This thread's last reply is from January 5, 2006, 4:53 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Recently I removed this virus using Microsoft Antivirus. Now when I reboot I get a message about kernels64.exe missing. Also my Windows Explorer continually sends an error message back to the mothership at Microsoft. Below is my notepad:
Logfile of HijackThis v1.99.1
Scan saved at 8:37:20 AM, on 12/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\alt.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Tardis95.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchtraffic.com/search.php3?l=protect1&term=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.srh.noaa.gov/ifps/MapClick.php?site=EWX&llon=-98.909583&rlon=-98.027083&tlat=29.880417&blat=28.997917&smap=1&mp=1&map.x=68&map.y=63
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchtraffic.com/search.php3?l=protect1&term=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\kernels64.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.msnbc.msn.com/"); (C:\Documents and Settings\Craig Allen\Application Data\Mozilla\Profiles\default\2bhohxal.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Craig Allen\Application Data\Mozilla\Profiles\default\2bhohxal.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: C:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - C:\WINDOWS\adsldpbf.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {8B224779-3B0E-4FEA-8AE1-B66C20DD840F} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [AlexaToolbar] C:\WINDOWS\alt.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Tardis95.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132747439284
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp.cab
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
O16 - DPF: {E0051273-5988-41EC-A891-11D4A1BABF35} (KDreg class) - http://193.242.125.31/player/kdreg.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A312C3A-80A0-4CC5-818C-2233FFDAA992}: NameServer = 85.255.113.130,85.255.112.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1600FA7-729C-414B-B226-E11309F241FC}: NameServer = 85.255.113.130,85.255.112.67
O18 - Protocol: bw+0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {A676C3BD-457D-4267-A5C7-602A5B13DBC6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello creepers,
Thanks for the information about Tardis95.exe.
Ok, here we go - lot's to do on the PC ...
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Disable Microsoft AntiSpyware, it will interfer with the fix.
- Open Microsoft AntiSpyware.
- Click on Options, Settings.
- In the left pane, click on Real-time Protection.
- Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
- Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
- After you unchecked these, click on the Save button and close Microsoft AntiSpyware.
- Right click on the Microsoft AntiSpyware Icon on the taskbar and select Shutdown Microsoft AntiSpyware.
______________________________
Make sure that you can see hidden files.
- Click Start.
- Click My Computer.
- Select the Tools menu and click Folder Options.
- Select the View Tab.
- Under the Hidden files and folders heading select Show hidden files and folders.
- Uncheck the Hide protected operating system files (recommended) option.
- Click Yes to confirm.
- Uncheck the Hide file extensions for known file types.
- Click OK.
______________________________
Copy/paste the following text into a new Notepad document. Make sure that you have one blank line at the end of the document as shown in the quoted text.
REGEDIT4
[HKEY_CURRENT_USER\\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{31EE3286-D785-4E3F-95FC-51D00FDABC01}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31EE3286-D785-4E3F-95FC-51D00FDABC01}]
Save it to your desktop as
Fixme.reg. Save it as :
File Type: All Files (not as a text document or it wont work).
Name: Fixme.reg
Locate
Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click
YES. Wait for the
merged successfully prompt.
______________________________
Run HijackThis, click on
None of the above, just start the program, click on
Scan. Put a
check in the box on the left side of the following items if still present:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A312C3A-80A0-4CC5-818C-2233FFDAA992}: NameServer = 85.255.113.130,85.255.112.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1600FA7-729C-414B-B226-E11309F241FC}: NameServer = 85.255.113.130,85.255.112.67
Close
ALL windows and browsers
except HijackThis and click
Fix Checked
______________________________
Reset your DNS servers
- Click Start, click Control Panel, click Network and Internet Connections, and then click Network Connections.
- Right-click the network connection that you want to configure, and then click Properties.
- On the General tab (for a local area connection), or the Networking tab (for all other connections), click Internet Protocol (TCP/IP), and then click Properties.
- If you want to obtain DNS server addresses from a DHCP server, click Obtain DNS server address automatically. (Recommended)
- If you want to manually configure DNS server addresses, click Use the following DNS server addresses, and then type the preferred DNS server and alternate DNS server IP addresses in the Preferred DNS server and Alternate DNS server boxes.
Reboot your PC
______________________________
Please download FixWareout from
http://swandog46.geekstogo.com/Fixwareout.exe
Note: Leave your internet connection running, the fixwareout may prompt you to download BFU from merijn.
Save it to your Desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, HijackThis will launch.
Put a
check in the box on the left side of the following items if still present:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\kernels64.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A312C3A-80A0-4CC5-818C-2233FFDAA992}: NameServer = 85.255.113.130,85.255.112.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1600FA7-729C-414B-B226-E11309F241FC}: NameServer = 85.255.113.130,85.255.112.67
Close
ALL windows and browsers
except HijackThis and click
Fix Checked
At the end of the fix, you may need to restart your computer again. A log will be created,
C:\fixwareout\report.txt, I will need that file later on.
If present, delete the folder C:\Program Files\WareOut
______________________________
Download win32delfkil.exe from:
http://users.telenet.be/marcvn/tools/win32delfkil.exe.
Save it on your desktop. Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil
Close all windows, open the win32delfkil folder and double click on
fix.bat.
The computer should reboot automatically, if not you'll need to
reboot the computer manually, by turning the power off and then back on.
It will create a log named
c:\windelf.txt, I will need that later on.
______________________________
Download Registry Search by Bobbi Flekman
http://www.bleepingcomputer.com/files/regsearch.php
Create a folder named C:\Reg for it and unzip into that folder.
______________________________
Please download SmitRem.exe by noahdfear to your Desktop.
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
Double-click the
smitRem.exe and it will extract the files to a smitRem folder on your Desktop.
______________________________
Please download the trial version of Ewido Security Suite 3.5 from here:
http://www.ewido.net/en/download/
- Install Ewido Security Suite.
- When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
- When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
- The program will prompt you to update. Click the Ok button.
- The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
- On the left-hand side of the main screen click the Update Button.
- Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido.
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________
If you already have the latest Ad-Aware SE 1.06 version, skip to
Run Ad-Aware. Otherwise download Ad-Aware SE 1.06 from
here and install it. Uncheck all the options before leaving the Install Wizard.
Run Ad-Aware and Click on the
World Icon. Click the
Connect button on the webupdate screen. If an update is available download it and install it. Click the
Finish button to go back to the main screen.
Click on the
Gear Icon (second from the left at the top of the window) to access the Configuration Window.
Click on the
General Button on the left and select in
green
- Under Safety
- Automatically save log-file
- Automatically quarantine objects prior to removal
- Safe Mode (always request confirmation)
- Under Definitions
- Prompt to udate outdated definitions - set to 7 days
Click on the
Scanning Button of the left and select in
green
- Under Driver, Folders & Files
- Under Select drives & folders to scan
- Under Memory & Registry
- Scan Active Processes
- Scan Registry
- Deep Scan Registry
- Scan my IE favorites for banned URL’s
- Scan my Hosts file
Click on the
Advanced Button on the left and select in
green
- Under Shell Integration
- Move deleted files to Recycle Bin
- Under Logfile Detail Level
- Include addtional object information
- DESELECT - Include negligible objects information (make it show a red X)
- Include environment information
- Under Alternate Data Streams
- Don't log streams smaller than 0 bytes
- Don't log ADS with the following names: CA_INOCULATEIT
Click the
Tweak Button and select in
green
- Under the Scanning Engine (Click on the + sign to expand)
- DESELECT Unload recognized processes & modules during scan (make it show a red X)
- Scan registry for all users instead of current user only
- Under the Cleaning Engine (Click on the + sign to expand)
- Always try to unload modules before deletion
- During Removal, unload Explorer and IE if necessary
- Let Windows remove files in use at next reboot
- Under the Log Files (Click on the + sign to expand)
- Include basic Ad-aware SE settings in logfile
- Include additional Ad-aware SE settings in logfile
- Include reference summarry in log file
- Include alternate data stream details in log file
Click on
Proceed to save the settings and close the program.
______________________________
If not already installed, download and install the
VX2 Cleaner 2.0 plugin from Lavasoft by following the instructions below.
Installing VX2 Cleaner 2.0
- Close Ad-Aware, if it is currently open.
- Download the VX2 Cleaner 2.0 Plug-in here.
- Install the VX2 Cleaner by clicking on vx2cleaner_inst.exe.
______________________________
If Spybot - S&D 1.4 is already installed on your system, skip to
Update Spybot - S&D before using it. Otherwise download Spybot - S&D from the following link:
Spybot - Search and Destroy
When you have downloaded the program, double click on the downloaded file to start the installation. Follow the default selections, pressing the Next button until you get to the
Select Additional Tasks screen.
Under
Permanent protection, make sure to
uncheck the following items for now:
- Use Internet Explorer Protection
- Use system settings Protection (TeaTimer)
Press the Next button and then the Install button to start the installation process. When the installation process is complete, make sure that
Run Teatimer is
unchecked.
Launch Spybot - S&D
If you told Spybot to launch when it was done installing, the program should now be open. Otherwise find the icon on your desktop and double-click on it. When you use Spybot - S&D for the first time, it will prompt you for certain tasks to complete. Skip all tasks for now by pressing the
Next button. Click on the button labeled
Start using this program to begin using Spybot - Search & Destroy.
Update Spybot - S&D before using it
Click on the
Search for Updates button. If there are available updates, they will be listed. Click on the
Download Updates button and Spybot - S&D will download the updates and install them.
______________________________
MySearch comes with WeatherBug, it's is questionable and mostly identified as adware bordering on spyware..
Alternatives and more info here:
WeatherBug Removal Instructions and Help
http://www.pchell.com/support/weatherbug.shtml
A good read on weatherbug here :
http://www.searchlores.org/weatherbug.htm
May I suggest you remove this application.
In order to avoid future problems with Weatherbug, make sure the program is not running before uninstalling it. If there is a WeatherBug icon in the system tray (in the lower right hand corner of the screen) you'll need to right-click on it and choose "Exit WeatherBug" or "Terminate Weatherbug".
Click on
Start,
Control Panel, click on
Add/Remove Programs
Look through the installed programs for the following items and remove them if present:
Logitech Desktop Manager
WeatherBug
My Search
During the uninstall process, you might be presented with several prompts to guide you through uninstalling the product. Read these carefully to make sure you are actually choosing to uninstall rather than keep the software.
______________________________
Reboot your computer in
Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
______________________________
Double-click the icon for
RegSearch.exe in the C:\reg folder to launch the program.
Enter
contextplus to search for and click "OK".
After completion Notepad will be opened with all the found instances of the string.
The resulting file is saved in the same folder location as RegSearch.exe. I will need that file later on.
______________________________
Run HijackThis, click on
None of the above, just start the program, click on
Scan. Put a
check in the box on the left side of the following items if still present.
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchtraffic.com/search.php3?l=protect1&term=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchtraffic.com/search.php3?l=protect1&term=
R3 - Default URLSearchHook is missing
O2 - BHO: C:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - C:\WINDOWS\adsldpbf.dll
O3 - Toolbar: (no name) - {8B224779-3B0E-4FEA-8AE1-B66C20DD840F} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [AlexaToolbar] C:\WINDOWS\alt.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp.cab
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
O16 - DPF: {E0051273-5988-41EC-A891-11D4A1BABF35} (KDreg class) - http://193.242.125.31/player/kdreg.cab
All O18 lines with \Logitech\Desktop Messenger
O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
Close
ALL windows and browsers
except HijackThis and click
Fix Checked.
