1
   

Aurora/ABI Network popup problem

 
 
WLW
 
Reply Sat 3 Sep, 2005 06:04 am
About a week ago ads started popping up on my computer from ABI. I tried to get rid of them using the tool they recommended but it didn't work. I (hopefully) went thru your procedure, and am posting the Hijack log and other info below.

=============================================
The last McAfee scan on 9/3/05 showed this:

C:\WINDOWS\qssyea.exe == Cannot be cleaned == Program Name: Adware-abetterintrnt
C:\WINDOWS\system32\in3b6s.dll == Cannot be cleaned == Program Name: Adware-abetterintrnt
D:\Program Files\Quark\QuarkXpress 6.0\Quark.exe == Cannot be cleaned == Program Name: Tool-TPatch
=============================================


Logfile of HijackThis v1.99.1
Scan saved at 8:14:23 PM, on 9/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Conversions Plus\FORMATM.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Conversions Plus\MacName.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\No-IP\DUC20.exe
C:\mysql\bin\winmysqladmin.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLHOS~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLServiceHost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\HJT\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Wayman L. Widgins\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=090705 serial=DR12CRP-2909658-QBC lang=EN
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1101239718\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/registration/3_0_0_804/sdcregie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) - http://www.stamps.com/download/us/cab/stamps/stamps.cab?r=0.26698548657567&file=stamps.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by10fd.bay10.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:40:20 PM, 9/2/2005
+ Report-Checksum: AA3D0535

+ Scan result:

HKLM\SOFTWARE\Classes\.s3d -> Spyware.BrilliantDigital : Cleaned without backup
HKLM\SOFTWARE\Classes\CLSID\{27557cf1-a237-496d-8c8f-08f3844c6a8b} -> Spyware.WhistleSoftware : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselLogServices -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselLogServices\CLSID -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselLogServices\CurVer -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselXmlServices -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselXmlServices\CLSID -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Classes\WselServices.WselXmlServices\CurVer -> Spyware.Whistle : Cleaned without backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27557cf1-a237-496d-8c8f-08f3844c6a8b} -> Spyware.WhistleSoftware : Cleaned without backup
HKU\S-1-5-21-1004336348-706699826-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{27557CF1-A237-496D-8C8F-08F3844C6A8B} -> Spyware.WhistleSoftware : Cleaned without backup
HKU\S-1-5-21-1004336348-706699826-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D568F0F-8AC9-40AB-88B7-415134C78777} -> Spyware.Begin2Search : Cleaned without backup
HKU\S-1-5-21-1004336348-706699826-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{52FE5233-367C-4EFB-BDD7-0BE4D212C107} -> Spyware.Begin2Search : Cleaned without backup
[776] VM_00AF0000 -> Adware.BetterInternet : Error during cleaning
[888] C:\WINDOWS\system32\khfrax.exe -> Trojan.Agent.cp : Cleaned without backup
:mozilla.6:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.7:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.8:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.10:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.11:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.12:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned without backup
:mozilla.13:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned without backup
:mozilla.14:C:\Documents and Settings\WLW\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@-1shz2prbmdj6wvny-1sez2pra2dj6wjkygoajwbow-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1sdzwbogqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@a-1shz2prbmdj6wvny-1sez2pra2dj6wfkiqhdpmhog-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@a-1shz2prbmdj6wvny-1sez2pra2dj6wjmikkdzsgoa-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@a-1shz2prbmdj6wvny-1sez2pra2dj6wjnyuodzckpg-1dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@com[2].txt -> Spyware.Cookie.Com : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Masterstats : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4ggczshoqudj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkigocpmfoqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkiond5olowwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkoopdpkgoqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkowgdzekpqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfkyqld5eboqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wflieoc5mgpg6dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wfloshdjsaowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4khdzghqqydj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4qocpohpasdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4umczolqqsdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4whazcaogqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoaoajmfoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkocnajoeoaqdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoejajcfoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoeodzcaqq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkogkdpsgqaydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkokhcpsapq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkowjdjikpqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkykgdjwboqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkykhdpmdogwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyklajaloaidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyokczkgpaidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyuhajaepasdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4ggaziboq2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4gmdjmeoqwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjl4und5ikowudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlialdpiboawdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjligpd5gbow6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliqmczkkpgsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloagazcboaudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloapdzifoqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlocjazgepaqdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlokhajoepa6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlokocpaeqawdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyajdjicpgydj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlycidjgbow2dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlyugc5kgoqidj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiemdzclpg2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmisgcpefqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmiumazegogqdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyanczsapwmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycgd5wcowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycgdjclpwidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnychdjklqaidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycicpkdpgmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnycmc5wboqsdj6x9ny-1seq-2-2.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygicpsloaudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygmazsboaudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygodzwdoamdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Cookies\WLW@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyokazmdpwudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned without backup
C:\Documents and Settings\WLW\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
C:\Documents and Settings\WLW\Local Settings\Temp\Cookies\WLW@com[2].txt -> Spyware.Cookie.Com : Cleaned without backup
C:\Documents and Settings\WLW\Local Settings\Temp\sntaudio.tmp -> Spyware.SafeSurfing : Cleaned without backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned without backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned without backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned without backup
C:\WINDOWS\mrfbneyjma.exe -> Adware.BetterInternet : Cleaned without backup
C:\WINDOWS\system32\pkshsidg.dll -> Spyware.SafeSurfing : Cleaned without backup
C:\WINDOWS\system32\pshwr.exe -> Spyware.SafeSurfing : Cleaned without backup
D:\Program Files\Shareaza\downloads\OmniPage Pro 14 Office.zip/setup.exe -> Trojan.Crypt.e : Cleaned without backup


