Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I posted a message earlier in the Security and Virus Forum - 16829. It was about a Blue desktop with a red Spyware logo. I received a very informative response and printed it out, but left it at work inadvertently. Now, I am unable to locate it on the board and am at home.
Can someone please point me in the right direction? I posted it this morning around 6:00 AM.
Thanks,Ann

If it's not there, it's not there. If your post contains HJT log it gets nicked at this site.
i_XpUser

ann05,
It has been deleted, removed. Don't ask me why, as I don't know why. I WASN'T the one that removed it, ok.
Justin and/or Kevin ect. should know the answer to the question.
You're Welcome,
CrazyOne

It's vanished!
There are various common reasons:
If it's a bit like hacking, cracking software codes and the like, then that's one good reason (ie getting software to run for free that you should pay for).
Rude postings sometimes get nuked too (but this doesn't sound like you).
In reality I've no idea why it's gone, so best bet is to repost bearing in mind the above, just in case it was misconstrued. Let's hope the respondee looks back or maybe someone else can help.
DerekW

Thanks. I sent in an unrequested HJT log. I did not realize that was against the rules. I'm sure it is stated, but I did not read them close enough. I know not to do that again!
Thanks,
Ann

Fine, but by all means post your problem. It's just that the place can get overwhelmed with stacks of logs - hence the rather large warning that pops up.
If HJT is the appropriate way forward then one of the helpers will ask you to post the log, but there are often other things to do first.
DerekW

Run this free online scan from Panda
If you think you have vundo or winfixer download SpySweeper from this link http://www.spywaredb.com/remove-win32-vundo-522752trojan/
Choose download SpySweeper from this line:
Delete Win32/Vundo.522752!Trojan automatically >>> Get PestPatrol or Download SpySweeper at the above link
Then download and run ccleaner to clean out all your temp files. Make sure there is not anything in the recycle bin that you need as ccleaner will delete recycle bin items unless checked not to do so..
Then download,update and run these spyware removal programs
Adaware SE and once you get it updated go back to the link and install the vx2 cleaner and follow the directions to install it the run it. This updated tool will remove most vx2 infections including Look2Me.
cwshredder use the stand alone version.
Purge System Restore by shutting it down and restarting it.
To create a new restore point go Start>Run>type "msconfig" without the quotes>ok>Launch System Restore>Tick the circle beside "create a restore point">next>name it anything you wish>Creast>home>restart the computer.
If that don't help You will most likely need to post a Hijack This log so that the files associated with the virus can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.
Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

I was making progress and able to get some of the programs run. It found and removed CoolWWWSearch. Well, after rebooting - even in safe mode - my mouse moves, but nothing I click on works. Is there something I can do if I reboot from the prompt to at least be able to use Windows in Safe Mode? I have Windows 2000. I've been trying rebooting.
Thanks,
Thanks,
Ann

Ann, Should have said this first, try choosing "last know configuration" from the advanced option screen as you boot into safe mode.

Thank you! Doing "last known good config" got me back in. That sure was frustrating not being able to try more things.
For future reference, does the xp link you sent work on either xp or 2000? I have Win 2000 on the computer I am having trouble with and XP on the one I am using now to correspond.
Logfile of HijackThis v1.99.1
Scan saved at 3:56:53 AM, on 10/27/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\WebProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\sysme.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\nvsvc32.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\WINNT\Explorer.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
D:\Program Files\Dell\Solution Center\service.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\Mixer.exe
C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\hphmon06.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\sdkqx32.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wral.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] d:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [DellSC] d:\Program Files\Dell\Solution Center\service.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [HPHUPD06] D:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINNT\system32\hphmon06.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [XTermInit] bhoserv.exe
O4 - HKLM\..\Run: [defect08] syspanel.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [sdkqx32.exe] C:\WINNT\sdkqx32.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124244789410
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://live.landsend.com/webline/applets/msie40x.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.indiansprings.org/activex/AxisCamControl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
O23 - Service: Panda Pavkre (Pavkre) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
O23 - Service: Panda PavProt (PavProt) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exePlease advise further.
Thanks,
Ann

It should work on 2000 and xp.
You still have two viruses. Close all windows,Scan with HT again and mark to delete these items:
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [XTermInit] bhoserv.exe
O4 - HKLM\..\Run: [defect08] syspanel.exe
O4 - HKLM\..\Run: [sdkqx32.exe] C:\WINNT\sdkqx32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe
Now press "fix checked".
Go to start control panel>folder options>view tab>check the circle beside "show hidden files and folders">Ok.
Navigate to and delete these files if found:
C:\WINNT\sdkqx32.exe
C:\WINNT\sysme.exe
Reboot and psot a new HT log.