______________________________
Open the smitRem Folder, then double-click the
RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named
smitfiles.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Using
Windows Explorer,
Search and
Delete these
Folders if listed:
C:\Program Files\Logitech\
DesktopMessenger
C:\Program Files\
AWS
C:\Program Files\
mysearch
C:\Program Files\
WareOut <--- if not yet done
Using
Windows Explorer,
Search and
Delete these
Files if listed:
C:\WINDOWS\
adsldpbf.dll
C:\WINDOWS\
alt.exe
C:\WINDOWS\system32\
kernels64.exe
C:\WINDOWS\system32\
idemlog.exe
C:\WINDOWS\system32\
browsela.dll
If you get an error when deleting a file,
right click on the file and check to see if the
read only attribute is checked. If it is
uncheck it and try again.
______________________________
Navigate to
C:\Windows\Prefetch
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Navigate to
C:\Windows\Temp
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Navigate to
C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Clean out your
Temporary Internet files. Procede like this:
- Quit Internet Explorer and quit any instances of Windows Explorer.
- Click Start, click Control Panel, and then double-click Internet Options.
- On the General tab, click Delete Files under Temporary Internet Files.
- In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
- On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
- Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
- Click OK.
Next Click
Start, click
Control Panel and then double-click
Display. Click on the
Desktop tab, then click the
Customize Desktop button. Click on the
Web tab. Under
Web Pages you should see an checked entry called
Security info or something similar. If it is there, select that entry and click the
Delete button. Click
Ok then
Apply and
Ok.
Empty the Recycle Bin by right-clicking the
Recycle Bin icon on your Desktop, and then clicking
Empty Recycle Bin.
______________________________
Close
ALL open Windows / Programs / Folders. Please start
Ewido Security Suite, and run a full scan.
- Click on Scanner
- Click on Settings
- Under How to scan all boxes should be checked
- Under Unwanted Software all boxes should be checked
- Under What to scan select Scan every file
- Click on Ok
- Click on Complete System Scan to start the scan process.
- Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says
Perform action on all infections, then choose clean and click Ok.
Once the scan has completed, there will be a button located on the bottom of the screen named
Save Report.
- Click Save Report button
- Save the report to your Desktop
Close Ewido.
______________________________
Start Ad-Aware SE
- Click on Add-ons
- Select the VX2 Cleaner plug-in and click Run Tool
- If your computer isn’t infected, click Close.
OR - If you computer is infected with VX2, a dialog box with text such as New VX2 variant found or VX2 variant 1 found will appear.
- Press Clean and a dialog box with text The first phase completed. Please reboot and perform a Smart Scan will appear.
- Reboot your computer
- Run Ad-Aware and Click on the Scan Now Button
- Choose Perform Full System Scan
- DESELECT Search for negligible risk entries, as negligible risk entries (MRU's) are not considered to be a threat. (make it show a red X)
Click Next to begin the scan. When the scan is completed, the Performing System Scan screen will change name to Scan Complete.
Click the Next Button to get to the Scanning Results Window where more information about the objects detected during the scan is available. Click the Critical Objects Tab. In general all of the items listed will be bad. To fix all the bad critical objects, right click on one of them, click the Select All entry in the pop-up menu to mark all entries. Click Next and then OK in the dialog box to confirm the removal.
Repeat this until the VX2 Cleaner reports
System clean. Press
Close to exit.
Run Ad-Aware one more time and perform a
Perform Full System Scan of your computer to make sure VX2 has been found and removed. Reboot in
Normal Mode
______________________________
Run Spybot - S&D
Click the button
Check for Problems
When Spybot is complete, it will be showing
RED entries,
BLACK entries and
GREEN entries in the window.
Make sure that there is a check mark beside all of the
RED entries
ONLY.
Choose
Fix Selected Problems and allow Spybot to fix the
RED entries.
If it has trouble removing any spyware, you will get a message window, asking if it would be ok to run Spybot - S&D on the next reboot before any other applications start running. You should reply
Yes to this. The next time you start Windows, Spybot will run automatically and fix any of the programs it could not fix previously.
At this point you will be presented with the list of found entries again, but now there will be large green checkmarks next to the items that Spybot - S&D was able to remove. The ones that are still checked but do not have the large green checkmark next to them will be fixed on the next reboot of windows. Reboot the PC.
______________________________
Please do an online scan with
Kaspersky Online Scanner
Click on
Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click
Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (If available otherwise Standard)
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK
- Now under select a target to scan select My Computer
- The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
- Copy and paste that information in your next post.
______________________________
Download WinPFind.zip to your Desktop or to your usual Download Folder.
http://www.bleepingcomputer.com/files/winpfind.php
Extract it to your
C:\ folder. This will create a folder called
WinPFind in the C:\ folder.
Open the
C:\WinPFind folder and double-click on
WinPFind.exe.
Click on
Configure Scan Options.
Remove all the checkmarks under
Folder Options on the left side by clicking the button
Remove All, uncheck
Run Addon's and click
Apply.
Click on the
Start Scan button and wait for it to finish.
Please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log file named
C:\WinPFind\WinPFind.txt. Please copy that log into your next reply.
______________________________
Please post :
- C:\fixwareout\report.txt
- c:\windelf.txt
- The results from the RegSearch.exe
- smitfiles.txt
- Ewido log
- Kaspersky results
- C:\WinPFind\WinPFind.txt
- a new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Kim
2.
Volume in drive C is DRV1_VOL1
Volume Serial Number is 91B2-3A40
Directory of C:\WINDOWS
08/04/2004 01:56 AM 146,432 regedit.exe
09/18/2004 11:22 PM <DIR> RegisteredPackages
07/10/2004 10:19 PM <DIR> Registration
07/13/2004 06:45 PM 8,192 REGLOCS.OLD
07/10/2004 05:09 PM 1,052 regopt.log
3 File(s) 155,676 bytes
Directory of C:\WINDOWS\$MSI31Uninstall_KB893803$
04/15/2005 02:00 AM 8,192 reg00012
04/15/2005 02:00 AM 8,192 reg00013
04/15/2005 02:00 AM 8,192 reg00014
04/15/2005 02:00 AM 8,192 reg00015
04/15/2005 02:00 AM 8,192 reg00016
04/15/2005 02:00 AM 8,192 reg00017
04/15/2005 02:00 AM 8,192 reg00018
04/15/2005 02:00 AM 8,192 reg00019
04/15/2005 02:00 AM 8,192 reg00020
04/15/2005 02:00 AM 8,192 reg00021
04/15/2005 02:00 AM 8,192 reg00022
04/15/2005 02:00 AM 8,192 reg00023
04/15/2005 02:00 AM 8,192 reg00024
04/15/2005 02:00 AM 8,192 reg00025
04/15/2005 02:00 AM 8,192 reg00026
04/15/2005 02:00 AM 8,192 reg00027
04/15/2005 02:00 AM 8,192 reg00028
04/15/2005 02:00 AM 8,192 reg00029
04/15/2005 02:00 AM 8,192 reg00030
04/15/2005 02:00 AM 8,192 reg00031
04/15/2005 02:00 AM 8,192 reg00032
04/15/2005 02:00 AM 8,192 reg00033
04/15/2005 02:00 AM 8,192 reg00034
04/15/2005 02:00 AM 8,192 reg00035
04/15/2005 02:00 AM 8,192 reg00036
04/15/2005 02:00 AM 8,192 reg00037
04/15/2005 02:00 AM 8,192 reg00038
04/15/2005 02:00 AM 8,192 reg00039
04/15/2005 02:00 AM 8,192 reg00040
04/15/2005 02:00 AM 8,192 reg00041
04/15/2005 02:00 AM 8,192 reg00042
04/15/2005 02:00 AM 8,192 reg00043
04/15/2005 02:00 AM 8,192 reg00044
04/15/2005 02:00 AM 8,192 reg00045
04/15/2005 02:00 AM 8,192 reg00046
04/15/2005 02:00 AM 8,192 reg00047
04/15/2005 02:00 AM 8,192 reg00050
04/15/2005 02:00 AM 8,192 reg00051
04/15/2005 02:00 AM 8,192 reg00052
04/15/2005 02:00 AM 8,192 reg00053
04/15/2005 02:00 AM 8,192 reg00054
04/15/2005 02:00 AM 8,192 reg00055
