View Single Post
Old 08-23-2005, 03:35 AM   #3 (permalink)
Spoonie
Registered User
 
Join Date: Aug 2005
Posts: 13
OS: Win/XP


Fresh Logs

Here's the fresh logs. As you can see, "Abc" is still bothering me. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 12:36:48 AM, on 8/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\windows\eixcvha.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abcsearch4u.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKCU\..\Run: [kmjghck] c:\windows\ehxwpcs.exe
O4 - HKCU\..\Run: [mudcwfa] c:\windows\ehxwpcs.exe
O4 - HKCU\..\Run: [oupsxwh] c:\windows\ehxwpcs.exe
O4 - HKCU\..\Run: [njsivxm] c:\windows\ehxwpcs.exe
O4 - HKCU\..\Run: [plspbqq] c:\windows\ehxwpcs.exe
O4 - HKCU\..\Run: [rxlhdxq] c:\windows\hjaxsbi.exe
O4 - HKCU\..\Run: [jyoloii] c:\windows\hjaxsbi.exe
O4 - HKCU\..\Run: [ngcsdgs] c:\windows\rumxygq.exe
O4 - HKCU\..\Run: [vvpspak] c:\windows\rumxygq.exe
O4 - HKCU\..\Run: [jddelcp] c:\windows\rsfofrr.exe
O4 - HKCU\..\Run: [kunppfw] c:\windows\jtbbphw.exe
O4 - HKCU\..\Run: [vpcnsen] c:\windows\cctvvxs.exe
O4 - HKCU\..\Run: [fogpowx] c:\windows\frdrlrw.exe
O4 - HKCU\..\Run: [bmdwtrl] c:\windows\kthtjmy.exe
O4 - HKCU\..\Run: [wgcpfaw] c:\windows\kthtjmy.exe
O4 - HKCU\..\Run: [xcuesgb] c:\windows\smcclrh.exe
O4 - HKCU\..\Run: [rmcjiid] c:\windows\smcclrh.exe
O4 - HKCU\..\Run: [vyeoexn] c:\windows\jqptcvc.exe
O4 - HKCU\..\Run: [aqkpcxd] c:\windows\wxcxmeo.exe
O4 - HKCU\..\Run: [ychrvmi] c:\windows\jqptcvc.exe
O4 - HKCU\..\Run: [eqeghbv] c:\windows\wxcxmeo.exe
O4 - HKCU\..\Run: [affijos] c:\windows\cotgdqx.exe
O4 - HKCU\..\Run: [lniltrg] c:\windows\cotgdqx.exe
O4 - HKCU\..\Run: [flqiyte] c:\windows\kvqfbsp.exe
O4 - HKCU\..\Run: [sssqsot] c:\windows\kvqfbsp.exe
O4 - HKCU\..\Run: [wscrpvw] c:\windows\kvqfbsp.exe
O4 - HKCU\..\Run: [qxqgpkq] c:\windows\crvhvod.exe
O4 - HKCU\..\Run: [meuemcx] c:\windows\ryjodny.exe
O4 - HKCU\..\Run: [prhsihs] c:\windows\ryjodny.exe
O4 - HKCU\..\Run: [ydmhyuo] c:\windows\heshvsh.exe
O4 - HKCU\..\Run: [noaapiw] c:\windows\sfbimkg.exe
O4 - HKCU\..\Run: [kqdcmrv] c:\windows\sfbimkg.exe
O4 - HKCU\..\Run: [bllwney] c:\windows\sfbimkg.exe
O4 - HKCU\..\Run: [xdfkqwf] c:\windows\iusuknl.exe
O4 - HKCU\..\Run: [jkdpmwe] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [vnlohmb] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [ahusrth] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [ufslyur] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [jfprcsj] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [hkagimf] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [tiyjowl] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [pfkqdpm] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [jekqtxx] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [lbsngkk] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [bxvvgae] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [vcydumn] c:\windows\xyhdwko.exe
O4 - HKCU\..\Run: [cprdfws] c:\windows\tuhdsjx.exe
O4 - HKCU\..\Run: [qjtwblu] c:\windows\ertkloh.exe
O4 - HKCU\..\Run: [adhrbtm] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [uyxtbxi] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [gsutcyh] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [iyxraqv] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [ephvflp] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [erpouxk] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [gsdgbea] c:\windows\dyakflu.exe
O4 - HKCU\..\Run: [vhxdtmh] c:\windows\jyquhjm.exe
O4 - HKCU\..\Run: [guyxqga] c:\windows\jyquhjm.exe
O4 - HKCU\..\Run: [yarybsq] c:\windows\cdhipuc.exe
O4 - HKCU\..\Run: [lwrpujk] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [ihhqkvh] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [vluywwk] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [bxhmoaq] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [pgwmbyi] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [ijnquan] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [aynhspq] c:\windows\uttfmci.exe
O4 - HKCU\..\Run: [ttrgqlb] c:\windows\apgcqaw.exe
O4 - HKCU\..\Run: [vrubjcy] c:\windows\wtotqmx.exe
O4 - HKCU\..\Run: [kqqfxnk] c:\windows\wtotqmx.exe
O4 - HKCU\..\Run: [pliomry] c:\windows\wtotqmx.exe
O4 - HKCU\..\Run: [lepfmln] c:\windows\wtotqmx.exe