::Report End

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:09:58 PM, 9/2/2005
+ Report-Checksum: 892986EA

+ Scan result:

No infected objects found.


::Report End

============================================
PANDA ACTIVESCAN REPORT
============================================

Incident Status Location

Adware:Adware/EnhSrch No disinfected C:\WINDOWS\dsr.dll
Virus:Trj/Pakes.AX Disinfected Operating system
Adware:adware/aurora No disinfected C:\WINDOWS\system32\DrPMon.dll
Adware:adware/aurora No disinfected C:\WINDOWS\SYSTEM32\DrPMon.dll
Spyware:spyware/whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Adware:adware/sahagent No disinfected C:\DOCUMENTS AND SETTINGS\WLW\LOCAL SETTINGS\TEMP\bundletracking.asp
Adware:adware/kingporn No disinfected C:\DOCUMENTS AND SETTINGS\WLW\LOCAL SETTINGS\TEMP\ExtractDLL.dll
Adware:adware/transponder No disinfected C:\WINDOWS\abiuninst.htm
Adware:adware/enhsrch No disinfected C:\WINDOWS\dinst.exe
Spyware:spyware/aveo-attune No disinfected C:\PROGRAM FILES\Aveo
Adware:adware/clocksync No disinfected C:\PROGRAM FILES\ClockSync
Adware:adware/sidesearch No disinfected C:\PROGRAM FILES\Lycos
Adware:adware/ncase No disinfected C:\PROGRAM FILES\nCase
Adware:adware/cws No disinfected C:\DOCUMENTS AND SETTINGS\WLW\FAVORITES\Health
Dialer:dialer.bjp No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONEMAP\DOMAINS\ARCHIVIOSEX.NET
Dialer:dialer.akd No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\ZONEMAP\DOMAINS\SGRUNT.BIZ
Spyware:spyware/shopnav No disinfected Windows Registry
Virus:Eicar.Mod No disinfected C:\Documents and Settings\WLW\Desktop\kaspersky\Kaspersky Anti-Virus Personal v4.5.0.94 Regged-Pleasuredome101\data1.cab[eicar.html]
Virus:Trj/Pakes.AX Disinfected C:\Documents and Settings\WLW\Local Settings\Temp\135.tmp
Spyware:Spyware/SafeSurf No disinfected C:\Documents and Settings\WLW\Local Settings\Temp\ExtractDLL.dll
Virus:Trj/Pakes.AX Disinfected C:\Documents and Settings\WLW\Local Settings\Temporary Internet Files\Content.IE5\OD2FSL2N\Poller[2].exe
Virus:Trj/Stervis.D Disinfected C:\Documents and Settings\WLW\Local Settings\Temporary Internet Files\Content.IE5\UFM3IHYJ\svcproc[1].exe
Spyware:Spyware/Cydoor No disinfected C:\Program Files\Spybot - Search & Destroy\Dummies\dummy.cd_clint.dll
============================================
MISCELLANEOUS
============================================
When I tried to run nailfix.cmd, I received a message saying that process.exe was missing...


THANKS IN ADVANCE FOR ANY HELP YOU CAN PROVIDE.