04/15/2005 02:00 AM 8,192 reg00056
04/15/2005 02:00 AM 8,192 reg00057
04/15/2005 02:00 AM 8,192 reg00058
04/15/2005 02:00 AM 8,192 reg00059
04/15/2005 02:00 AM 8,192 reg00060
04/15/2005 02:00 AM 8,192 reg00061
04/15/2005 02:00 AM 8,192 reg00062
04/15/2005 02:00 AM 8,192 reg00063
04/15/2005 02:00 AM 8,192 reg00064
04/15/2005 02:00 AM 8,192 reg00065
04/15/2005 02:00 AM 8,192 reg00066
04/15/2005 02:00 AM 8,192 reg00067
04/15/2005 02:00 AM 8,192 reg00068
04/15/2005 02:00 AM 8,192 reg00069
04/15/2005 02:00 AM 8,192 reg00070
04/15/2005 02:00 AM 8,192 reg00071
04/15/2005 02:00 AM 8,192 reg00072
04/15/2005 02:00 AM 8,192 reg00073
04/15/2005 02:00 AM 8,192 reg00074
04/15/2005 02:00 AM 8,192 reg00075
04/15/2005 02:00 AM 8,192 reg00076
04/15/2005 02:00 AM 8,192 reg00077
04/15/2005 02:00 AM 8,192 reg00078
04/15/2005 02:00 AM 8,192 reg00079
04/15/2005 02:00 AM 8,192 reg00080
04/15/2005 02:00 AM 8,192 reg00081
04/15/2005 02:00 AM 8,192 reg00082
04/15/2005 02:00 AM 8,192 reg00083
04/15/2005 02:00 AM 8,192 reg00084
04/15/2005 02:00 AM 8,192 reg00085
04/15/2005 02:00 AM 8,192 reg00086
04/15/2005 02:00 AM 8,192 reg00087
04/15/2005 02:00 AM 8,192 reg00088
04/15/2005 02:00 AM 8,192 reg00089
04/15/2005 02:00 AM 8,192 reg00090
04/15/2005 02:00 AM 8,192 reg00091
04/15/2005 02:00 AM 8,192 reg00092
04/15/2005 02:00 AM 8,192 reg00093
04/15/2005 02:00 AM 8,192 reg00094
04/15/2005 02:00 AM 8,192 reg00095
04/15/2005 02:00 AM 8,192 reg00096
04/15/2005 02:00 AM 8,192 reg00097
04/15/2005 02:00 AM 8,192 reg00098
04/15/2005 02:00 AM 8,192 reg00099
04/15/2005 02:00 AM 8,192 reg00100
04/15/2005 02:00 AM 8,192 reg00101
04/15/2005 02:00 AM 8,192 reg00102
04/15/2005 02:00 AM 8,192 reg00103
04/15/2005 02:00 AM 8,192 reg00104
04/15/2005 02:00 AM 8,192 reg00105
04/15/2005 02:00 AM 8,192 reg00106
04/15/2005 02:00 AM 8,192 reg00107
04/15/2005 02:00 AM 8,192 reg00108
04/15/2005 02:00 AM 8,192 reg00109
04/15/2005 02:00 AM 8,192 reg00110
04/15/2005 02:00 AM 8,192 reg00111
04/15/2005 02:00 AM 8,192 reg00112
04/15/2005 02:00 AM 8,192 reg00113
04/15/2005 02:00 AM 8,192 reg00114
04/15/2005 02:00 AM 8,192 reg00115
102 File(s) 835,584 bytes
Directory of C:\WINDOWS\$MSI31Uninstall_KB893803v2$
05/20/2005 11:05 PM 8,192 reg00003
05/20/2005 11:05 PM 8,192 reg00004
05/20/2005 11:05 PM 8,192 reg00005
05/20/2005 11:05 PM 8,192 reg00006
05/20/2005 11:05 PM 8,192 reg00007
05/20/2005 11:05 PM 8,192 reg00008
05/20/2005 11:05 PM 8,192 reg00009
05/20/2005 11:05 PM 8,192 reg00010
05/20/2005 11:05 PM 8,192 reg00011
05/20/2005 11:05 PM 8,192 reg00012
05/20/2005 11:05 PM 8,192 reg00013
05/20/2005 11:05 PM 8,192 reg00014
05/20/2005 11:05 PM 8,192 reg00015
05/20/2005 11:05 PM 8,192 reg00016
05/20/2005 11:05 PM 8,192 reg00017
05/20/2005 11:05 PM 8,192 reg00018
05/20/2005 11:05 PM 8,192 reg00019
05/20/2005 11:05 PM 8,192 reg00020
05/20/2005 11:05 PM 8,192 reg00021
05/20/2005 11:05 PM 8,192 reg00022
05/20/2005 11:05 PM 8,192 reg00023
05/20/2005 11:05 PM 8,192 reg00024
05/20/2005 11:05 PM 8,192 reg00025
05/20/2005 11:05 PM 8,192 reg00026
05/20/2005 11:05 PM 8,192 reg00027
05/20/2005 11:05 PM 8,192 reg00028
05/20/2005 11:05 PM 8,192 reg00029
05/20/2005 11:05 PM 8,192 reg00030
05/20/2005 11:05 PM 8,192 reg00031
05/20/2005 11:05 PM 8,192 reg00032
05/20/2005 11:05 PM 8,192 reg00033
05/20/2005 11:05 PM 8,192 reg00034
05/20/2005 11:05 PM 8,192 reg00035
05/20/2005 11:05 PM 8,192 reg00036
05/20/2005 11:05 PM 8,192 reg00037
05/20/2005 11:05 PM 8,192 reg00038
05/20/2005 11:05 PM 8,192 reg00039
05/20/2005 11:05 PM 8,192 reg00040
05/20/2005 11:05 PM 8,192 reg00041
05/20/2005 11:05 PM 8,192 reg00042
05/20/2005 11:05 PM 8,192 reg00043
05/20/2005 11:05 PM 8,192 reg00044
05/20/2005 11:05 PM 8,192 reg00045
05/20/2005 11:05 PM 8,192 reg00046
05/20/2005 11:05 PM 8,192 reg00047
05/20/2005 11:05 PM 8,192 reg00048
05/20/2005 11:05 PM 8,192 reg00051
05/20/2005 11:05 PM 8,192 reg00052
05/20/2005 11:05 PM 8,192 reg00053
05/20/2005 11:05 PM 8,192 reg00054
05/20/2005 11:05 PM 8,192 reg00055
05/20/2005 11:05 PM 8,192 reg00056
05/20/2005 11:05 PM 8,192 reg00057
05/20/2005 11:05 PM 8,192 reg00058
05/20/2005 11:05 PM 8,192 reg00059
05/20/2005 11:05 PM 8,192 reg00060
05/20/2005 11:05 PM 8,192 reg00061
05/20/2005 11:05 PM 8,192 reg00062
05/20/2005 11:05 PM 8,192 reg00063
05/20/2005 11:05 PM 8,192 reg00064
05/20/2005 11:05 PM 8,192 reg00065
05/20/2005 11:05 PM 8,192 reg00066
05/20/2005 11:05 PM 8,192 reg00067
05/20/2005 11:05 PM 8,192 reg00068
05/20/2005 11:05 PM 8,192 reg00069
05/20/2005 11:05 PM 8,192 reg00070
05/20/2005 11:05 PM 8,192 reg00071
05/20/2005 11:05 PM 8,192 reg00072
05/20/2005 11:05 PM 8,192 reg00073
05/20/2005 11:05 PM 8,192 reg00074
05/20/2005 11:05 PM 8,192 reg00075
05/20/2005 11:05 PM 8,192 reg00076
05/20/2005 11:05 PM 8,192 reg00077
05/20/2005 11:05 PM 8,192 reg00078
05/20/2005 11:05 PM 8,192 reg00079
05/20/2005 11:05 PM 8,192 reg00080
05/20/2005 11:05 PM 8,192 reg00081
05/20/2005 11:05 PM 8,192 reg00082
05/20/2005 11:05 PM 8,192 reg00083
05/20/2005 11:05 PM 8,192 reg00084
05/20/2005 11:05 PM 8,192 reg00085
05/20/2005 11:05 PM 8,192 reg00086
05/20/2005 11:05 PM 8,192 reg00087
05/20/2005 11:05 PM 8,192 reg00088
05/20/2005 11:05 PM 8,192 reg00089
05/20/2005 11:05 PM 8,192 reg00090
05/20/2005 11:05 PM 8,192 reg00091
05/20/2005 11:05 PM 8,192 reg00092
05/20/2005 11:05 PM 8,192 reg00093
05/20/2005 11:05 PM 8,192 reg00094
05/20/2005 11:05 PM 8,192 reg00095
05/20/2005 11:05 PM 8,192 reg00096
05/20/2005 11:05 PM 8,192 reg00097
05/20/2005 11:05 PM 8,192 reg00098
05/20/2005 11:05 PM 8,192 reg00099
05/20/2005 11:05 PM 8,192 reg00100
05/20/2005 11:05 PM 8,192 reg00101
05/20/2005 11:05 PM 8,192 reg00102
05/20/2005 11:05 PM 8,192 reg00103
05/20/2005 11:05 PM 8,192 reg00104
05/20/2005 11:05 PM 8,192 reg00105
05/20/2005 11:05 PM 8,192 reg00106
05/20/2005 11:05 PM 8,192 reg00107
05/20/2005 11:05 PM 8,192 reg00108
05/20/2005 11:05 PM 8,192 reg00109
05/20/2005 11:05 PM 8,192 reg00110
05/20/2005 11:05 PM 8,192 reg00111
05/20/2005 11:05 PM 8,192 reg00112
05/20/2005 11:05 PM 8,192 reg00113
05/20/2005 11:05 PM 8,192 reg00114
05/20/2005 11:05 PM 8,192 reg00115
05/20/2005 11:05 PM 8,192 reg00116
112 File(s) 917,504 bytes
Directory of C:\WINDOWS\$NtServicePackUninstall$
08/29/2002 04:41 AM 48,128 reg.exe
08/25/2004 06:03 PM 8,192 reg00001
08/25/2004 06:03 PM 8,192 reg00005
08/25/2004 06:03 PM 8,192 reg00013
08/25/2004 06:03 PM 8,192 reg00017
08/25/2004 06:03 PM 12,288 reg00018
08/25/2004 06:03 PM 8,192 reg00019
08/25/2004 06:03 PM 49,152 reg00020
08/25/2004 06:03 PM 8,192 reg00021
08/25/2004 06:03 PM 12,288 reg00070
08/25/2004 06:03 PM 8,192 reg00071
08/25/2004 06:03 PM 8,192 reg00072
08/25/2004 06:03 PM 24,576 reg00073
08/25/2004 06:03 PM 8,192 reg00139
08/25/2004 06:03 PM 8,192 reg00140
08/25/2004 06:03 PM 8,192 reg00141
08/25/2004 06:03 PM 8,192 reg00142
08/25/2004 06:03 PM 8,192 reg00166
08/25/2004 06:03 PM 8,192 reg00167
08/25/2004 06:03 PM 8,192 reg00168
08/25/2004 06:03 PM 8,192 reg00169
08/25/2004 06:03 PM 8,192 reg00170
08/25/2004 06:03 PM 8,192 reg00171
08/25/2004 06:03 PM 8,192 reg00172
08/25/2004 06:03 PM 8,192 reg00173
08/25/2004 06:03 PM 8,192 reg00174
08/25/2004 06:03 PM 8,192 reg00176
08/25/2004 06:03 PM 8,192 reg00177
08/25/2004 06:03 PM 8,192 reg00178
08/25/2004 06:03 PM 8,192 reg00179
08/25/2004 06:03 PM 8,192 reg00180
08/25/2004 06:03 PM 8,192 reg00181
08/25/2004 06:03 PM 8,192 reg00182
08/25/2004 06:03 PM 8,192 reg00183
08/25/2004 06:03 PM 8,192 reg00184
08/25/2004 06:03 PM 8,192 reg00185
08/25/2004 06:03 PM 8,192 reg00186
08/25/2004 06:03 PM 8,192 reg00187
08/25/2004 06:03 PM 8,192 reg00188
08/25/2004 06:03 PM 8,192 reg00189
08/25/2004 06:03 PM 8,192 reg00190
08/25/2004 06:03 PM 8,192 reg00191
08/25/2004 06:03 PM 8,192 reg00192
08/25/2004 06:03 PM 8,192 reg00193
08/25/2004 06:03 PM 8,192 reg00194
08/25/2004 06:03 PM 8,192 reg00195
08/25/2004 06:03 PM 8,192 reg00196
08/25/2004 06:03 PM 8,192 reg00197
08/25/2004 06:03 PM 8,192 reg00198
08/25/2004 06:03 PM 8,192 reg00199
08/25/2004 06:03 PM 8,192 reg00200
08/25/2004 06:03 PM 8,192 reg00201
08/25/2004 06:03 PM 8,192 reg00202
08/25/2004 06:03 PM 8,192 reg00203
08/25/2004 06:03 PM 8,192 reg00204
08/25/2004 06:03 PM 8,192 reg00205
08/25/2004 06:03 PM 8,192 reg00206
08/25/2004 06:03 PM 8,192 reg00207
08/25/2004 06:03 PM 8,192 reg00208
08/25/2004 06:03 PM 8,192 reg00209
08/25/2004 06:03 PM 8,192 reg00210
08/25/2004 06:03 PM 8,192 reg00211