O4 - HKCU\..\Run: [temvoco] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [smydscn] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [vwxfdwv] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [drpjvij] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [sjcmrps] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [irnyxfi] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [jktnsdp] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [kqwdywc] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [fplufjn] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [fbqrdtq] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [ftdsveg] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [trqghky] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [rvbasgf] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [hxdfyll] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [mguttov] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [smxkdwr] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [xiynner] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [aeeycoj] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [gektqbp] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [oiripjt] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [lvxvylk] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [uioutex] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [avyuwrv] c:\windows\gheaqxi.exe
O4 - HKCU\..\Run: [ojxyyqd] c:\windows\uhpejci.exe
O4 - HKCU\..\Run: [wivpivr] c:\windows\uhpejci.exe
O4 - HKCU\..\Run: [hflbpns] c:\windows\uhpejci.exe
O4 - HKCU\..\Run: [osjkakv] c:\windows\uhpejci.exe
O4 - HKCU\..\Run: [nbxvfvf] c:\windows\rjjgmin.exe
O4 - HKCU\..\Run: [peswypq] c:\windows\rjjgmin.exe
O4 - HKCU\..\Run: [cnjnstf] c:\windows\rjjgmin.exe
O4 - HKCU\..\Run: [idhpwbv] c:\windows\rjjgmin.exe
O4 - HKCU\..\Run: [nqoevns] c:\windows\eixcvha.exe
O4 - HKCU\..\Run: [mbhpecc] c:\windows\eixcvha.exe
O4 - HKCU\..\Run: [mmofckl] c:\windows\eixcvha.exe
O4 - HKCU\..\Run: [awrvxxg] c:\windows\pwaxvnk.exe
O4 - HKCU\..\Run: [gemnyvx] c:\windows\pwaxvnk.exe
O4 - HKCU\..\Run: [rtqtnhj] c:\windows\wwyojgq.exe
O4 - HKCU\..\Run: [kuxmqbs] c:\windows\vpvanpj.exe
O4 - HKCU\..\Run: [yjchmgf] c:\windows\vpvanpj.exe
O4 - HKCU\..\Run: [trtbvde] c:\windows\vblgmvc.exe
O4 - HKCU\..\Run: [ccnvnck] c:\windows\vblgmvc.exe
O4 - HKCU\..\Run: [maesnfw] c:\windows\ohrlccd.exe
O4 - HKCU\..\Run: [yepqtef] c:\windows\ccxskyk.exe
O4 - HKCU\..\Run: [ctnoxnt] c:\windows\ccxskyk.exe
O4 - HKCU\..\Run: [biyttql] c:\windows\ccxskyk.exe
O4 - HKCU\..\Run: [uflbipx] c:\windows\ccxskyk.exe
O4 - HKCU\..\Run: [edxkven] c:\windows\ccxskyk.exe
O4 - HKCU\..\Run: [lpernbx] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [kusntmr] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [ylosaxx] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [vvutonp] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [rfbtlhl] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [csgxfof] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [nqsooqm] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [sgdlquk] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [dbkmgrw] c:\windows\ytqpolh.exe
O4 - HKCU\..\Run: [yubfgom] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [jigtpua] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [nwhyrdw] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [lkvmyvf] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [rcvboew] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [ravokft] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [nkkvwcr] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [hfxtxjp] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [nkigohe] c:\windows\rjgpjsa.exe
O4 - HKCU\..\Run: [ncilvci] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [jbihyij] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [khxaojc] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [occamjm] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [ujheakm] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [hmrlsfh] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [llsajew] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [mwlvxjj] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [biseeyl] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [ndgnpfe] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [ppasohg] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [wfvwhka] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [civnrsx] c:\windows\krftghp.exe
O4 - HKCU\..\Run: [afomidc] c:\windows\spcvoec.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1122623011640
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole...rcadeRdxIE.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D8A8A7F1-53EF-41F2-B44D-F3E2E595DC27} - ms-its:mhtml:file://C:\MAIN.MHT!http://69.50.172.102/355//strpg.chm::/update.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Intuit Fuse Service - Intuit - C:\Program Files\Common Files\Intuit\Fuse\Service\Intuit Fuse Service.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Panda Online Scan