WLW
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,213 • Replies: 13
No top replies

 
timberlandko
 
  1  
Reply Sat 3 Sep, 2005 08:56 am
Lets see another HJT log, from immediately following a fresh normal boot.

One thing I'd like to mention is that the Ad-Aware SE, EWIDO, Microsoft Antispyware, and Spybot S&D scan & fix steps should each be run a couple times at least while in safe mode.
0 Replies
 
WLW
 
  1  
Reply Sat 3 Sep, 2005 09:15 am
okay. i'll generate a new HJT report and post it shortly.
0 Replies
 
WLW
 
  1  
Reply Sat 3 Sep, 2005 09:58 am
Logfile of HijackThis v1.99.1
Scan saved at 11:56:02 AM, on 9/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Conversions Plus\FORMATM.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLHOS~1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLServiceHost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Conversions Plus\MacName.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\No-IP\DUC20.exe
C:\mysql\bin\winmysqladmin.exe
C:\HJT\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Wayman L. Widgins\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=090705 serial=DR12CRP-2909658-QBC lang=EN
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1101239718\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/registration/3_0_0_804/sdcregie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) - http://www.stamps.com/download/us/cab/stamps/stamps.cab?r=0.26698548657567&file=stamps.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by10fd.bay10.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
0 Replies
 
timberlandko
 
  1  
Reply Sat 3 Sep, 2005 01:28 pm
That's looking lots better ... mebbe not done yet, but getting pretty close.

With no browsers or other windows open, run HJT, place a checkmark next to each of Only the following entries, if found:

O9 - Extra button: Whistle - {220E39C3-B081-4719-AB1A-9A884DCBD05C} - C:\WINDOWS\System32\shdocvw.dll
O16 - DPF: {12589FA1-C456-11CE-BF01-10AA1055595A} - http://www.wsel.net/imcupdatefiles/whistlesilent610.cab
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)


Click "Fix Checked". Also, look in Add/Remove Programs for anything named or closely resembling "Whistle", "Whistles Software" or "Whistle Toolbar" - anything recognizeably close to that needs to be removed. Whether or not you find anything in Add/Remove, using Windows Explorer (Windows key + E") search your Programs folder for anything similarly named - some variant on "Whistle" - and, if found, delete the entire suspect folder - not the Programs folder, just any folder clearly related to Whistle. Then locate and launch CCleaner, select "Issues", scan, and allow it to"fix" all issues found, then select Cleaner, and run a full scan-and-clean with CCleaner, then reboot normally, immediately run a scan with HJT, fixing nothing, and post the log.
0 Replies
 
WLW
 
  1  
Reply Sat 3 Sep, 2005 04:16 pm
Logfile of HijackThis v1.99.1
Scan saved at 6:07:49 PM, on 9/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Conversions Plus\FORMATM.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLHOS~1.EXE
D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Conversions Plus\MacName.exe
C:\PROGRA~1\COMMON~1\AOL\110123~1\EE\AOLServiceHost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\No-IP\DUC20.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\mysql\bin\winmysqladmin.exe
C:\HJT\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Wayman L. Widgins\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=090705 serial=DR12CRP-2909658-QBC lang=EN
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1101239718\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/registration/3_0_0_804/sdcregie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) - http://www.stamps.com/download/us/cab/stamps/stamps.cab?r=0.26698548657567&file=stamps.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by10fd.bay10.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

I also did a search for nail.exe and found the file:
NAIL.EXE-25042152.pf in the C:\WINDOWS\Prefetch folder.
0 Replies
 
timberlandko
 
  1  
Reply Sat 3 Sep, 2005 08:55 pm
Quote:
I also did a search for nail.exe and found the file:
NAIL.EXE-25042152.pf in the C:\WINDOWS\Prefetch folder

That should go away. NAIL doesn't appear to be running on your machine, but lets make sure. CCleaner ought to have emptied Prefetch, but apparently didn't, so I suggest you download and install (but don't yet run) Steve Gould's similar, but slightly different app, Cleanup! 4 - be sure to read the FAQ HERE. It should remove anything and everything of a "temporary" nature (and it might take it a while to do it - its pretty thorough). I'm gonna hafta look into why CCleaner missed that one - thanks for the feedback.

Also interesting is that we seem to have 1 new orphan Service reference, "LicCtrlService", and "MacFormatService", which should have been removed by HJT last time you "Fixed" things, still appears.