08/25/2004 06:03 PM 8,192 reg00212
08/25/2004 06:03 PM 8,192 reg00213
08/25/2004 06:03 PM 8,192 reg00214
08/25/2004 06:03 PM 8,192 reg00215
08/25/2004 06:03 PM 8,192 reg00216
08/25/2004 06:04 PM 8,192 reg00217
08/25/2004 06:04 PM 8,192 reg00218
08/25/2004 06:04 PM 8,192 reg00219
08/25/2004 06:04 PM 8,192 reg00220
08/25/2004 06:04 PM 8,192 reg00221
08/25/2004 06:04 PM 8,192 reg00222
08/25/2004 06:04 PM 8,192 reg00223
08/25/2004 06:04 PM 8,192 reg00224
08/25/2004 06:04 PM 8,192 reg00225
08/25/2004 06:04 PM 8,192 reg00226
08/25/2004 06:04 PM 8,192 reg00227
08/25/2004 06:04 PM 8,192 reg00228
08/25/2004 06:04 PM 8,192 reg00229
08/25/2004 06:04 PM 8,192 reg00230
08/25/2004 06:04 PM 8,192 reg00231
08/25/2004 06:04 PM 8,192 reg00232
08/25/2004 06:04 PM 8,192 reg00233
08/25/2004 06:04 PM 8,192 reg00234
08/25/2004 06:04 PM 8,192 reg00235
08/25/2004 06:04 PM 8,192 reg00236
08/25/2004 06:04 PM 8,192 reg00237
08/25/2004 06:04 PM 8,192 reg00238
08/25/2004 06:04 PM 8,192 reg00239
08/25/2004 06:04 PM 8,192 reg00240
08/25/2004 06:04 PM 8,192 reg00241
08/25/2004 06:04 PM 8,192 reg00242
08/25/2004 06:04 PM 8,192 reg00243
08/25/2004 06:04 PM 143,360 reg00244
08/25/2004 06:04 PM 8,192 reg00245
08/25/2004 06:04 PM 8,192 reg00246
08/25/2004 06:04 PM 8,192 reg00247
08/25/2004 06:04 PM 8,192 reg00248
08/25/2004 06:04 PM 8,192 reg00249
08/25/2004 06:04 PM 8,192 reg00250
08/25/2004 06:04 PM 8,192 reg00251
08/25/2004 06:04 PM 8,192 reg00252
08/25/2004 06:04 PM 8,192 reg00253
08/25/2004 06:04 PM 8,192 reg00264
08/25/2004 06:04 PM 8,192 reg00265
08/25/2004 06:04 PM 8,192 reg00266
08/25/2004 06:04 PM 8,192 reg00267
08/25/2004 06:04 PM 8,192 reg00268
08/25/2004 06:04 PM 8,192 reg00269
08/25/2004 06:04 PM 8,192 reg00270
08/25/2004 06:04 PM 8,192 reg00271
08/25/2004 06:04 PM 8,192 reg00272
08/25/2004 06:04 PM 8,192 reg00273
08/25/2004 06:04 PM 8,192 reg00274
08/25/2004 06:04 PM 8,192 reg00275
08/25/2004 06:04 PM 8,192 reg00276
08/25/2004 06:04 PM 8,192 reg00277
08/25/2004 06:04 PM 8,192 reg00278
08/25/2004 06:04 PM 8,192 reg00279
08/25/2004 06:04 PM 8,192 reg00280
08/25/2004 06:04 PM 8,192 reg00281
08/25/2004 06:04 PM 8,192 reg00282
08/25/2004 06:04 PM 8,192 reg00283
08/25/2004 06:04 PM 8,192 reg00284
08/25/2004 06:04 PM 8,192 reg00285
08/25/2004 06:04 PM 8,192 reg00286
08/25/2004 06:04 PM 8,192 reg00287
08/25/2004 06:04 PM 8,192 reg00288
08/25/2004 06:04 PM 8,192 reg00289
08/25/2004 06:04 PM 8,192 reg00290
08/25/2004 06:04 PM 8,192 reg00291
08/25/2004 06:04 PM 8,192 reg00292
08/25/2004 06:04 PM 8,192 reg00293
08/25/2004 06:04 PM 8,192 reg00294
08/25/2004 06:04 PM 8,192 reg00299
08/25/2004 06:04 PM 8,192 reg00301
08/25/2004 06:04 PM 8,192 reg00303
08/25/2004 06:04 PM 8,192 reg00305
08/25/2004 06:04 PM 8,192 reg00307
08/25/2004 06:04 PM 8,192 reg00309
08/25/2004 06:04 PM 8,192 reg00311
08/25/2004 06:04 PM 8,192 reg00313
08/25/2004 06:04 PM 8,192 reg00315
08/25/2004 06:04 PM 8,192 reg00316
08/25/2004 06:04 PM 8,192 reg00317
08/25/2004 06:04 PM 8,192 reg00318
08/25/2004 06:04 PM 8,192 reg00319
08/25/2004 06:04 PM 8,192 reg00320
08/25/2004 06:04 PM 8,192 reg00321
08/25/2004 06:04 PM 8,192 reg00322
08/25/2004 06:04 PM 8,192 reg00323
08/25/2004 06:04 PM 8,192 reg00324
08/25/2004 06:04 PM 8,192 reg00325
08/25/2004 06:04 PM 8,192 reg00326
08/25/2004 06:04 PM 8,192 reg00327
08/25/2004 06:04 PM 8,192 reg00328
08/25/2004 06:04 PM 8,192 reg00329
08/25/2004 06:04 PM 8,192 reg00330
08/25/2004 06:04 PM 8,192 reg00331
08/25/2004 06:04 PM 8,192 reg00332
08/25/2004 06:04 PM 8,192 reg00333
08/25/2004 06:04 PM 8,192 reg00334
08/25/2004 06:04 PM 8,192 reg00335
08/25/2004 06:04 PM 8,192 reg00336
08/25/2004 06:04 PM 8,192 reg00337
08/25/2004 06:04 PM 8,192 reg00338
08/25/2004 06:04 PM 8,192 reg00339
08/25/2004 06:04 PM 8,192 reg00340
08/25/2004 06:04 PM 8,192 reg00341
08/25/2004 06:04 PM 8,192 reg00342
08/25/2004 06:04 PM 8,192 reg00343
08/25/2004 06:04 PM 8,192 reg00344
08/25/2004 06:04 PM 8,192 reg00345
08/25/2004 06:04 PM 8,192 reg00346
08/25/2004 06:04 PM 8,192 reg00347
08/25/2004 06:04 PM 8,192 reg00348
08/25/2004 06:04 PM 8,192 reg00349
08/25/2004 06:04 PM 8,192 reg00350
08/25/2004 06:04 PM 8,192 reg00351
08/25/2004 06:04 PM 8,192 reg00352
08/25/2004 06:04 PM 8,192 reg00353
08/25/2004 06:04 PM 8,192 reg00355
08/25/2004 06:04 PM 143,360 reg00356
08/25/2004 06:04 PM 8,192 reg00357
08/25/2004 06:04 PM 49,152 reg00358
08/25/2004 06:04 PM 8,192 reg00359
08/25/2004 06:04 PM 8,192 reg00360
08/25/2004 06:04 PM 8,192 reg00361
08/25/2004 06:04 PM 8,192 reg00362
08/25/2004 06:04 PM 8,192 reg00363
08/25/2004 06:04 PM 8,192 reg00365
08/25/2004 06:04 PM 8,192 reg00366
08/25/2004 06:04 PM 8,192 reg00367
08/25/2004 06:04 PM 8,192 reg00368
08/25/2004 06:04 PM 8,192 reg00369
08/25/2004 06:04 PM 8,192 reg00370
08/25/2004 06:04 PM 8,192 reg00373
08/25/2004 06:04 PM 8,192 reg00374
08/25/2004 06:04 PM 8,192 reg00375
08/25/2004 06:04 PM 8,192 reg00392
08/25/2004 06:04 PM 8,192 reg00396
08/25/2004 06:04 PM 8,192 reg00397
08/25/2004 06:04 PM 8,192 reg00404
08/25/2004 06:04 PM 8,192 reg00405
08/25/2004 06:04 PM 8,192 reg00410
08/25/2004 06:04 PM 8,192 reg00411
08/25/2004 06:04 PM 8,192 reg00412
08/25/2004 06:04 PM 8,192 reg00413
08/25/2004 06:04 PM 8,192 reg00414
08/25/2004 06:04 PM 8,192 reg00415
08/25/2004 06:04 PM 8,192 reg00416
08/25/2004 06:04 PM 8,192 reg00417
08/25/2004 06:04 PM 8,192 reg00418
08/25/2004 06:04 PM 8,192 reg00419
08/25/2004 06:04 PM 8,192 reg00420
08/25/2004 06:04 PM 8,192 reg00421
08/25/2004 06:04 PM 8,192 reg00422
08/25/2004 06:04 PM 8,192 reg00423
08/25/2004 06:04 PM 8,192 reg00424
08/25/2004 06:04 PM 8,192 reg00425
08/25/2004 06:04 PM 8,192 reg00426
08/25/2004 06:04 PM 8,192 reg00460
08/25/2004 06:04 PM 8,192 reg00461
08/25/2004 06:04 PM 8,192 reg00462
08/25/2004 06:04 PM 8,192 reg00463
08/25/2004 06:04 PM 8,192 reg00464
08/25/2004 06:04 PM 8,192 reg00465
08/25/2004 06:04 PM 8,192 reg00466
08/25/2004 06:04 PM 8,192 reg00467
08/25/2004 06:04 PM 8,192 reg00468
08/25/2004 06:04 PM 8,192 reg00469
08/25/2004 06:04 PM 8,192 reg00470
08/25/2004 06:04 PM 8,192 reg00471
08/25/2004 06:04 PM 8,192 reg00472
08/25/2004 06:04 PM 8,192 reg00473
08/25/2004 06:04 PM 8,192 reg00474
08/25/2004 06:04 PM 8,192 reg00475
08/25/2004 06:04 PM 8,192 reg00476
08/25/2004 06:04 PM 8,192 reg00477
08/25/2004 06:04 PM 8,192 reg00478
08/25/2004 06:04 PM 8,192 reg00479
08/25/2004 06:04 PM 8,192 reg00480
08/25/2004 06:04 PM 8,192 reg00481
08/25/2004 06:04 PM 8,192 reg00482
08/25/2004 06:04 PM 8,192 reg00483
08/25/2004 06:04 PM 8,192 reg00484
08/25/2004 06:04 PM 8,192 reg00485
08/25/2004 06:04 PM 8,192 reg00486
08/25/2004 06:04 PM 8,192 reg00487
08/25/2004 06:04 PM 8,192 reg00488
08/25/2004 06:04 PM 8,192 reg00489
08/25/2004 06:04 PM 8,192 reg00490
08/25/2004 06:04 PM 8,192 reg00491
08/25/2004 06:04 PM 8,192 reg00492
08/25/2004 06:04 PM 8,192 reg00493
08/25/2004 06:04 PM 8,192 reg00494
08/25/2004 06:04 PM 8,192 reg00495
08/25/2004 06:04 PM 8,192 reg00496
08/25/2004 06:04 PM 8,192 reg00497
08/25/2004 06:04 PM 8,192 reg00498
08/25/2004 06:04 PM 8,192 reg00576
08/25/2004 06:04 PM 8,192 reg00577
08/25/2004 06:04 PM 8,192 reg00578
08/25/2004 06:04 PM 8,192 reg00606
08/25/2004 06:04 PM 8,192 reg00607
08/25/2004 06:04 PM 8,192 reg00608
08/25/2004 06:04 PM 8,192 reg00610
08/25/2004 06:04 PM 8,192 reg00626
08/25/2004 06:04 PM 8,192 reg00627
08/25/2004 06:04 PM 8,192 reg00628
08/25/2004 06:04 PM 8,192 reg00629
08/25/2004 06:04 PM 8,192 reg00630
08/25/2004 06:04 PM 8,192 reg00631
08/25/2004 06:04 PM 8,192 reg00632
08/25/2004 06:04 PM 8,192 reg00633
08/25/2004 06:04 PM 8,192 reg00634
08/25/2004 06:04 PM 8,192 reg00635
08/25/2004 06:04 PM 8,192 reg00636
08/25/2004 06:04 PM 8,192 reg00637
08/25/2004 06:04 PM 8,192 reg00638
08/25/2004 06:04 PM 8,192 reg00639
08/25/2004 06:04 PM 8,192 reg00660
08/25/2004 06:04 PM 8,192 reg00661
08/25/2004 06:04 PM 8,192 reg00662
08/25/2004 06:04 PM 8,192 reg00663
08/25/2004 06:04 PM 8,192 reg00664
08/25/2004 06:04 PM 8,192 reg00665
08/25/2004 06:04 PM 8,192 reg00666
08/25/2004 06:04 PM 8,192 reg00667
08/25/2004 06:04 PM 8,192 reg00668
08/25/2004 06:04 PM 8,192 reg00669
08/25/2004 06:04 PM 8,192 reg00670
08/25/2004 06:04 PM 8,192 reg00671
08/25/2004 06:04 PM 8,192 reg00672
08/25/2004 06:04 PM 8,192 reg00673
08/25/2004 06:04 PM 8,192 reg00674
08/25/2004 06:04 PM 8,192 reg00675
08/25/2004 06:04 PM 8,192 reg00676
08/25/2004 06:04 PM 8,192 reg00677
