This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Spybot is unable to fix 27 problems...

8 min read

This thread's last reply is from July 11, 2006, 9:57 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

rbanything
I have read and followed the instructions that were posted and cleaned as much as I could. I ran spybot and I still have 27 problems that were detected that spybot could not fix. Most are coolwwwsearch. Here is my spybot scan results:

ABetterInternet 2 entries
CoolWWWSearch.BadZoneMap 10 entries
CoolWWWSearch.Leftovers 1 entries
CoolWWWSearch.Mupdate 1 entries
CoolWWWSearch.Toolband 1 entries
CoolWWWSearch.wWinRes 1 entries
NeedEdware 1 entries
Smithfraud-C 10 entries

Here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 1:55:03 PM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\lxcrcoms.exe
C:\Program Files\TrojanHunter 4.5\THGuard.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8DD733A8-353A-4E93-AB85-93CA8DC96F6A} (ActivatorControl1 Class) - https://objects.aol.com/activator/en-us/Activator.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
rbanything
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:20:15 PM 7/3/2006

+ Scan result:



C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Crigger\Cookies\richard crigger@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\VANESSA\Cookies\vanessa@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Crigger\Cookies\richard [redacted][1].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Crigger\Cookies\richard crigger@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\VANESSA\Cookies\[redacted][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).


::Report end
rbanything
It looks like someone has used my usernames to create some sort of e-mail addresses.
rbanything
The file was okay. Nothing found.

I'm or are you in on him and I on I have a lot of these types of files in my Windows C. drive:
$NtUninstallKB911562$

I have no idea what these files mean. Can you tell me what these files are?

In the By the way, I believe that I have left out some important information about what I have done to try to remove coolwwwsearch. Spybot never included any coolsearch files in its scan results, until I located some information through a search on Google for how to remove cool wwwsearch. I followed some of their suggestions. I trusted them, like a dummy. Looking back, I believe that I in fact downloaded more spy ware from coolsearch because after I tried to fix my problem spy bot now had 27 entries that it could not fix. Whereas before I saw coolsearch showing up at the bottom as the files were scanned by spy bot but the scann did not select them as entries.

I downloaded cwshredder. I cannot remember what web site I went to.
Anyway, I really appreciate you taking your time to help me with my problems.
I got this link from Dell Computer's online forum.
I am assuming that you guys are doing this for the satisfaction of fighting maliciousness Internet users.
My computer is not giving me any problems, really. The homepage has changed on its own before, but it does not do it all the time.
I just really want to be in control of whom is spying on me.
rbanything
Do you know what this is: lxcr_device? I cannot find out anything about that process C:\WINDOWS\system32\lxcrcoms.exe
and service entry O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe
during searching...Is it some kind of Lexmark Device???

I deleted this entry. I was instructed to do this by someone in another forum. Now, my printer cannot communicate. I tried to install and uninstall. I rebooted, disconnected and reconnected all cables but it's still communicating. I tried all of the troubleshooting recommendations. My USB port is checked in printer properties. I believe that I have a device missing.

Is the USB port enabled on the computer?
To confirm that the USB port is enabled:

1 From the Windows Start menu, click Settings, and then click Control Panel.

2 Double-click the System icon, or click Performance and Maintenance, and then click the System icon.

3 Windows 2000 and Windows XP users only:

Click the Hardware tab.

Windows 98, Windows Me, Windows 2000, and Windows XP users:

Click Device Manager.

4 Click the plus sign (+) beside Universal Serial Bus Controller.

If you see USB Host Controller and USB Root Hub listed, the USB port is probably enabled.

I do not see USB host controller. I do see USB root hub listed.
rbanything
I fixed my problem on my own. Thanks for your help.

I went to Lexmark help. I followed the link and downloaded a driver for my printer. I had the driver already installed on my computer, and it prompted me to update my software. I updated and now my printer is working again.
rbanything
I still have 27 problems that were detected that spybot could not fix.