Sorry also that you had trouble with NailFix - lets "Plan B" that, too - uninstall/delete the copy of NailFix you have, then download a new one from Here - pick either the zipped version, and extract it, or, mebbe a better idea, take the .exe version - whichever, download to a convenient-to-find folder; on your desktop is prolly fine, though we're gonna use this in safe mode, and you may not see a desktop folder in safe mode. A sub-folder within "My Documents", or within your Program file might be better-whatever, your call.

When you've downloaded a new NailFix, (and unzipped it, if necessary), boot to safe mode, locate and click "NailFix.exe", and when it has installed, click "Next" , then click "Run NailFix", and click "Finish". Your desktop and icons should disappear then reappear, and a command box window should open and then quickly close - all that is normal. It may or may not find Nail, but as I said, lets be sure. When it has completed (won't take very long), run a full clean-and-scan with Cleanup 4 - Cleanup 4, not CCleaner this time, then reboot back into safe mode.

Now, lets see if we can't get rid of those two non-existant services - from safe mode, and with no browsers or other windows open, run HJT, place a checkmark next to each of the following entries, if found:

O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)


Look over the scan report carefully, and if you see any other entries that are marked "(file missing)", check those as well, but please note and report back the exact, verbatim entry, if any do show up, then click "Fix Checked", and before rebooting, locate and launch CCleaner -CCleaner this time, not Cleanup 4, and select "Issues", scan, and allow it to"fix" all issues found, then select Cleaner, and run a full scan-and-clean with CCleaner, then reboot normally, immediately run a scan with HJT, fixing nothing, and post the log.

BTW - your log actually looks clean; this is just tidying up - I hope. I think you're prolly just about done.

Oh, and again, sorry you had trouble with NailFix - I've not had reports of the failure you experienced - thanks for that bit of feedback, too; something else I'll look into. Unless folks let me know what happens, I have no way of knowing about problems. Hearing about 'em helps a bunch.
0 Replies
 
WLW
 
  1  
Reply Sun 4 Sep, 2005 07:22 am
I'm glad I could help. Here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:14:38 AM, on 9/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\HJT\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Wayman L. Widgins\Application Data\Mozilla\Profiles\default\q0oxvv33.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] D:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=090705 serial=DR12CRP-2909658-QBC lang=EN
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPagePro11.0\opware32.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKLM\..\Run: [MacLicense] "C:\Program Files\Conversions Plus\MacLic.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1101239718\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: No-IP DUC.lnk = C:\Program Files\No-IP\DUC20.exe
O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe
O4 - Global Startup: Acrobat Assistant.lnk = D:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MacName.lnk = C:\Program Files\Conversions Plus\MacName.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/registration/3_0_0_804/sdcregie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {BE5431D2-0F30-11D4-89D9-00C04F509C0A} (SDCInstaller Class) - http://www.stamps.com/download/us/cab/stamps/stamps.cab?r=0.26698548657567&file=stamps.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by10fd.bay10.hotmail.msn.com/activex/HMAtchmt.ocx
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
0 Replies
 
WLW
 
  1  
Reply Sun 4 Sep, 2005 07:28 am
By the way that NAIL.EXE file still appears in the Prefetch folder. Can I just delete it?
0 Replies
 
timberlandko
 
  1  
Reply Sun 4 Sep, 2005 08:44 am
Your log is clean, but those two items, O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing) and
O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing) still show up.They're unlikely to really bother anything, but they're unnexessary, and its odd they apparently return after being "fixed" by HJT while in safe mode. Do they appear in the report when you run HJT from safe mode? I suggest you try one more time to remove them - first run HJT from safe mode, and click to fix them, then boot to normal mode, run HJT again, see if they are there, and if so, click to fix them again, reboot normally, run a scan-only with HJT, and see if they're still there. No need to post an entire log when you respond, just lemme know if those 2 entries are gone or not, if you would please.
0 Replies
 
WLW
 
  1  
Reply Sun 4 Sep, 2005 09:08 am
I think both of these items are necessary. Both of these services will be there as long as the associated software is installed on the system. I do use these programs from time to time, though not recently. I'm not sure why they show up with the note: file missing

O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
THIS IS A SERVICE THAT ALLOWS ME TO RUN MOVIE MAGIC SOFTWARE.