08/25/2004 06:04 PM 8,192 reg00678
08/25/2004 06:04 PM 8,192 reg00679
08/25/2004 06:04 PM 8,192 reg00698
08/25/2004 06:04 PM 12,288 reg00726
08/25/2004 06:04 PM 8,192 reg00727
08/25/2004 06:04 PM 8,192 reg00728
08/25/2004 06:04 PM 8,192 reg00729
08/25/2004 06:04 PM 8,192 reg00730
08/25/2004 06:04 PM 8,192 reg00731
08/25/2004 06:04 PM 8,192 reg00732
08/25/2004 06:04 PM 8,192 reg00733
08/25/2004 06:04 PM 8,192 reg00734
08/25/2004 06:04 PM 8,192 reg00735
08/25/2004 06:04 PM 8,192 reg00736
08/25/2004 06:04 PM 8,192 reg00737
08/25/2004 06:04 PM 8,192 reg00738
08/25/2004 06:04 PM 8,192 reg00739
08/25/2004 06:04 PM 8,192 reg00740
08/25/2004 06:04 PM 8,192 reg00741
08/25/2004 06:04 PM 8,192 reg00742
08/25/2004 06:04 PM 8,192 reg00743
08/25/2004 06:04 PM 8,192 reg00744
08/25/2004 06:04 PM 8,192 reg00745
08/25/2004 06:04 PM 8,192 reg00746
08/25/2004 06:04 PM 8,192 reg00747
08/25/2004 06:04 PM 8,192 reg00748
08/25/2004 06:04 PM 8,192 reg00749
08/25/2004 06:04 PM 8,192 reg00750
08/25/2004 06:04 PM 8,192 reg00751
08/25/2004 06:04 PM 8,192 reg00752
08/25/2004 06:04 PM 8,192 reg00753
08/25/2004 06:04 PM 8,192 reg00754
08/25/2004 06:04 PM 8,192 reg00755
08/25/2004 06:04 PM 8,192 reg00756
08/25/2004 06:04 PM 8,192 reg00757
08/25/2004 06:04 PM 8,192 reg00758
08/25/2004 06:04 PM 8,192 reg00759
08/25/2004 06:04 PM 8,192 reg00760
08/25/2004 06:04 PM 8,192 reg00761
08/25/2004 06:04 PM 8,192 reg00762
08/25/2004 06:04 PM 8,192 reg00763
08/25/2004 06:04 PM 8,192 reg00764
08/25/2004 06:04 PM 8,192 reg00765
08/25/2004 06:04 PM 8,192 reg00766
08/25/2004 06:04 PM 8,192 reg00767
08/25/2004 06:04 PM 8,192 reg00768
08/25/2004 06:04 PM 8,192 reg00769
08/25/2004 06:04 PM 8,192 reg00770
08/25/2004 06:04 PM 8,192 reg00771
08/25/2004 06:04 PM 8,192 reg00772
08/25/2004 06:04 PM 8,192 reg00773
08/25/2004 06:04 PM 8,192 reg00774
08/25/2004 06:04 PM 8,192 reg00775
08/25/2004 06:04 PM 8,192 reg00776
08/25/2004 06:04 PM 8,192 reg00777
08/25/2004 06:04 PM 8,192 reg00778
08/25/2004 06:04 PM 8,192 reg00779
08/25/2004 06:04 PM 8,192 reg00780
08/25/2004 06:04 PM 8,192 reg00781
08/25/2004 06:04 PM 8,192 reg00782
08/25/2004 06:04 PM 8,192 reg00783
08/25/2004 06:04 PM 8,192 reg00784
08/25/2004 06:04 PM 8,192 reg00785
08/25/2004 06:04 PM 8,192 reg00786
08/25/2004 06:04 PM 8,192 reg00787
08/25/2004 06:04 PM 8,192 reg00788
08/25/2004 06:04 PM 8,192 reg00789
08/25/2004 06:04 PM 8,192 reg00790
08/25/2004 06:04 PM 8,192 reg00791
08/25/2004 06:04 PM 8,192 reg00792
08/25/2004 06:04 PM 8,192 reg00793
08/25/2004 06:04 PM 8,192 reg00794
08/25/2004 06:04 PM 8,192 reg00795
08/25/2004 06:04 PM 8,192 reg00796
08/25/2004 06:04 PM 8,192 reg00797
08/25/2004 06:04 PM 8,192 reg00798
08/25/2004 06:04 PM 8,192 reg00799
08/25/2004 06:04 PM 8,192 reg00800
08/25/2004 06:04 PM 8,192 reg00801
08/25/2004 06:04 PM 8,192 reg00802
08/25/2004 06:04 PM 8,192 reg00803
08/25/2004 06:04 PM 8,192 reg00804
08/25/2004 06:04 PM 8,192 reg00805
08/25/2004 06:04 PM 8,192 reg00806
08/25/2004 06:04 PM 8,192 reg00807
08/25/2004 06:04 PM 8,192 reg00808
08/25/2004 06:04 PM 8,192 reg00809
08/25/2004 06:04 PM 8,192 reg00810
08/25/2004 06:04 PM 8,192 reg00811
08/25/2004 06:04 PM 8,192 reg00812
08/25/2004 06:04 PM 8,192 reg00813
08/25/2004 06:04 PM 8,192 reg00814
08/25/2004 06:04 PM 8,192 reg00815
08/25/2004 06:04 PM 8,192 reg00816
08/25/2004 06:04 PM 8,192 reg00817
08/25/2004 06:04 PM 8,192 reg00818
08/25/2004 06:04 PM 8,192 reg00819
08/25/2004 06:04 PM 8,192 reg00820
08/25/2004 06:04 PM 8,192 reg00821
08/25/2004 06:04 PM 8,192 reg00822
08/25/2004 06:04 PM 8,192 reg00823
08/25/2004 06:04 PM 8,192 reg00824
08/25/2004 06:04 PM 8,192 reg00825
08/25/2004 06:04 PM 8,192 reg00826
08/25/2004 06:04 PM 8,192 reg00827
08/25/2004 06:04 PM 8,192 reg00828
08/25/2004 06:04 PM 8,192 reg00829
08/25/2004 06:04 PM 8,192 reg00830
08/25/2004 06:04 PM 8,192 reg00831
08/25/2004 06:04 PM 8,192 reg00832
08/25/2004 06:04 PM 8,192 reg00833
08/25/2004 06:04 PM 8,192 reg00834
08/25/2004 06:04 PM 8,192 reg00835
08/25/2004 06:04 PM 8,192 reg00836
08/25/2004 06:04 PM 8,192 reg00837
08/25/2004 06:04 PM 8,192 reg00838
08/25/2004 06:04 PM 8,192 reg00839
08/25/2004 06:04 PM 8,192 reg00840
08/25/2004 06:04 PM 8,192 reg00841
08/25/2004 06:04 PM 8,192 reg00842
08/25/2004 06:04 PM 8,192 reg00843
08/25/2004 06:04 PM 8,192 reg00844
08/25/2004 06:04 PM 8,192 reg00845
08/25/2004 06:04 PM 8,192 reg00846
08/25/2004 06:04 PM 8,192 reg00847
08/25/2004 06:04 PM 8,192 reg00850
08/25/2004 06:04 PM 8,192 reg00851
08/25/2004 06:04 PM 16,384 reg00852
08/25/2004 06:04 PM 8,192 reg00853
08/25/2004 06:04 PM 8,192 reg00854
08/25/2004 06:04 PM 8,192 reg00855
08/25/2004 06:04 PM 8,192 reg00856
08/25/2004 06:04 PM 8,192 reg00857
08/25/2004 06:04 PM 192,512 reg00858
08/25/2004 06:04 PM 163,840 reg00859
08/25/2004 06:04 PM 8,192 reg00860
08/25/2004 06:04 PM 8,192 reg00864
08/25/2004 06:04 PM 8,192 reg00865
08/25/2004 06:04 PM 8,192 reg00866
08/25/2004 06:04 PM 8,192 reg00867
08/25/2004 06:04 PM 8,192 reg00868
08/25/2004 06:04 PM 8,192 reg00869
08/25/2004 06:04 PM 8,192 reg00870
08/25/2004 06:04 PM 8,192 reg00871
08/25/2004 06:04 PM 8,192 reg00872
08/25/2004 06:04 PM 8,192 reg00873
08/25/2004 06:04 PM 8,192 reg00874
08/25/2004 06:04 PM 8,192 reg00875
08/25/2004 06:04 PM 8,192 reg00876
08/25/2004 06:04 PM 8,192 reg00877
08/25/2004 06:04 PM 8,192 reg00878
08/25/2004 06:04 PM 8,192 reg00879
08/25/2004 06:04 PM 8,192 reg00880
08/25/2004 06:04 PM 8,192 reg00881
08/25/2004 06:04 PM 8,192 reg00882
08/25/2004 06:04 PM 8,192 reg00883
08/25/2004 06:04 PM 8,192 reg00884
08/25/2004 06:04 PM 8,192 reg00885
08/25/2004 06:04 PM 8,192 reg00886
08/25/2004 06:04 PM 8,192 reg00887
08/25/2004 06:04 PM 8,192 reg00888
08/25/2004 06:04 PM 8,192 reg00889
08/25/2004 06:04 PM 8,192 reg00890
08/25/2004 06:04 PM 8,192 reg00891
08/25/2004 06:04 PM 8,192 reg00892
08/25/2004 06:04 PM 8,192 reg00893
08/25/2004 06:04 PM 8,192 reg00894
08/25/2004 06:04 PM 8,192 reg00895
08/25/2004 06:04 PM 8,192 reg00896
08/25/2004 06:04 PM 8,192 reg00897
08/25/2004 06:04 PM 8,192 reg00898
08/25/2004 06:04 PM 8,192 reg00899
08/25/2004 06:04 PM 8,192 reg00900
08/25/2004 06:04 PM 8,192 reg00901
08/25/2004 06:04 PM 8,192 reg00902
08/25/2004 06:04 PM 28,672 reg00903
08/25/2004 06:04 PM 8,192 reg00904
08/25/2004 06:04 PM 8,192 reg00905
08/25/2004 06:04 PM 8,192 reg00906
08/25/2004 06:04 PM 8,192 reg00907
08/25/2004 06:04 PM 8,192 reg00921
08/25/2004 06:04 PM 8,192 reg00923
08/25/2004 06:04 PM 8,192 reg00924
08/25/2004 06:04 PM 8,192 reg00925
08/25/2004 06:04 PM 8,192 reg00926
08/25/2004 06:04 PM 8,192 reg00927
08/25/2004 06:04 PM 8,192 reg00928
08/25/2004 06:04 PM 8,192 reg00929
08/25/2004 06:04 PM 8,192 reg00930
08/25/2004 06:04 PM 8,192 reg00931
08/25/2004 06:04 PM 8,192 reg00932
08/25/2004 06:04 PM 8,192 reg00933
08/25/2004 06:04 PM 8,192 reg00934
08/25/2004 06:04 PM 8,192 reg00935
08/25/2004 06:04 PM 8,192 reg00936
08/25/2004 06:04 PM 8,192 reg01396
08/25/2004 06:04 PM 8,192 reg01397
08/25/2004 06:04 PM 8,192 reg01399
08/25/2004 06:04 PM 8,192 reg01400
08/25/2004 06:04 PM 8,192 reg01401
08/25/2004 06:04 PM 8,192 reg01402
08/25/2004 06:04 PM 8,192 reg01403
08/25/2004 06:04 PM 8,192 reg01408
08/25/2004 06:04 PM 8,192 reg01414
08/25/2004 06:04 PM 8,192 reg01427
08/25/2004 06:04 PM 8,192 reg01428
08/25/2004 06:04 PM 8,192 reg01429
08/25/2004 06:04 PM 8,192 reg01430
08/25/2004 06:04 PM 8,192 reg01431
08/25/2004 06:04 PM 8,192 reg01432
08/25/2004 06:04 PM 8,192 reg01433
08/25/2004 06:04 PM 8,192 reg01434
08/25/2004 06:04 PM 8,192 reg01437
08/25/2004 06:04 PM 8,192 reg01438
08/25/2004 06:04 PM 8,192 reg01439
08/25/2004 06:04 PM 8,192 reg01440
08/25/2004 06:04 PM 8,192 reg01441
08/25/2004 06:04 PM 8,192 reg01442
08/25/2004 06:04 PM 8,192 reg01443
08/25/2004 06:04 PM 8,192 reg01444
08/25/2004 06:04 PM 8,192 reg01445
08/25/2004 06:04 PM 8,192 reg01446
08/25/2004 06:04 PM 8,192 reg01447
08/25/2004 06:04 PM 8,192 reg01448
08/25/2004 06:04 PM 8,192 reg01449
08/25/2004 06:04 PM 8,192 reg01450
08/25/2004 06:04 PM 8,192 reg01451
08/25/2004 06:04 PM 8,192 reg01452
08/25/2004 06:04 PM 8,192 reg01453
08/25/2004 06:04 PM 8,192 reg01454
08/25/2004 06:04 PM 8,192 reg01455
08/25/2004 06:04 PM 8,192 reg01456
08/25/2004 06:04 PM 8,192 reg01457
08/25/2004 06:04 PM 8,192 reg01458
08/25/2004 06:04 PM 8,192 reg01459
08/25/2004 06:04 PM 8,192 reg01460
08/25/2004 06:04 PM 8,192 reg01461
