005330.exe -> Adware.Webhancer.a : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004892.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006039.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\TIELT001.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\dsreg.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\oodsregj.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\rwinppes.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP41\A0004935.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP41\A0004936.exe -> Backdoor.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004888.exe -> Downloader.Adload. : Cleaned with backup (quarantined).
    C:\mc44a3.exe -> Downloader.Adload. : Cleaned with backup (quarantined).
    C:\kybrdff_e33.exe -> Downloader.Adload.gw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005088.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004893.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\aaa00000.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\unk1a8ba.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temp\OA.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP38\A0004900.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0005852.exe -> Downloader.PurityScan.dr : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004853.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005089.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005090.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005091.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005092.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005094.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\w018142f.dll -> Downloader.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\w14b32898.dll -> Downloader.Small : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\w1f61d81.dll -> Downloader.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004849.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
    C:\MTE3NDI6ODoxNg.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004889.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004890.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP39\A0004909.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006045.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\WINDOWS\idlemg.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\Program Files\Messenger\horecow.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004882.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006038.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
    C:\WINDOWS\ac3_0002.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005002.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005326.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005001.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005334.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0004999.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005333.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0004997.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005000.exe -> Downloader.TSUpdate.p : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005325.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
    C:\WINDOWS\jcfeuxzA.exe -> Downloader.VB.ang : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004854.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004855.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004856.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005099.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005239.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005240.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006060.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006061.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006062.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006063.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\WINDOWS\sys02199520322-1.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\WINDOWS\sys0399520322-11.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\WINDOWS\sys11-1199520322.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\WINDOWS\win320922-11995203.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
    C:\WINDOWS\jcfeuxz.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP46\A0005486.exe -> Dropper.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004894.exe -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP45\A0005184.exe -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006047.exe -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP52\A0006080.exe -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Local Settings\Temporary Internet Files\Content.IE5\GTQMB7C5\wallpap[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\Program Files\ComPlus Applications\howymym.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\kyzep.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP37\A0004874.exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
    C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
    :mozilla.159:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.160:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.24:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.25:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.26:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.27:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.29:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.30:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.31:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
    :mozilla.125:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.127:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.128:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.129:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.130:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.131:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.170:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.171:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@www.adtrak[1].txt -> TrackingCookie.Adtrak : Cleaned.
    :mozilla.75:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.77:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.78:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.79:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.80:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.44:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.120:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.97:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\LocalService\Cookies\system@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.51:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.46:C:\Documents and Settings\Praveen Karunanidhi\Application Data\Mozilla\Firefox\Profiles\vqlvdap1.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
    C:\Documents and Settings\Praveen Karunanidhi\Cookies\praveen_karunanidhi@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.

    94 Posts

    October 24th, 2006 19:00

    Final Part AVG Scan log:

    C:\Documents and Settings\Praveen Karunanidhi\Complete\Register Now.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Server Move.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Site map.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Spyware Removal.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Submit Software.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Terms of use.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\The Market 2.0.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Tips & Tricks.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Today on CNET.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\TorrentPod Episode 9.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\Two Swedes Got Fined for Sharing Files.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\battlestar galactica.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\company of heroes.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\desperate housewives.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\family guy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\fifa 07.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\fifa 2007.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\gilmore girls.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\gothic 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\grey s anatomy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\greys anatomy.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jPDFViewer 1.61.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jRestaurant 3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jTFlashManager 1.1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jWebApp 2.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\ 2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\joshhumble.com wallpapers Port Everglades #1 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\joshhumble.com wallpapersPort Everglades #1 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jsLogix 1.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\just cause.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jv16 PowerTools 2006 1.5.2.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jvprinter 1.5.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\jxcell 1.3.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\miami vice.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\my name is earl.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\need for speed carbon.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\nip tuck.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\one tree hill.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\open season.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\prison break.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\south park.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\the departed.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\the killers.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\the office.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\windows xp.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Praveen Karunanidhi\Complete\world trade center.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Program Files\outlook\p.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\Program Files\outlook\v.tmp -> Worm.VB.dw : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP41\A0004934.exe -> Worm.VB.dw : Cleaned with backup (quarantined).


    ::Report end

    10.4K Posts

    October 24th, 2006 23:00

    kvpp

    You have a file, or files, on your PC that I would like to have checked.
    Please go here and click on the Browse... button at the top and navigate to the following file(s), one at a time:

    C:\WINDOWS\SYSTEM32\SsoWindows.dll

    and then click on Submit.

    When all the scans have been completed, please copy and paste the results into your next reply.