ABetterInternet 2 entries
CoolWWWSearch.BadZoneMap 10 entries
CoolWWWSearch.Leftovers 1 entries
CoolWWWSearch.Mupdate 1 entries
CoolWWWSearch.Toolband 1 entries
CoolWWWSearch.wWinRes 1 entries
NeedEdware 1 entries
Smithfraud-C 10 entries
rbanything
--- Report generated: 2006-07-09 13:24 ---

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\bestcounter.biz\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\skoobidoo.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\windupdates.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\my-internet.info\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\scoobidoo.com\*!=W=4

CoolWWWSearch.BadZoneMap: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com\*!=W=4

CoolWWWSearch.Leftovers: Trusted Site (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\greatplugin.com\*!=W=4

CoolWWWSearch.Mupdate: Trusted Site (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\masspass.com\*!=W=4

CoolWWWSearch.Toolband: Trusted Site (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\isprime.com\*!=W=4

CoolWWWSearch.WinRes: Trusted Site (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\offshoreclicks.com\*!=W=4

ABetterInternet: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net\*!=W=4

ABetterInternet: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\popuppers.com\*!=W=4

NeedEdware: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\neededware.com\*!=W=4

Smitfraud-C.: Settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\asdbiz.biz\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\cc20foreva.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fast-look.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fuck-fuck.org\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\letgohome.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\msnprotection.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\t34rulit.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\toprefsys.com\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\visitfriend.net\*!=W=4

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2995775916-592914421-636505945-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webpidor.biz\*!=W=4


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-06-15 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-07-07 Includes\Cookies.sbi (*)
2006-07-07 Includes\Dialer.sbi (*)
2006-07-07 Includes\Hijackers.sbi (*)
2006-07-07 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-07-07 Includes\Malware.sbi (*)
2006-07-07 Includes\PUPS.sbi (*)
2006-07-07 Includes\Revision.sbi (*)
2006-07-07 Includes\Security.sbi (*)
2006-07-07 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-07-07 Includes\Trojans.sbi (*)
rbanything
Incident Status Location

Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard191.dat
Adware:adware/fchelp Not disinfected c:\program files\EQAdvice
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Richard Crigger\Cookies\richard crigger@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Richard Crigger\Cookies\richard [redacted][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\VANESSA\Cookies\vanessa@atwola[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\VANESSA\Cookies\[redacted][1].txt
rbanything
I believe that I was fooled into installing something malicious when I tried to search for a way to remove cool WWW search. I did a search on google.com for a way to remove cool WW W. search. I tried to download CW shredder and nothing happened when I hit run. I believe that I unknowingly installed more spy ware.

After I tried to fix by following the instructions that I found from the search, I ran another spy bot scan and and 27 entries then showed up. Before, spy bot did not isolate the cool WW W. search. I only saw cool WW W search files showing up as the scan was running in spy bot. That is the reason that I tried to remove it in the first place; I had seen cool www search showing up along the bottom of my screen during the scan with spy bot.
My homepage changed on me on its own probably about three or four times. One time when I was trying to access my pictures on sprint.com, I was totally blocked. I typed in the correct web address and hit go on over and over. Some search page kept popping up. This has not happened to me in at least 10 days or so. I was only blocked on that one occasion.[/img]
rbanything
I did what you said...............It tries to open, but it just flashes.........it flashes but will not stay on the screen............
rbanything
I saved in Notepad, but there was no option to save as all files. I saved it as an RTF file.
I believe that I saved it correctly because a shortcut with an icon was created on my desktop as peek.bat. :cry: That part worked.
When I try to open it by selecting open or double-clicking the icon on my desktop it tries to open. I see a small window with a black background and text appearing quickly and disappearing. The window flashes as if it's being blocked. It's just as if there is a pop-up blocker against this window.
rbanything
I cannot open it but I can click edit and this appears:


{\rtf1\ansi\ansicpg1252\deff0\deflang1033{\fonttbl{\f0\froman\fcharset0 Times New Roman;}{\f1\fswiss\fcharset0 Arial;}}
{\*\generator Msftedit 5.41.15.1507;}\viewkind4\uc1\pard\sb100\sa100\f0\fs24 regedit /e peek.txt \line "HKEY_USERS\\S-1-5-21-2995775916-592914421-636505945-1005\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\bestcounter.biz" \line\line notepad peek.txt\par
\pard\f1\fs20\par
}
rbanything
May I send you this screenshot that I saved with word?

I captured the screen shot during an ad ware SE scan. When I double clicked on the shortcut that I created on my desktop for peek.bat, I managed to quickly take a snapshot of the screen
because my system was running slower due to the scan. The window still wouldn't stay on the screen, but I managed to capture it when it flashed.

It says can not find the path specified.
It has about 13 lines. I want to send this to you as an attachment somehow so that you can see for yourself what it says.
It has a black background with white writing. I believe it says not recognized as an internal or external command. And then it says something about a batch file.
rbanything
I went back and saved to notepad. I was previously trying to save peek.bat with WordPad.

How do I paste the results? The screen that I create with the peek.bat notepad shortcut that I put on my desktop(the one with the black background)-- I can not copy and paste it????

How do I send you attachments? If I can send you attachments, I can let you see what my screen is displaying with snapshots.[/img]