08/25/2004 06:04 PM 8,192 reg01462
08/25/2004 06:04 PM 8,192 reg01463
08/25/2004 06:04 PM 8,192 reg01464
08/25/2004 06:04 PM 8,192 reg01465
08/25/2004 06:04 PM 8,192 reg01466
08/25/2004 06:04 PM 8,192 reg01467
08/25/2004 06:04 PM 8,192 reg01468
08/25/2004 06:04 PM 8,192 reg01469
08/25/2004 06:04 PM 8,192 reg01470
08/25/2004 06:04 PM 8,192 reg01471
08/25/2004 06:04 PM 8,192 reg01472
08/25/2004 06:04 PM 8,192 reg01473
08/25/2004 06:04 PM 8,192 reg01474
08/25/2004 06:04 PM 8,192 reg01475
08/25/2004 06:04 PM 8,192 reg01476
08/25/2004 06:04 PM 8,192 reg01477
08/25/2004 06:04 PM 8,192 reg01478
08/25/2004 06:04 PM 8,192 reg01479
08/25/2004 06:04 PM 8,192 reg01480
08/25/2004 06:04 PM 8,192 reg01483
08/25/2004 06:04 PM 8,192 reg01484
08/25/2004 06:04 PM 8,192 reg01485
08/25/2004 06:04 PM 8,192 reg01486
08/25/2004 06:04 PM 8,192 reg01487
08/25/2004 06:04 PM 8,192 reg01488
08/25/2004 06:04 PM 8,192 reg01489
08/25/2004 06:04 PM 8,192 reg01490
08/25/2004 06:04 PM 8,192 reg01491
08/25/2004 06:04 PM 8,192 reg01492
08/25/2004 06:04 PM 8,192 reg01493
08/25/2004 06:04 PM 8,192 reg01494
08/25/2004 06:04 PM 8,192 reg01495
08/25/2004 06:04 PM 8,192 reg01496
08/25/2004 06:04 PM 8,192 reg01497
08/25/2004 06:04 PM 8,192 reg01498
08/25/2004 06:04 PM 8,192 reg01499
08/25/2004 06:04 PM 8,192 reg01500
08/25/2004 06:04 PM 8,192 reg01501
08/25/2004 06:04 PM 8,192 reg01502
08/25/2004 06:04 PM 8,192 reg01503
08/25/2004 06:04 PM 8,192 reg01504
08/25/2004 06:04 PM 8,192 reg01505
08/25/2004 06:04 PM 8,192 reg01506
08/25/2004 06:04 PM 8,192 reg01507
08/25/2004 06:04 PM 8,192 reg01508
08/25/2004 06:04 PM 8,192 reg01509
08/25/2004 06:04 PM 8,192 reg01510
08/25/2004 06:04 PM 8,192 reg01511
08/25/2004 06:04 PM 8,192 reg01512
08/25/2004 06:04 PM 8,192 reg01513
08/25/2004 06:04 PM 8,192 reg01514
08/25/2004 06:04 PM 8,192 reg01515
08/25/2004 06:04 PM 8,192 reg01516
08/25/2004 06:04 PM 8,192 reg01517
08/25/2004 06:04 PM 8,192 reg01518
08/25/2004 06:04 PM 8,192 reg01519
08/25/2004 06:04 PM 8,192 reg01520
08/25/2004 06:04 PM 8,192 reg01521
08/25/2004 06:04 PM 8,192 reg01522
08/25/2004 06:04 PM 8,192 reg01523
08/25/2004 06:04 PM 8,192 reg01524
08/25/2004 06:04 PM 8,192 reg01525
08/25/2004 06:04 PM 8,192 reg01526
08/25/2004 06:04 PM 8,192 reg01527
08/25/2004 06:04 PM 8,192 reg01528
08/25/2004 06:04 PM 8,192 reg01529
08/25/2004 06:04 PM 8,192 reg01530
08/25/2004 06:04 PM 8,192 reg01531
08/25/2004 06:04 PM 8,192 reg01532
08/25/2004 06:04 PM 8,192 reg01543
08/25/2004 06:04 PM 8,192 reg01544
08/25/2004 06:04 PM 8,192 reg01545
08/25/2004 06:04 PM 8,192 reg01546
08/25/2004 06:04 PM 8,192 reg01547
08/25/2004 06:04 PM 8,192 reg01548
08/25/2004 06:04 PM 8,192 reg01549
08/25/2004 06:04 PM 8,192 reg01550
08/25/2004 06:04 PM 8,192 reg01551
08/25/2004 06:04 PM 8,192 reg01552
08/25/2004 06:04 PM 8,192 reg01553
08/25/2004 06:04 PM 8,192 reg01554
08/25/2004 06:04 PM 8,192 reg01555
08/25/2004 06:04 PM 8,192 reg01556
08/25/2004 06:04 PM 8,192 reg01557
08/25/2004 06:04 PM 8,192 reg01558
08/25/2004 06:04 PM 8,192 reg01559
08/25/2004 06:04 PM 8,192 reg01560
08/25/2004 06:04 PM 8,192 reg01561
08/25/2004 06:04 PM 8,192 reg01562
08/25/2004 06:04 PM 8,192 reg01565
08/25/2004 06:04 PM 8,192 reg01566
08/25/2004 06:04 PM 8,192 reg01567
08/25/2004 06:04 PM 8,192 reg01568
08/25/2004 06:04 PM 8,192 reg01569
08/25/2004 06:04 PM 8,192 reg01571
08/25/2004 06:04 PM 8,192 reg01572
08/25/2004 06:04 PM 8,192 reg01573
08/25/2004 06:04 PM 8,192 reg01574
08/25/2004 06:04 PM 8,192 reg01576
08/25/2004 06:04 PM 8,192 reg01581
08/25/2004 06:04 PM 8,192 reg01594
08/25/2004 06:04 PM 8,192 reg01599
08/25/2004 06:04 PM 8,192 reg01600
08/25/2004 06:04 PM 8,192 reg01602
08/25/2004 06:04 PM 8,192 reg01603
08/25/2004 06:04 PM 8,192 reg01604
08/25/2004 06:04 PM 8,192 reg01610
08/25/2004 06:04 PM 8,192 reg01611
08/25/2004 06:04 PM 8,192 reg01612
08/25/2004 06:04 PM 8,192 reg01613
08/25/2004 06:04 PM 8,192 reg01615
08/25/2004 06:04 PM 8,192 reg01616
08/25/2004 06:04 PM 8,192 reg01619
08/25/2004 06:04 PM 8,192 reg01620
08/25/2004 06:04 PM 8,192 reg01622
08/25/2004 06:04 PM 8,192 reg01623
08/25/2004 06:04 PM 8,192 reg01624
08/25/2004 06:04 PM 8,192 reg01625
08/25/2004 06:04 PM 8,192 reg01626
08/25/2004 06:04 PM 8,192 reg01627
08/25/2004 06:04 PM 8,192 reg01628
08/25/2004 06:04 PM 8,192 reg01629
08/25/2004 06:04 PM 8,192 reg01630
08/25/2004 06:04 PM 8,192 reg01631
08/25/2004 06:04 PM 8,192 reg01632
08/25/2004 06:04 PM 8,192 reg01633
08/25/2004 06:04 PM 8,192 reg01634
08/25/2004 06:04 PM 8,192 reg01635
08/25/2004 06:04 PM 8,192 reg01636
08/25/2004 06:04 PM 8,192 reg01637
08/25/2004 06:04 PM 8,192 reg01639
08/25/2004 06:04 PM 8,192 reg01654
08/25/2004 06:04 PM 8,192 reg01658
08/25/2004 06:04 PM 8,192 reg01659
08/29/2002 04:41 AM 44,032 regapi.dll
08/29/2002 04:41 AM 134,144 regedit.exe
08/18/2001 06:00 AM 51,712 regsvc.dll
08/18/2001 06:00 AM 9,728 regsvr32.exe
08/18/2001 06:00 AM 387,584 regwizc.dll
676 File(s) 6,913,536 bytes
Directory of C:\WINDOWS\$NtUninstallKB820291$
07/10/2004 11:59 PM 28,672 reg00005
1 File(s) 28,672 bytes
Directory of C:\WINDOWS\$NtUninstallKB826942$
07/10/2004 11:58 PM 8,192 reg00003
07/10/2004 11:58 PM 8,192 reg00004
2 File(s) 16,384 bytes
Directory of C:\WINDOWS\$NtUninstallKB835732$
07/10/2004 11:18 PM 8,192 reg00004
07/10/2004 11:18 PM 8,192 reg00005
07/10/2004 11:18 PM 8,192 reg00006
07/10/2004 11:18 PM 8,192 reg00008
07/10/2004 11:18 PM 8,192 reg00009
5 File(s) 40,960 bytes
Directory of C:\WINDOWS\$NtUninstallKB842773$
07/13/2004 06:43 PM 8,192 reg00002
07/13/2004 06:43 PM 8,192 reg00005
07/13/2004 06:43 PM 8,192 reg00006
07/13/2004 06:43 PM 8,192 reg00007
07/13/2004 06:43 PM 8,192 reg00008
07/13/2004 06:43 PM 8,192 reg00009
07/13/2004 06:43 PM 8,192 reg00010
07/13/2004 06:43 PM 8,192 reg00011
07/13/2004 06:43 PM 8,192 reg00012
07/13/2004 06:43 PM 8,192 reg00013
07/13/2004 06:43 PM 8,192 reg00014
07/13/2004 06:43 PM 8,192 reg00015
07/13/2004 06:43 PM 8,192 reg00016
07/13/2004 06:43 PM 8,192 reg00017
07/13/2004 06:43 PM 8,192 reg00018
07/13/2004 06:43 PM 8,192 reg00019
07/13/2004 06:43 PM 8,192 reg00020
07/13/2004 06:43 PM 8,192 reg00021
07/13/2004 06:43 PM 8,192 reg00022
07/13/2004 06:43 PM 8,192 reg00023
07/13/2004 06:43 PM 8,192 reg00032
07/13/2004 06:43 PM 8,192 reg00033
07/13/2004 06:43 PM 8,192 reg00034
23 File(s) 188,416 bytes
Directory of C:\WINDOWS\$NtUninstallKB867282$
02/11/2005 06:31 AM 184,320 reg00001
02/11/2005 06:31 AM 8,192 reg00002
2 File(s) 192,512 bytes
Directory of C:\WINDOWS\$NtUninstallKB883939$
06/14/2005 08:40 PM 184,320 reg00001
06/14/2005 08:40 PM 8,192 reg00002
06/14/2005 08:40 PM 8,192 reg00003
3 File(s) 200,704 bytes
Directory of C:\WINDOWS\$NtUninstallKB890923$
04/15/2005 02:01 AM 184,320 reg00001
04/15/2005 02:01 AM 8,192 reg00002
04/15/2005 02:01 AM 8,192 reg00003
3 File(s) 200,704 bytes
Directory of C:\WINDOWS\$NtUninstallKB896358$
06/14/2005 08:40 PM 8,192 reg00001
06/14/2005 08:40 PM 8,192 reg00002
2 File(s) 16,384 bytes
Directory of C:\WINDOWS\$NtUninstallKB896688$
10/14/2005 02:01 AM 8,192 reg00001
10/14/2005 02:01 AM 8,192 reg00002
10/14/2005 02:01 AM 8,192 reg00003
10/14/2005 02:01 AM 8,192 reg00004
10/14/2005 02:01 AM 8,192 reg00005
10/14/2005 02:01 AM 8,192 reg00006
10/14/2005 02:01 AM 8,192 reg00007
10/14/2005 02:01 AM 8,192 reg00008
10/14/2005 02:01 AM 8,192 reg00009
10/14/2005 02:01 AM 8,192 reg00010
10/14/2005 02:01 AM 8,192 reg00011
10/14/2005 02:01 AM 8,192 reg00012
10/14/2005 02:01 AM 200,704 reg00013
13 File(s) 299,008 bytes
Directory of C:\WINDOWS\$NtUninstallKB896727$
08/13/2005 02:01 AM 8,192 reg00001
08/13/2005 02:01 AM 8,192 reg00002
08/13/2005 02:01 AM 188,416 reg00003
3 File(s) 204,800 bytes
Directory of C:\WINDOWS\$NtUninstallKB903235$
07/14/2005 02:00 AM 188,416 reg00001
1 File(s) 188,416 bytes
Directory of C:\WINDOWS\$NtUninstallKB905915$
12/14/2005 09:25 PM 8,192 reg00001
12/14/2005 09:25 PM 8,192 reg00002
12/14/2005 09:25 PM 8,192 reg00003
12/14/2005 09:25 PM 8,192 reg00004
12/14/2005 09:25 PM 8,192 reg00005
12/14/2005 09:25 PM 8,192 reg00006
12/14/2005 09:25 PM 8,192 reg00007
12/14/2005 09:25 PM 8,192 reg00008
12/14/2005 09:25 PM 8,192 reg00009
12/14/2005 09:25 PM 8,192 reg00010
12/14/2005 09:25 PM 8,192 reg00011
12/14/2005 09:25 PM 8,192 reg00012
12/14/2005 09:25 PM 217,088 reg00013
12/14/2005 09:25 PM 8,192 reg00016
12/14/2005 09:25 PM 8,192 reg00017
12/14/2005 09:25 PM 8,192 reg00019