When I rebooted my computer in safe mode, it locked up again. However, when I go into normal mode, I am able to maneuver about my Windows fine.
Is there something more I can do in the normal mode to remove some of the problem prior to rebooting in safe mode?
One thing I overlooked mentioning earlier is that Spy Sweeper would not install properly. I received a message that there was a problem with the installation. I did uninstall that before rebooting in safe mode since that was running on start up and I thought it might be causing my computer to hang.
Upon reboot, my computer shows in the bottom right-hand corner "Your computer might be at risk. Your virus protection status is bad. Spyware activity detected. Click this balloon to fix this problem." This is what was happening right before things got worse. I knew that was a message from a virus itself and did not click to go into it.
Also, if I go into desktop properties, it is greyed out the ability to change them.
Just thought those items may help you have a further understanding into my problems here.
Thanks for checking up on my postings!
Thanks,Ann

Launch Notepad, and copy/paste the box below(BETWEEN LINES ONLY) into a new text file. Save it as fixme.reg (make sure that Save as Type is set at "All Files") on your Desktop. Ensure there is no space at or above REGEDIT 4.
----------------
REGEDIT4[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=-
"System"=""
----------------
Next download KillboxRun Killbox.
Select "Delete on Reboot".
Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\WINNT\sdkqx32.exe
C:\WINNT\sysme.exe
Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
Click the red-and-white "Delete File" button.
Click "Yes" at the Delete on Reboot prompt.
Click "No" at the Pending Operations prompt.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, go Here to download and run missingfilesetup.exe.
Then try TheKillbox again
Reboot the computer,post a HT log.

Here is my new hjt log. Is the fixme.reg file supposed to be used just in case we need it?
I ran the killbox program and pasted in those 2 bad files. Then, I rebooted. When I tried to paste it in again, it didn't paste.
Logfile of HijackThis v1.99.1
Scan saved at 9:17:05 PM, on 10/27/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\WebProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\Explorer.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
D:\Program Files\Dell\Solution Center\service.exe
C:\WINNT\Mixer.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.exe
C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\hphmon06.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wral.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] d:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [DellSC] d:\Program Files\Dell\Solution Center\service.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [HPHUPD06] D:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINNT\system32\hphmon06.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [XTermInit] bhoserv.exe
O4 - HKLM\..\Run: [defect08] syspanel.exe
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [sdkqx32.exe] C:\WINNT\sdkqx32.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124244789410
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://live.landsend.com/webline/applets/msie40x.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.indiansprings.org/activex/AxisCamControl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
O23 - Service: Panda Pavkre (Pavkre) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
O23 - Service: Panda PavProt (PavProt) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeThanks,
Ann

Looks like you got one of them. Run an HT scan, close all windows except HT and check to select these(some again):
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [XTermInit] bhoserv.exe
O4 - HKLM\..\Run: [defect08] syspanel.exe
O4 - HKLM\..\Run: [sdkqx32.exe] C:\WINNT\sdkqx32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
Then press fix checked.
Use killbox to delete C:\WINNT\sdkqx32.exe.
Do a search for these and if found delete them with killbox but use the full patheg.C:\WINNT\syspanel.exe(example only)
syspanel.exe
bhoserv.exe
tcausti.exe
XTermInit.exe
defect08.exe
Run the registry fix in response #15.
Look in add/remove programs and uninstall Wareout if found.

I received a message saying that sdkqx32.exe could not be found when I went to delete it using killbox and search did not find the other files. I ran the fixreg file. When I tried to uninstall WareOut, it said it appeared to already be uninstalled and I selected to remove it from the list of programs.
When I rebooted, Panda showed the message Trj/DelCache.P C:\WINNT\system32\csphw.exe - virus found and file disinfected.
I have the dark blue screen in the background and options to change this are greyed out still. The black box in the middle says "Spyware Infection" in big red letters.
I have not tried to restart in safe mode again yet.
Please advise what to do next.
Thanks,
Ann

Ann, Use killbox to delete C:\WINNT\system32\csphw.exe then reboot and post another HT log making sure you did response #17.

Here is my hjt log. I believe I did all steps in 17. I did not find any of the files when I searched. Btw, Win Explorer used to crash when I searched and doesn't now so that's one big improvement. Also, when I rebooted, the blue screen still came up instead of my desktop picture and I can't change the desktop, but the red letters on black in the middle are gone.
Logfile of HijackThis v1.99.1
Scan saved at 10:42:59 PM, on 10/29/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\WebProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\nvsvc32.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
D:\Program Files\Dell\Solution Center\service.exe
C:\WINNT\Mixer.exe
C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\hphmon06.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wral.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] d:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [DellSC] d:\Program Files\Dell\Solution Center\service.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [HPHUPD06] D:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINNT\system32\hphmon06.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124244789410
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://live.landsend.com/webline/applets/msie40x.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.indiansprings.org/activex/AxisCamControl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
O23 - Service: Panda Pavkre (Pavkre) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
O23 - Service: Panda PavProt (PavProt) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeThanks,
Ann

