I have been getting two pop up windows ULWindowseek and ULWindowURl
My HJT log file is
Logfile of HijackThis v1.99.1
Scan saved at 6:23:05 PM, on 6/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1. Install ewido security suite
2. When installing, under "Additional Options" uncheck..
* Install background guard
* Install scan via context menu
3. Launch ewido, there should be an icon on your desktop, double-click it.
4. The program will now open to the main screen.
5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
6. You will need to update ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
Reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
Launch ewido:
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* You will be prompted to clean the first infection.
* Select "Perform action on all infections", then proceed.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.
+ Created on: 4:41:50 PM, 6/9/2006
+ Report-Checksum: C60C67CA
+ Scan result:
HKLM\SOFTWARE\Classes\WinRes.WindowsResources.1 -> Adware.CoolWebSearch : Cleaned with backup
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000004.MOZ -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000006.MOZ -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000006.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000006.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000006.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000006.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000008.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000008.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000008.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000008.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000008.MOZ -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00000010.MOZ -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00000016.MOZ -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000036.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000036.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000036.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000037.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000037.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000037.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000038.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000038.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000038.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000038.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000040.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000040.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000040.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000040.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000040.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000041.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000041.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000041.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000041.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000041.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000042.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000042.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000042.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000042.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000042.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000043.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000043.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000043.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000043.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000043.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00000044.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000044.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000044.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000044.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000044.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00000046.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000046.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000046.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000046.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000046.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000047.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000047.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000047.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000047.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000047.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000048.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000048.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000048.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000048.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000048.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000049.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000049.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000049.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000049.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000049.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00000055.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00000055.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00000055.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00000055.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00000055.MOZ -> TrackingCookie.Yieldmanager : Cleaned with backup
::Report End
hjt log
Logfile of HijackThis v1.99.1
Scan saved at 6:23:05 PM, on 6/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Run Killbox.exe
-> Choose Delete on Reboot
-> Click All Files option.
Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)
C:\WINDOWS\SYSTEM32\winrzf32.dll
Then go back to Killbox
-> go to File
-> choose Paste from Clipboard
-> Click the red-white Delete File option.
-> Click Yes to Delete on Reboot question
-> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
-> Restart your computer if Killbox won't do it.
(If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)
When comp is running after removin, Scan hijack this and check
I did not get any messages or error messages.. The system restarted as soon as i clicked the reboot option..
Everything went on well..
This is the log file i have..
Logfile of HijackThis v1.99.1
Scan saved at 9:53:03 PM, on 6/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)