O23 - Service: MacFormatService - Unknown owner - C:\Program Files\Conversions Plus\FORMATM.EXE" /SERVICE (file missing)
THIS IS A SERVICE THAT ALLOWS ME TO FORMAT REMOVABLE MEDIA FOR USE ON A MAC COMPUTER.
0 Replies
 
timberlandko
 
  1  
Reply Sun 4 Sep, 2005 09:37 am
Yeah, I know what they're associated with, and I'm not at all concerned they're mailicious. Leave 'em be then ... as I said, they're not malicious. The files referenced as missing may mean the related software may not function correctly without repair or re-install, but that's remote. That out of the way, I'd say this one's resolved.

Go ahead and test things for a while - and of course stay absolutely current on all of your updates and make sure your security/privacy software is active and functioning properly. If after a brief period of normal use things seem to stay normal and you're satisfied all is as it should be, you can delete the tools you won't be using any more (they won't hurt anything, but they do take up some disk space) - though I strongly recommend keeping, using, and maintaining updates for Ad-Aware SE, CCleaner, and/or Cleanup, Microsoft Antispyware, Spybot S&D and SpywareBlaster.

When you're ready, run Cleanup one more time while in safe mode, then defrag your machine, re-enable System Restore, boot back into safe mode, and when the system has fully booted, set a fresh restore point. Reboot normally, Stay Safe Out There, and enjoy.
0 Replies
 
WLW
 
  1  
Reply Sun 4 Sep, 2005 11:17 am
I will work on that over the next day or so.

But, after the last reboot, I cannot seem to return my taskbar, etc to the Windows XP style. No matter what I try, it only uses the Classic style. Did what we've been doing remove that from the system? If so, how can I get it back?
0 Replies
 
timberlandko
 
  1  
Reply Sun 4 Sep, 2005 12:46 pm
That can happen with MS updates, and sometimes from installing/uninstalling programs, whether MS or 3rd-party. Its a pain, and its not at all uncommon. Sometimes, it cures itself after a few reboots or a new MS update, but that's not a very efficient fix. It might be that the Windows component "Themes" is not installed, check that in "Add/Remove Windows Components" in Add/Remove Programs - if its not installed, install it (you'll prolly need an XP install disc). Sometimes, the problem is simply that the "Themes" service is not running; you can check, and possibly fix, this, by going to Start>Control Panel> Administrative Tools> Services, and make sure "Themes" is turned on and set to Automatic. If its been stopped, just start it, and you should be able to access and change "Themes" in the normal fashion. Usually, however, that's too easy to actually be the solution, and you hafta do a bit more.

Most likely, the Windows file named "c:\Windows\Resources\Themes\Luna\luna.msstyles" (assuming "c: is your root drive - the drive on which Windows is installed) has become corrupt or even gone missing.

The easiest, surest fix I know of is to replace the file. Create a temporary directory on your c: drive (name it something like "Themefix", or anything else meaningful and memorable to you).

Grab any XP install disc, pop it in, don't let it "Autostart", just quit "Setup" if it starts. Now, go to Start>Run, and type, without the quotes, "cmd" (sometimes typing the whole word "command" works better), and click "OK" or hit "Enter".

A black-and-white Command window will open, with a blinking cursor following something like "C:\DOCUME~1\<yourusername>.

At the blinking cursor, type the letter of the optical drive in which you put the XP install disc followed by a colon (for example, D:, if your optical drive is drive "D"), and hit "Enter". That should change you into the directory of the install disc.

Next, at the cursor in the Command box, type in, without the quotes, "cd i386" (observe the lower-case "i" and the space between "cd" and "i386"), and hit "Enter". That should change you into the i386 directory.

At the i386 directory prompt, type, without the quotes, "expand luna.ms_ c:\<EXACTLY whatever you named the temporary folder created earler>, for example, "expand luna.ms_ c:\Themefix". Note the space following "expand" and "luna.ms_" and the space following the underscore (_) which is part of "luna.ms_", and "c:\ <whatever the target folder is named>", and hit "Enter". This should expand the file from the install disc's i386 folder into your target folder.

Open the target folder, and rename the "luna.ms_" file to "luna.msstyles". Double-click the renamed file, which should reset your appearance to XP style. If it does, copy the new file to your c:\windows\resources\themes\luna" folder, confirming overwrite if prompted, then reboot and you should be back to where you want to be.

A less-certain alternative, if you don't have an install disc handy, would be to copy the "luna.msstyles" folder from another, known-to-be-working-OK XP machine, and place the good copy into your c:\windows\resources\themes\luna" folder.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Aurora/ABI Network popup problem
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 12/28/2025 at 05:11:12