Ann,Your Spysweeper and spybot real time protection may be part of the problem so do this:
Open Spysweeper and click on Options > Program Options and uncheck "load at windows startup".
On the left click "shields" and then uncheck everything there.
Uncheck "home page shield".
Uncheck "automatically restore default without notification".
Exit the program.
Then in spybot do this if you have tea timer running(Don't think you do):Run Spybot-S&D in Advanced Mode.
If it is not already set to do this Go to the Mode menu select "Advanced Mode"
On the left hand side, Click on Tools
Then click on the Resident Icon in the List
Uncheck "Resident TeaTimer" and OK any prompts.
Restart your computer.
In case the host file has been altered download http://www.funkytoad.com/hoster.htm to your desk top, open it and click "restore original host".
You have two items refering to Norton's System Works in the HT log, if it's your firewall don't worry about it, if not the two av's will conflict.Run Ht again check these items the press fix checked:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
O4 - HKLM\..\Run: [LoadQM] loadqm.exe (not needed)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (not needed)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
It is prabably running from a temp file so download http://www.ccleaner.com/ccdownload.asp and run it, remember that it deletes items in the recycle bin.
Click internet explorer on the desktop>tools>reset web settings.
Click a blank spot on the desktop>properties>desktop>customize desktop>web(if the is anything other than "my current home page" or something you put there>delete it by clicking on it once to highlight>delete.
Update ewido and run it then post the log it makes.
Post a new HT log.

My Spysweeper had an error on installation so I had uninstalled that. I used to have Norton AntiVirus 2001, but when I unsuccessfully attempted to update to Norton Systemworks 2005, I lost the Norton program. I think there may have been a conflict with all this mess going on. I was able to install the Norton program fine on my laptop which has XP.
I am able to connect to the Internet again! So, I was able to update ewido and run it. I also updated AdAware and ran it which resulted in only one critical error which I removed. For the ewido, should I go into the quarantine area and remove all the files?
The balloon popup messages are not happening anymore. The only problem I can directly see right now is that I still can't change my desktop. "My current home page" is the only thing that shows when I go into the area you stated on my desktop. On the background tab, all is grayed out except for an added background at the bottom titled "desktop" and has the IE icon by it.
I have not tried lately to see if I still lock up in safe mode.
My ewido:
ewido security suite - Scan report
+ Created on: 11:18:21 AM, 10/30/2005
+ Report-Checksum: 96726828+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP\CLSID -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP\CLSID\\ -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP\CurVer -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP.1 -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IETLBAss.DOMP.1\CLSID\\ -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
C:\!KillBox\sdkqx32.exe -> TrojanDownloader.Agent.td : Cleaned with backup
C:\!KillBox\sysme.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD6.tmp\SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\ICD7.tmp\SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C5YZ0T27\tvguide[1] -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Application Data\Administrator.HOME-B17WKABONA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XC4V9X4H\show[1].aspx -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Administrator.JP\Cookies\administrator@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\RECYCLER\NPROTECT\00000777.exe -> Spyware.FindSpy : Cleaned with backup
C:\RECYCLER\NPROTECT\00000778.exe -> Spyware.Msnagent : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.45:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.47:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.59:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.60:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.105:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.112:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.130:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.131:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.132:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.136:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.166:C:\RECYCLER\NPROTECT\00000823.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.49:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.53:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.71:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.106:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.113:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.130:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.131:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.132:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.136:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.166:C:\RECYCLER\NPROTECT\00000824.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.114:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.131:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.132:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.133:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.137:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.167:C:\RECYCLER\NPROTECT\00000825.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.114:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.131:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.132:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.133:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.137:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.167:C:\RECYCLER\NPROTECT\00000828.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.27:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.28:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.29:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.31:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.32:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.50:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.54:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.55:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.58:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.66:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.72:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.73:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.107:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.114:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.131:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.132:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.133:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.137:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.167:C:\RECYCLER\NPROTECT\00000830.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\WINNT\ARCADE.INI:zirxs -> TrojanDropper.Small.tn : Cleaned with backup
C:\WINNT\Ocean Sunset.bmp:qkygsx -> Trojan.Agent.bi : Cleaned with backup
C:\WINNT\system32:yfaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINNT\system32\fonts\pmmc32.exe -> Not-A-Virus.Tool.PsExec.123 : Cleaned with backup
C:\WINNT\system32\hclean32.exe -> Trojan.Qhost.dv : Cleaned with backup
C:\WINNT\winnt.bmp:fxvbc -> TrojanDownloader.Agent.bq : Cleaned with backup
::Report Endhjt:
Logfile of HijackThis v1.99.1
Scan saved at 11:49:42 AM, on 10/30/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\WebProxy.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\WINNT\System32\svchost.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\Explorer.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\WINNT\system32\regsvc.exe
D:\Program Files\Dell\Solution Center\service.exe
C:\WINNT\Mixer.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\hphmon06.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINNT\system32\stisvc.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\AlbumDB2.exe
C:\HJT\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wral.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Speed racer] C:\Program Files\Creative\PlayCenter\CTSRReg.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] d:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [DellSC] d:\Program Files\Dell\Solution Center\service.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [HPHUPD06] D:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINNT\system32\hphmon06.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1124244789410
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://live.landsend.com/webline/applets/msie40x.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam.indiansprings.org/activex/AxisCamControl.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EFAEF0E4-F044-4D57-9900-1C3FF18524C9} (AV Class) - http://www.pcpitstop.com/antivirus/PitPav.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINNT\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINNT\system32\hpboid.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
O23 - Service: Panda Pavkre (Pavkre) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
O23 - Service: Panda PavProt (PavProt) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv50.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Panda Preventium+ Service (PREVSRV) - Panda Software - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software Internacional - D:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeThanks,
Ann