12/14/2005 09:25 PM 8,192 reg00020
17 File(s) 348,160 bytes
Directory of C:\WINDOWS\$NtUninstallQ327979$
07/11/2004 12:02 AM 8,192 reg00003
07/11/2004 12:02 AM 8,192 reg00004
07/11/2004 12:02 AM 8,192 reg00006
07/11/2004 12:02 AM 8,192 reg00007
07/11/2004 12:02 AM 8,192 reg00010
07/11/2004 12:02 AM 8,192 reg00011
07/11/2004 12:02 AM 8,192 reg00012
07/11/2004 12:02 AM 8,192 reg00013
07/11/2004 12:02 AM 8,192 reg00014
07/11/2004 12:02 AM 8,192 reg00015
07/11/2004 12:02 AM 8,192 reg00016
07/11/2004 12:02 AM 8,192 reg00017
07/11/2004 12:02 AM 8,192 reg00018
07/11/2004 12:02 AM 8,192 reg00019
07/11/2004 12:02 AM 8,192 reg00020
07/11/2004 12:02 AM 8,192 reg00021
07/11/2004 12:02 AM 8,192 reg00022
07/11/2004 12:02 AM 8,192 reg00023
07/11/2004 12:02 AM 8,192 reg00024
07/11/2004 12:02 AM 8,192 reg00025
07/11/2004 12:02 AM 8,192 reg00026
07/11/2004 12:02 AM 8,192 reg00027
07/11/2004 12:02 AM 8,192 reg00028
07/11/2004 12:02 AM 8,192 reg00029
07/11/2004 12:02 AM 8,192 reg00030
07/11/2004 12:02 AM 8,192 reg00031
07/11/2004 12:02 AM 8,192 reg00032
07/11/2004 12:02 AM 8,192 reg00033
07/11/2004 12:02 AM 8,192 reg00034
07/11/2004 12:02 AM 8,192 reg00035
07/11/2004 12:02 AM 8,192 reg00036
31 File(s) 253,952 bytes
Directory of C:\WINDOWS\Help
08/18/2001 06:00 AM 46,684 regedit.chm
08/18/2001 06:00 AM 12,886 regedit.hlp
07/17/2002 04:32 AM 24,567 regopt.chm
3 File(s) 84,137 bytes
Directory of C:\WINDOWS\Prefetch
12/31/2005 06:52 AM 17,940 REGEDIT.EXE-1B606482.pf
12/29/2005 04:11 PM 17,374 REGSVR32.EXE-25EEFE2F.pf
2 File(s) 35,314 bytes
Directory of C:\WINDOWS\provisioning\schemas
07/17/2004 12:35 PM 1,032 register.xdr
1 File(s) 1,032 bytes
Directory of C:\WINDOWS\ServicePackFiles\i386
08/04/2004 01:56 AM 50,176 reg.exe
08/04/2004 01:56 AM 49,664 regapi.dll
08/04/2004 01:56 AM 146,432 regedit.exe
07/17/2002 04:32 AM 24,567 regopt.chm
08/04/2004 01:56 AM 59,904 regsvc.dll
08/04/2004 01:56 AM 11,776 regsvr32.exe
08/04/2004 01:56 AM 397,824 regwizc.dll
7 File(s) 740,343 bytes
Directory of C:\WINDOWS\SoftwareDistribution\SelfUpdate
12/31/2005 08:34 AM <DIR> Registered
0 File(s) 0 bytes
Directory of C:\WINDOWS\system32
08/04/2004 01:56 AM 50,176 reg.exe
08/04/2004 01:56 AM 49,664 regapi.dll
08/18/2001 06:00 AM 3,584 regedt32.exe
08/18/2001 06:00 AM 33,792 regini.exe
08/04/2004 01:56 AM 59,904 regsvc.dll
08/04/2004 01:56 AM 11,776 regsvr32.exe
08/18/2001 06:00 AM 4,608 regwiz.exe
08/04/2004 01:56 AM 397,824 regwizc.dll
8 File(s) 611,328 bytes
Directory of C:\WINDOWS\system32\dllcache
08/18/2001 06:00 AM 3,584 regedt32.exe
08/18/2001 06:00 AM 33,792 regini.exe
08/18/2001 06:00 AM 14,848 register.exe
08/18/2001 06:00 AM 4,608 regwiz.exe
4 File(s) 56,832 bytes
Directory of C:\WINDOWS\system32\oobe
08/18/2001 06:00 AM 124 reg.isp
07/10/2004 10:17 PM <DIR> regerror
1 File(s) 124 bytes
Directory of C:\WINDOWS\system32\oobe\setup
08/18/2001 06:00 AM 6,457 reg1.htm
08/18/2001 06:00 AM 8,477 reg3.htm
08/18/2001 06:00 AM 2,411 regdial.htm
3 File(s) 17,345 bytes
Directory of C:\WINDOWS\system32\wbem
08/18/2001 06:00 AM 38,578 regevent.mfl
08/18/2001 06:00 AM 46,372 regevent.mof
2 File(s) 84,950 bytes
Directory of C:\WINDOWS\Temp
08/21/2004 07:47 AM 88 RegisteringDLLs.log
1 File(s) 88 bytes
Total Files Listed:
1031 File(s) 12,632,865 bytes
4 Dir(s) 3,905,019,904 bytes free
I hope this is what you wanted.
Yes, this is what I did want. Nothing shows that the registry should be disabled, the regedit tool is present too. Just noticed a typo, could have been that.
Click Start > Run > type in regedit and hit enter.
Does the registry editor open or not ?
If it does not open, stop immediately and let me know. Otherwise proceed with the rest of the fix.
Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Disable Microsoft AntiSpyware, it will interfer with the fix.
- Open Microsoft AntiSpyware.
- Click on Options, Settings.
- In the left pane, click on Real-time Protection.
- Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
- Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
- After you unchecked these, click on the Save button and close Microsoft AntiSpyware.
- Right click on the Microsoft AntiSpyware Icon on the taskbar and select Shutdown Microsoft AntiSpyware.
______________________________
Make sure that you can see hidden files.
- Click Start.
- Click My Computer.
- Select the Tools menu and click Folder Options.
- Select the View Tab.
- Under the Hidden files and folders heading select Show hidden files and folders.
- Uncheck the Hide protected operating system files (recommended) option.
- Click Yes to confirm.
- Uncheck the Hide file extensions for known file types.
- Click OK.
______________________________
Copy/paste the following text into a new Notepad document. Make sure that you have one blank line at the end of the document as shown in the quoted text.
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=dword:00000000
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{31EE3286-D785-4E3F-95FC-51D00FDABC01}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31EE3286-D785-4E3F-95FC-51D00FDABC01}]
Save it to your desktop as
Fixme.reg. Save it as :
File Type: All Files (not as a text document or it wont work).
Name: Fixme.reg
Locate
Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click
YES. Wait for the
merged successfully prompt.
______________________________
Run HijackThis, click on
None of the above, just start the program, click on
Scan. Put a
check in the box on the left side of the following items if still present:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A312C3A-80A0-4CC5-818C-2233FFDAA992}: NameServer = 85.255.113.130,85.255.112.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1600FA7-729C-414B-B226-E11309F241FC}: NameServer = 85.255.113.130,85.255.112.67
Close
ALL windows and browsers
except HijackThis and click
Fix Checked
______________________________
Reset your DNS servers
- Click Start, click Control Panel, click Network and Internet Connections, and then click Network Connections.
- Right-click the network connection that you want to configure, and then click Properties.
- On the General tab (for a local area connection), or the Networking tab (for all other connections), click Internet Protocol (TCP/IP), and then click Properties.
- If you want to obtain DNS server addresses from a DHCP server, click Obtain DNS server address automatically. (Recommended)
- If you want to manually configure DNS server addresses, click Use the following DNS server addresses, and then type the preferred DNS server and alternate DNS server IP addresses in the Preferred DNS server and Alternate DNS server boxes.
Reboot your PC
______________________________
Please download FixWareout from
http://swandog46.geekstogo.com/Fixwareout.exe
Note: Leave your internet connection running, the fixwareout may prompt you to download BFU from merijn.
Save it to your Desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts. Afterwards, HijackThis will launch.
Put a
check in the box on the left side of the following items if still present:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\kernels64.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A312C3A-80A0-4CC5-818C-2233FFDAA992}: NameServer = 85.255.113.130,85.255.112.67
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1600FA7-729C-414B-B226-E11309F241FC}: NameServer = 85.255.113.130,85.255.112.67
Close
ALL windows and browsers
except HijackThis and click
Fix Checked
At the end of the fix, you may need to restart your computer again. A log will be created,
C:\fixwareout\report.txt, I will need that file later on.
If present, delete the folder C:\Program Files\WareOut
______________________________
Download win32delfkil.exe from:
http://users.telenet.be/marcvn/tools/win32delfkil.exe.
Save it on your desktop. Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil
Close all windows, open the win32delfkil folder and double click on
fix.bat.
The computer should reboot automatically, if not you'll need to
reboot the computer manually, by turning the power off and then back on.
It will create a log named
c:\windelf.txt, I will need that later on.
______________________________
Download Registry Search by Bobbi Flekman
http://www.bleepingcomputer.com/files/regsearch.php
Create a folder named C:\Reg for it and unzip into that folder.