    You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
    ** These files are hidden to stop you accidentally removing something important.

     It is advisable to hide them again after fixing your computer. **
     
    bamajim   Graduate of Malware Removal University




    94 Posts

    October 25th, 2006 02:00

    Here are the results:

    Service load:
    0% 100%
    File: SsoWindows.dll
    Status:
    OK (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
    MD5 14889037c442afb2755693eede536ba9
    Packers detected:
    -
    Scanner results
    AntiVir
    Found nothing
    ArcaVir
    Found nothing
    Avast
    Found nothing
    AVG Antivirus
    Found nothing
    BitDefender
    Found nothing
    ClamAV
    Found nothing
    Dr.Web
    Found nothing
    F-Prot Antivirus
    Found nothing
    Fortinet
    Found nothing
    Kaspersky Anti-Virus
    Found nothing
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    VirusBuster
    Found nothing
    VBA32
    Found nothing

    10.4K Posts

    October 25th, 2006 13:00

    kvpp

    Thanks for checking that file. When we see an unknown, it never hurts to be sure.

    First Copy and paste the following into NotePad (Not Wordpad)
    • sc stop "Windows Overlay Components"
      sc delete "Windows Overlay Components"

    Click File ->> Save as ->>type in cmd.bat
    • Under "Save as type" Select " all files" ->>Save it to your Desktop
      Close Notepad
      The cmd.bat file should now appear on your Desktop
      Double Click that file (It will appear that nothing has happened, but that's o.k.)
    Next Please download the Killbox.
    • 1) Save it to the desktop and run it.
      2) Select " Delete on Reboot", and then select "All files".
      3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

      • C:\WINDOWS\system32\duomo.exe
        C:\Program Files\CMIntex\CMIntex.exe
        C:\Program Files\PSCastor\PSCastor.exe
        C:\Program Files\webHancer\Programs\whagent.exe

      4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
      5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.
    Next Rerun Hijackthis (scan only) and place checks beside the following entries
    • F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\duomo.exe
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,oqvqyjt.exe
      O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
      O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
      O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
      O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
      O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL (file missing)
      O2 - BHO: (no name) - {D8C420CB-598C-4F8E-994F-554E6E9644E3} - C:\Program Files\Messenger\horecow.dll (file missing)
      O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
      O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
      O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
      O4 - HKCU\..\Run: [PSCastor] "C:\Program Files\PSCastor\PSCastor.exe"
      O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
      O11 - Options group: [INTERNATIONAL] International*
      O15 - Trusted Zone: *.elitemediagroup.net
      O15 - Trusted Zone: *.media-motor.net
      O15 - Trusted Zone: *.mmohsix.com
      O15 - Trusted Zone: http://click.getmirar.com (HKLM)
      O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
      O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
      O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
      O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\mmxml.dll (file missing)
      O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\lokrn11n.dll (file missing)
      O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\jcfeuxz.exe (file missing)
    Close all other open windows except Hijackthis and Select " Fix checked"

    Reboot your PC->>Rerun Hijackthis and post a fresh Hijackthis log please
     
    bamajim   Graduate of Malware Removal University
     



    94 Posts

    October 25th, 2006 16:00

    Heres the new HJT log. When I ran hijackthis and was checking the boxes you told me too, the last one, which was the O23 Windows Overlay Components, was not there. I just wanted to tell you that.

    Logfile of HijackThis v1.99.1
    Scan saved at 12:56:30 PM, on 10/25/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Veoh\VeohClientService.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\NetWaiting\netWaiting.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\Program Files\Valve\Steam\Steam.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Common Files\AOL\1158186795\ee\aolsoftware.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.espn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22.dll' missing
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154470619722
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156538806531
    O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
    O18 - Filter: text/html - {994D478A-45D0-4DB4-AE27-738B1E346F99} - (no file)
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: mdc - C:\WINDOWS\SYSTEM32\SsoWindows.dll
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AEGIS SecureConnect Service (AEGIS SecureConnect) - Meetinghouse Data Communications - C:\Program Files\Meetinghouse\AEGIS SecureConnect\ConnectionClient.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Veoh Client Service - Veoh Networks, Inc. - C:\Program Files\Veoh\VeohClientService.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    10.4K Posts

    October 25th, 2006 23:00

    kvpp
     
    The batch file we made killed it, but I included it in the HJT removal list to make sure :smileyhappy:
     
    How's your PC running now?
     
    bamajim   Graduate of Malware Removal University

     

    No Events found!

    Top