Incident Status Location

Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\SPCVOEC.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\KRFTGHP.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\RJGPJSA.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\YTQPOLH.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\CCXSKYK.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\OHRLCCD.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\VBLGMVC.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\VPVANPJ.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\WWYOJGQ.EXE
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\PWAXVNK.EXE
Adware:Adware/Startpage.WH No disinfected C:\windows\eixcvha.exe
Adware:adware/findspy No disinfected C:\DOCUMENTS AND SETTINGS\YAM\FAVORITES\ FREE Access to 800 Paid sites.url
Adware:adware/topsearch4u No disinfected Windows Registry
Possible Virus. No disinfected C:\Program Files\2Wire\sy_apps\dllupdate.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\bludtba.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\bsebvfx.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\ccxskyk.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\eixcvha.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\fyntatb.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\krftghp.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\neiykrn.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\nmawyda.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\ohrlccd.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\pulqfcf.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\pwaxvnk.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\rjgpjsa.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\spcvoec.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\SYSTEM32\arusxaaa.exe
Adware:Adware/StartPage.AFK No disinfected C:\WINDOWS\SYSTEM32\shdocvn.dll
Possible Virus. No disinfected C:\WINDOWS\temp\ASHeuristic\dllupdate.exe.vir
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\tpuebwr.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\vblgmvc.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\vpvanpj.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\wwyojgq.exe
Adware:Adware/Startpage.WH No disinfected C:\WINDOWS\ytqpolh.exe


Antispyware.Log
Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Internet URL Shortcuts
Found ' Free Spy Cam - Realtime.url' in 'C:\Documents and Settings\Yam\Favorites\'
Found ' FREE Access to 800 Paid sites.url' in 'C:\Documents and Settings\Yam\Favorites\'
Files and Directories
Finished Scanning
Started Backup
Finished Backup
Started Cleaning
Finished Cleaning


AB Log
Scanned at: 1:17:49 AM on: 8/23/2005

-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 31

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!

-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 31

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 2:18:29 AM, 8/23/2005
+ Report-Checksum: EC8473B8

+ Scan result:

No infected objects found.


::Report End


smitRem log file
version 2.3

by noahdfear

The current date is: Tue 08/23/2005
The current time is: 1:20:17.18

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Wininet.dll ~~~

CLEAN! :)

Last edited by Spoonie; 08-23-2005 at 03:38 AM.
Spoonie is offline