______________________________
Please download SmitRem.exe by noahdfear to your Desktop.
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
Double-click the
smitRem.exe and it will extract the files to a smitRem folder on your Desktop.
______________________________
Please download the trial version of Ewido Security Suite 3.5 from here:
http://www.ewido.net/en/download/
- Install Ewido Security Suite.
- When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
- When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
- The program will prompt you to update. Click the Ok button.
- The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
- On the left-hand side of the main screen click the Update Button.
- Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido.
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________
If you already have the latest Ad-Aware SE 1.06 version, skip to
Run Ad-Aware. Otherwise download Ad-Aware SE 1.06 from
here and install it. Uncheck all the options before leaving the Install Wizard.
Run Ad-Aware and Click on the
World Icon. Click the
Connect button on the webupdate screen. If an update is available download it and install it. Click the
Finish button to go back to the main screen.
Click on the
Gear Icon (second from the left at the top of the window) to access the Configuration Window.
Click on the
General Button on the left and select in
green
- Under Safety
- Automatically save log-file
- Automatically quarantine objects prior to removal
- Safe Mode (always request confirmation)
- Under Definitions
- Prompt to udate outdated definitions - set to 7 days
Click on the
Scanning Button of the left and select in
green
- Under Driver, Folders & Files
- Under Select drives & folders to scan
- Under Memory & Registry
- Scan Active Processes
- Scan Registry
- Deep Scan Registry
- Scan my IE favorites for banned URL’s
- Scan my Hosts file
Click on the
Advanced Button on the left and select in
green
- Under Shell Integration
- Move deleted files to Recycle Bin
- Under Logfile Detail Level
- Include addtional object information
- DESELECT - Include negligible objects information (make it show a red X)
- Include environment information
- Under Alternate Data Streams
- Don't log streams smaller than 0 bytes
- Don't log ADS with the following names: CA_INOCULATEIT
Click the
Tweak Button and select in
green
- Under the Scanning Engine (Click on the + sign to expand)
- DESELECT Unload recognized processes & modules during scan (make it show a red X)
- Scan registry for all users instead of current user only
- Under the Cleaning Engine (Click on the + sign to expand)
- Always try to unload modules before deletion
- During Removal, unload Explorer and IE if necessary
- Let Windows remove files in use at next reboot
- Under the Log Files (Click on the + sign to expand)
- Include basic Ad-aware SE settings in logfile
- Include additional Ad-aware SE settings in logfile
- Include reference summarry in log file
- Include alternate data stream details in log file
Click on
Proceed to save the settings and close the program.
______________________________
If not already installed, download and install the
VX2 Cleaner 2.0 plugin from Lavasoft by following the instructions below.
Installing VX2 Cleaner 2.0
- Close Ad-Aware, if it is currently open.
- Download the VX2 Cleaner 2.0 Plug-in here.
- Install the VX2 Cleaner by clicking on vx2cleaner_inst.exe.
______________________________
If Spybot - S&D 1.4 is already installed on your system, skip to
Update Spybot - S&D before using it. Otherwise download Spybot - S&D from the following link:
Spybot - Search and Destroy
When you have downloaded the program, double click on the downloaded file to start the installation. Follow the default selections, pressing the Next button until you get to the
Select Additional Tasks screen.
Under
Permanent protection, make sure to
uncheck the following items for now:
- Use Internet Explorer Protection
- Use system settings Protection (TeaTimer)
Press the Next button and then the Install button to start the installation process. When the installation process is complete, make sure that
Run Teatimer is
unchecked.
Launch Spybot - S&D
If you told Spybot to launch when it was done installing, the program should now be open. Otherwise find the icon on your desktop and double-click on it. When you use Spybot - S&D for the first time, it will prompt you for certain tasks to complete. Skip all tasks for now by pressing the
Next button. Click on the button labeled
Start using this program to begin using Spybot - Search & Destroy.
Update Spybot - S&D before using it
Click on the
Search for Updates button. If there are available updates, they will be listed. Click on the
Download Updates button and Spybot - S&D will download the updates and install them.
______________________________
MySearch comes with WeatherBug, it's is questionable and mostly identified as adware bordering on spyware..
Alternatives and more info here:
WeatherBug Removal Instructions and Help
http://www.pchell.com/support/weatherbug.shtml
A good read on weatherbug here :
http://www.searchlores.org/weatherbug.htm
May I suggest you remove this application.
In order to avoid future problems with Weatherbug, make sure the program is not running before uninstalling it. If there is a WeatherBug icon in the system tray (in the lower right hand corner of the screen) you'll need to right-click on it and choose "Exit WeatherBug" or "Terminate Weatherbug".
Click on
Start,
Control Panel, click on
Add/Remove Programs
Look through the installed programs for the following items and remove them if present:
Logitech Desktop Manager
WeatherBug
My Search
During the uninstall process, you might be presented with several prompts to guide you through uninstalling the product. Read these carefully to make sure you are actually choosing to uninstall rather than keep the software.
______________________________
Reboot your computer in
Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
______________________________
Double-click the icon for
RegSearch.exe in the C:\reg folder to launch the program.
Enter
contextplus to search for and click "OK".
After completion Notepad will be opened with all the found instances of the string.
The resulting file is saved in the same folder location as RegSearch.exe. I will need that file later on.
______________________________
Run HijackThis, click on
None of the above, just start the program, click on
Scan. Put a
check in the box on the left side of the following items if still present.
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchtraffic.com/search.php3?l=protect1&term=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchtraffic.com/search.php3?l=protect1&term=
R3 - Default URLSearchHook is missing
O2 - BHO: C:\WINDOWS\adsldpbf.dll - {EEE7178C-BBC3-4153-9DDE-CD0E9AB1B5B6} - C:\WINDOWS\adsldpbf.dll
O3 - Toolbar: (no name) - {8B224779-3B0E-4FEA-8AE1-B66C20DD840F} - (no file)
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\system32\idemlog.exe
O4 - HKCU\..\Run: [AlexaToolbar] C:\WINDOWS\alt.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp.cab
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab
O16 - DPF: {E0051273-5988-41EC-A891-11D4A1BABF35} (KDreg class) - http://193.242.125.31/player/kdreg.cab
All O18 lines with \Logitech\Desktop Messenger
O20 - Winlogon Notify: browsela - C:\WINDOWS\system32\browsela.dll
Close
ALL windows and browsers
except HijackThis and click
Fix Checked.
______________________________
Open the smitRem Folder, then double-click the
RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named
smitfiles.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Using
Windows Explorer,
Search and
Delete these
Folders if listed:
C:\Program Files\Logitech\
DesktopMessenger
C:\Program Files\
AWS
C:\Program Files\
mysearch
C:\Program Files\
WareOut <--- if not yet done
Using
Windows Explorer,
Search and
Delete these
Files if listed:
C:\WINDOWS\
adsldpbf.dll
C:\WINDOWS\
alt.exe
C:\WINDOWS\system32\
kernels64.exe
C:\WINDOWS\system32\
idemlog.exe
C:\WINDOWS\system32\
browsela.dll
If you get an error when deleting a file,
right click on the file and check to see if the
read only attribute is checked. If it is
uncheck it and try again.
______________________________
Navigate to
C:\Windows\Prefetch
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Navigate to
C:\Windows\Temp
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Navigate to
C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click
Edit, click
Select All, press the DELETE key, and then click
Yes to confirm that you want to send all the items to the Recycle Bin.
Clean out your
Temporary Internet files. Procede like this:
- Quit Internet Explorer and quit any instances of Windows Explorer.
- Click Start, click Control Panel, and then double-click Internet Options.
- On the General tab, click Delete Files under Temporary Internet Files.
- In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
- On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
- Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
- Click OK.
Next Click
Start, click
Control Panel and then double-click
Display. Click on the
Desktop tab, then click the
Customize Desktop button. Click on the
Web tab. Under
Web Pages you should see an checked entry called
Security info or something similar. If it is there, select that entry and click the
Delete button. Click
Ok then
Apply and
Ok.
Empty the Recycle Bin by right-clicking the
Recycle Bin icon on your Desktop, and then clicking
Empty Recycle Bin.
______________________________
Close
ALL open Windows / Programs / Folders. Please start
Ewido Security Suite, and run a full scan.
- Click on Scanner
- Click on Settings
- Under How to scan all boxes should be checked
- Under Unwanted Software all boxes should be checked
- Under What to scan select Scan every file
- Click on Ok
- Click on Complete System Scan to start the scan process.
- Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says
Perform action on all infections, then choose clean and click Ok.
Once the scan has completed, there will be a button located on the bottom of the screen named
Save Report.
- Click Save Report button
- Save the report to your Desktop
Close Ewido.
______________________________
Start Ad-Aware SE
- Click on Add-ons
- Select the VX2 Cleaner plug-in and click Run Tool
- If your computer isn’t infected, click Close.
OR - If you computer is infected with VX2, a dialog box with text such as New VX2 variant found or VX2 variant 1 found will appear.
- Press Clean and a dialog box with text The first phase completed. Please reboot and perform a Smart Scan will appear.
- Reboot your computer
- Run Ad-Aware and Click on the Scan Now Button
- Choose Perform Full System Scan
- DESELECT Search for negligible risk entries, as negligible risk entries (MRU's) are not considered to be a threat. (make it show a red X)
Click Next to begin the scan. When the scan is completed, the Performing System Scan screen will change name to Scan Complete.
Click the Next Button to get to the Scanning Results Window where more information about the objects detected during the scan is available. Click the Critical Objects Tab. In general all of the items listed will be bad. To fix all the bad critical objects, right click on one of them, click the Select All entry in the pop-up menu to mark all entries. Click Next and then OK in the dialog box to confirm the removal.
Repeat this until the VX2 Cleaner reports
System clean. Press
Close to exit.
Run Ad-Aware one more time and perform a
Perform Full System Scan of your computer to make sure VX2 has been found and removed. Reboot in
Normal Mode
______________________________
Run Spybot - S&D
Click the button
Check for Problems
When Spybot is complete, it will be showing
RED entries,
BLACK entries and
GREEN entries in the window.
Make sure that there is a check mark beside all of the
RED entries
ONLY.
Choose
Fix Selected Problems and allow Spybot to fix the
RED entries.
If it has trouble removing any spyware, you will get a message window, asking if it would be ok to run Spybot - S&D on the next reboot before any other applications start running. You should reply
Yes to this. The next time you start Windows, Spybot will run automatically and fix any of the programs it could not fix previously.
At this point you will be presented with the list of found entries again, but now there will be large green checkmarks next to the items that Spybot - S&D was able to remove. The ones that are still checked but do not have the large green checkmark next to them will be fixed on the next reboot of windows. Reboot the PC.
______________________________
Please do an online scan with
Kaspersky Online Scanner
Click on
Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click
Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (If available otherwise Standard)
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK
- Now under select a target to scan select My Computer
- The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
- Copy and paste that information in your next post.
______________________________
Download WinPFind.zip to your Desktop or to your usual Download Folder.
http://www.bleepingcomputer.com/files/winpfind.php
Extract it to your
C:\ folder. This will create a folder called
WinPFind in the C:\ folder.
Open the
C:\WinPFind folder and double-click on
WinPFind.exe.
Click on
Configure Scan Options.
Remove all the checkmarks under
Folder Options on the left side by clicking the button
Remove All, uncheck
Run Addon's and click
Apply.
Click on the
Start Scan button and wait for it to finish.
Please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log file named
C:\WinPFind\WinPFind.txt. Please copy that log into your next reply.
______________________________
Please post :
- C:\fixwareout\report.txt
- c:\windelf.txt
- The results from the RegSearch.exe
- smitfiles.txt
- Ewido log
- Kaspersky results
- C:\WinPFind\WinPFind.txt
- a new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Kim