Ann, You still need to remove this item with HT:
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
The 020 item is the damaged SpySweeper file, you should uninstall SpySweeper.
This should repair the desktop.Download and Save Cleandesktop to your computer from this link: http://www.thespykiller.co.uk/files/cleandesktop.exe and double click on the cleandesktop.exe
It will automatically extract to c:\desktopclean where it needs to be to run and will automatically run the cleandesktop.vbs script.If it doesn't open then go to c:\desktopclean and double click on the cleandesktop.vbs Do not run any other file from there please unless asked to.
If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.
If you get a message when you first run it "Cannot find script file "blah blah blah" then don't worry just double click the cleandesktop.vbs script again as you sometimes get that message when a script blocker blocks the script.
It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.
It will restart Explorer.
Once you have performed the big cleanup, each of the other Users on the System needs to be signed in to clean up their desktop and regain the right click.
Another vbs is included to do this. It is named Other Profiles Regfix.vbs
Have each User sign in and run Other Profiles Regfix.vbs.
Open C:\ (Go to Start – Run and type C: Press enter) and Open the c:\desktopclean folder. Double click on Other Profiles Regfix.vbs
Explorer will be ended and that user's active desktop registry entries will be repaired. Explorer will be restarted.
Compliments of Mosaic1 via Cookieagle hope it works for you.

Wow! Thanks. That desktop cleanup program worked great.
I can get in using Safe Mode now, too. I ran ewido and AdAware again in Safe Mode. Those are showing my files are clean.
I even tried to delete that hjt line:
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINNT\sysme.exe (file missing)
using safe mode, but it still stays. Is there another way I can remove it?
Regarding: The 020 item is the damaged SpySweeper file, you should uninstall SpySweeper.
I have uninstalled SpySweeper, but I guess it did not totally uninstall fine. There was an error when I was installing it so that probably has something to do with it. Should I try deleting that entry in hjt?
In ewido, should I delete all the items in quarantine?
My computer is working soooooooo much better now. I really appreciate all you have done to help me through all this over the past several days.
Thanks,
Ann

Sorry to intrude but I've been watching this post. I'd like to add my congrats to jabuck who has worked hard with you to fix this problem and won. Good luck with the minor outstanding tid bits both of you.
DerekW

Ann, On the 020 item just delete it with HT,my oversight on SpySweeper uninstall.As for the items in Ewido quarantine leave them for a few days the delete them if you have no probs.
Go to start>control panel>administrative tools>services>Scroll down to "Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner" and double click it>in the properties box click the drop down arrow on right side of "startup type" and click disabled>apply>ok.Then see if you can remove it with HT.

I was able to remove the #20 entry in hjt. After I disabled the Network Security Service pointing to sysme.exe, it no longer shows up in hjt. Do I leave it this way then? At the end of the path, it also had a "/s". When I clicked on it to disable, I received an internal error message, but was still able to go in and make the change to disable it.
Derek, I could not agree with you more about jabuck's assistance with all these issues. I have been extremely impressed with all jabuck's technical expertise with removing spyware and the dedication shown.
Thanks,
Ann

Ann, After having problems like this it is best to purge system restore and create a new restore point.
Purge System Restore by shutting it down and restarting it.
To create a new restore point go Start>Run>type "msconfig" without the quotes>ok>Launch System Restore>Tick the circle beside "create a restore point">next>name it anything you wish>Create>home>restart the computer.

![]() |
addicticting games
|
Do I have a virus
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |