Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Drive Cleaner 2006


  • This topic is locked This topic is locked
14 replies to this topic

#1 alshaheen002

alshaheen002

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 10 August 2007 - 03:55 PM

I had a lot of problems with viruses and adware and spyware recently and I've seemed to get rid of everything except for Drive Cleaner 2006. Spybot records two entries but cannot fix them. I've done everything that you guys said to do before posting the HijackThis log, but it doesn't work so here is the log. Thanks for the help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:53:21 PM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\TV EXPERT 350\T7Ir9x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {101E9DBD-37CD-4415-9A2F-25A5AEFE322C} - C:\Program Files\MSN\mewod58441.dll (file missing)
O2 - BHO: 0 - {448FC4EE-67E4-4F97-968C-609C73EDDDD8} - C:\Program Files\Windows NT\qujawir515.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {80FF9132-9453-42A4-AEED-7CC338873E5F} - C:\Program Files\MSN\mewod83122.dll (file missing)
O2 - BHO: (no name) - {8247E968-8233-44A7-9557-6FA0851C16F5} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: (no name) - {8B93ED40-C973-4EFD-BF48-731204376B1A} - C:\WINDOWS\system32\geebx.dll (file missing)
O2 - BHO: (no name) - {9018B577-C93D-4ABB-8CA3-2E7CB11F1B35} - C:\WINDOWS\system32\jkkli.dll (file missing)
O2 - BHO: support - {991EF04C-93CF-469b-A2BE-CC1B3347566F} - C:\Program Files\BHO\plugin.dll (file missing)
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O2 - BHO: (no name) - {FC097A5C-6BD9-4CF4-B55C-774E3445954D} - C:\WINDOWS\system32\mljjk.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [poolsv] "C:\WINDOWS\poolsv.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\jhcaciwv.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [qrww] C:\PROGRA~1\COMMON~1\qrww\qrwwm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: DvdEncoderTvTray.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TV EXPERT 350 Remote control.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1106534118374
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax2622.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6701 bytes

BC AdBot (Login to Remove)

 


#2 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 11 August 2007 - 02:40 AM

Hello alshaheen002,

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
More information with a screenshot, can be found here.

Please download Combofix to your desktop.
Doubleclick combo.exe to launch the application.
Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
Posted Image

#3 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 11 August 2007 - 12:00 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:46 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\TV EXPERT 350\T7Ir9x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {101E9DBD-37CD-4415-9A2F-25A5AEFE322C} - C:\Program Files\MSN\mewod58441.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {80FF9132-9453-42A4-AEED-7CC338873E5F} - C:\Program Files\MSN\mewod83122.dll (file missing)
O2 - BHO: (no name) - {8247E968-8233-44A7-9557-6FA0851C16F5} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: (no name) - {8B93ED40-C973-4EFD-BF48-731204376B1A} - C:\WINDOWS\system32\geebx.dll (file missing)
O2 - BHO: (no name) - {9018B577-C93D-4ABB-8CA3-2E7CB11F1B35} - C:\WINDOWS\system32\jkkli.dll (file missing)
O2 - BHO: support - {991EF04C-93CF-469b-A2BE-CC1B3347566F} - C:\Program Files\BHO\plugin.dll (file missing)
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O2 - BHO: (no name) - {FC097A5C-6BD9-4CF4-B55C-774E3445954D} - C:\WINDOWS\system32\mljjk.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [qrww] C:\PROGRA~1\COMMON~1\qrww\qrwwm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: DvdEncoderTvTray.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TV EXPERT 350 Remote control.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1106534118374
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax2622.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6424 bytes









UNINSTALL LIST


Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 7.0.9
AdsGone Popup Killer Spyware Blocker by A1Tech.com
AOL Uninstaller (Choose which Products to Remove)
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
Creative DVD Audio Plugin for Audigy Series
Digital Locker Assistant
DVD Encoder
Easy CD & DVD Creator 6
GdiplusUpgrade
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.0 (KB932471)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
HP Memories Disc
HP Update
InterVideo Installer
InterVideo WinDVD 5
InterVideo WinRip
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment Standard Edition v1.3.1_04
Java™ 6 Update 2
Java™ SE Runtime Environment 6 Update 1
LiveUpdate 1.6 (Symantec Corporation)
Marvell Miniport Driver
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
Microsoft XML Parser and SDK
Mozilla Firefox (2.0.0.6)
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 6.0 Parser
Norton AntiVirus Corporate Edition
Photosmart 140,240,7200,7600,7700,7900 Series
PowerVCR II
QuickTime
RealArcade
RealPlayer
Realtek AC'97 Audio
Rhapsody Player Engine
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Sonic Foundry Sound Forge 5.0
Spybot - Search & Destroy 1.4
True Sword 4
TV EXPERT 350
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB925876)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Winamp (remove only)
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
ZoneAlarm











LOG





ComboFix 07-08-09.3 - "Albert" 2007-08-11 12:36:28.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.584 [GMT -4:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Albert\APPLIC~1.\racle~1
C:\DOCUME~1\Albert\MYDOCU~1.\smbols~1
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\mbols~1
C:\Program Files\mcroso~1
C:\Program Files\poolsv
C:\Program Files\poolsv\k11u72.exe
C:\Program Files\poolsv\svhost.exe
C:\Program Files\poolsv\YazzleBundle-1549.exe
C:\Program Files\stem~1
C:\Program Files\Windows NT\qujawir.dll
C:\Program Files\Windows NT\qujawir515.dll
C:\Program Files\Windows NT\qujawir548.dll
C:\Program Files\ystem~1
C:\temp\0b9
C:\temp\0b9\tmpTF.log
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\temp\iee
C:\temp\iee\tmpZTF.log
C:\WINDOWS\b103.exe
C:\WINDOWS\b104.exe
C:\WINDOWS\b136.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\icroso~1
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\fnts~1
C:\WINDOWS\system32\o09PrEz
C:\WINDOWS\system32\S1
C:\WINDOWS\system32\S2
C:\WINDOWS\system32\S6
C:\WINDOWS\system32\S7
C:\WINDOWS\system32\version69ie7fix.dll
C:\WINDOWS\system32\win
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\Z1
C:\WINDOWS\system32\Z11
C:\WINDOWS\system32\Z3
C:\WINDOWS\system32\Z5
C:\WINDOWS\system32\Z7
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_CMDSERVICE
-------\LEGACY_FOPN


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-11 12:35 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 23:11 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-08-09 23:09 <DIR> d-------- C:\Program Files\MSBuild
2007-08-09 23:01 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-08-09 23:00 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-08-09 22:58 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-08-09 22:57 <DIR> d-------- C:\83f9484bcc42eff283c07edd
2007-08-09 22:55 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2007-08-09 22:48 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-08-09 22:26 36,352 --------- C:\WINDOWS\system32\tsgqec.dll
2007-08-09 22:26 288,768 --------- C:\WINDOWS\system32\rhttpaa.dll
2007-08-09 22:26 116,736 --------- C:\WINDOWS\system32\aaclient.dll
2007-08-09 15:47 <DIR> d-------- C:\Program Files\Lavasoft
2007-08-09 15:47 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-08-09 15:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-08-09 15:16 <DIR> d-------- C:\hijackthis
2007-08-07 17:26 <DIR> d-------- C:\WINDOWS\pss
2007-08-06 21:03 <DIR> d-------- C:\DOCUME~1\Albert\APPLIC~1\.TrueSwordSettings
2007-08-06 20:48 <DIR> d-------- C:\WINDOWS\system32\backuped
2007-08-06 20:48 <DIR> d-------- C:\Program Files\True Sword 4
2007-08-06 20:48 <DIR> d-------- C:\DOCUME~1\Albert\APPLIC~1\True Sword
2007-08-06 20:44 <DIR> d-------- C:\Program Files\Digital Locker Assistant
2007-08-06 16:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-06 16:39 75,248 --a------ C:\WINDOWS\zllsputility.exe
2007-08-06 16:39 4,212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2007-08-06 16:39 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-08-06 16:38 75,932 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-08-06 16:38 74,396 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-08-06 16:38 3,242,016 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-06 16:37 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys
2007-08-06 16:35 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-08-06 16:35 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-08-06 16:34 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-08-02 20:51 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-25 22:51 <DIR> d-------- C:\VundoFix Backups
2007-07-25 21:26 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-07-25 21:22 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Help


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-11 12:46 39020 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-11 12:43 --------- d-------- C:\Program Files\Windows NT
2007-08-06 21:54 --------- d-------- C:\Program Files\Common Files\qrww
2007-08-06 21:03 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\.TrueSwordSettings
2007-07-19 10:14 --------- d-------- C:\Program Files\Google
2007-07-19 10:13 --------- d-------- C:\Program Files\Winamp
2007-07-16 23:32 --------- d-------- C:\DOCUME~1\Albert\APPLIC~1\Roxio
2007-07-16 22:42 --------- d-------- C:\Program Files\NavNT
2007-06-20 23:00 24944 --a------ C:\DOCUME~1\Albert\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-05-16 11:12 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 -----c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 -----c--- C:\WINDOWS\system32\dllcache\msoe.dll
2006-04-24 16:08 774144 --a--c--- C:\Program Files\RngInterstitial.dll
2005-07-29 20:24:26 472 --sha-r C:\WINDOWS\QVM\kpg.vbs


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{101E9DBD-37CD-4415-9A2F-25A5AEFE322C}]
C:\Program Files\MSN\mewod58441.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{80FF9132-9453-42A4-AEED-7CC338873E5F}]
C:\Program Files\MSN\mewod83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8247E968-8233-44A7-9557-6FA0851C16F5}]
C:\WINDOWS\system32\awvtt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B93ED40-C973-4EFD-BF48-731204376B1A}]
C:\WINDOWS\system32\geebx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9018B577-C93D-4ABB-8CA3-2E7CB11F1B35}]
C:\WINDOWS\system32\jkkli.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{991EF04C-93CF-469b-A2BE-CC1B3347566F}]
C:\Program Files\BHO\plugin.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC097A5C-6BD9-4CF4-B55C-774E3445954D}]
C:\WINDOWS\system32\mljjk.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-22 22:10]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 08:59]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2004-06-03 04:50]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-05-07 01:56]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2003-05-22 08:55]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 15:05]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 16:45]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 12:59]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"qrww"="C:\PROGRA~1\COMMON~1\qrww\qrwwm.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]

R1 cdudf_xp;cdudf_xp;C:\WINDOWS\system32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\system32\drivers\pwd_2k.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINDOWS\system32\drivers\UdfReadr_xp.sys
R2 NAVAPEL;NAVAPEL;\??\C:\Program Files\NavNT\NAVAPEL.SYS
R3 dvd_2K;dvd_2K;C:\WINDOWS\system32\drivers\dvd_2K.sys
R3 NAVAP;NAVAP;\??\C:\Program Files\NavNT\NAVAP.sys
R3 Point32;Microsoft IntelliPoint Filter Driver;C:\WINDOWS\system32\DRIVERS\point32.sys
R3 Tunx00;TV EXPERT 350 Capture;C:\WINDOWS\system32\DRIVERS\Tunx00.sys
R3 TxTuner;TV EXPERT 350 TV Tuner;C:\WINDOWS\system32\DRIVERS\TxTuner.sys
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 mmc_2K;mmc_2K;C:\WINDOWS\system32\drivers\mmc_2K.sys
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"


Contents of the 'Scheduled Tasks' folder
2007-07-26 00:24:00 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#7700#MY37P121MBJY.job - C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
2007-08-11 02:47:04 C:\WINDOWS\Tasks\HP Usg Daily.job
2007-08-09 18:48:45 C:\WINDOWS\Tasks\WebReg 20070809144844.job - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 12:48:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-11 12:53:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-11 12:53

--- E O F ---

#4 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 11 August 2007 - 02:06 PM

Hello alshaheen002,

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only

Please download OTMoveIt by Oldtimer and save it to your desktop.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {101E9DBD-37CD-4415-9A2F-25A5AEFE322C} - C:\Program Files\MSN\mewod58441.dll (file missing)
O2 - BHO: (no name) - {80FF9132-9453-42A4-AEED-7CC338873E5F} - C:\Program Files\MSN\mewod83122.dll (file missing)
O2 - BHO: (no name) - {8247E968-8233-44A7-9557-6FA0851C16F5} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: (no name) - {8B93ED40-C973-4EFD-BF48-731204376B1A} - C:\WINDOWS\system32\geebx.dll (file missing)
O2 - BHO: (no name) - {9018B577-C93D-4ABB-8CA3-2E7CB11F1B35} - C:\WINDOWS\system32\jkkli.dll (file missing)
O2 - BHO: support - {991EF04C-93CF-469b-A2BE-CC1B3347566F} - C:\Program Files\BHO\plugin.dll (file missing)
O2 - BHO: (no name) - {FC097A5C-6BD9-4CF4-B55C-774E3445954D} - C:\WINDOWS\system32\mljjk.dll (file missing)
O4 - HKCU\..\Run: [qrww] C:\PROGRA~1\COMMON~1\qrww\qrwwm.exe


Now close all windows other than HiJackThis, then click Fix Checked. Close HijackThis.

Run ATF Cleaner:Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Run OTMoveIt:
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system32\spmsg2.dll
C:\83f9484bcc42eff283c07edd
C:\VundoFix Backups
C:\Program Files\Common Files\qrww
C:\WINDOWS\QVM\kpg.vbs
  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Close OTMoveIt
(If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.)
Click the red Moveit! button.
Please "Copy" the results from the "Results" window (to the right) and then "Paste" them into your next reply on the forum.

Reboot into Normal Mode.

In your next reply please include the following:
  • A new Hijackthis log.
  • The OTMoveIt log.

Posted Image

#5 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 12 August 2007 - 06:36 PM

File/Folder C:\WINDOWS\system32\spmsg2.dll not found.
File/Folder C:\83f9484bcc42eff283c07edd not found.
File/Folder C:\VundoFix Backups not found.
File/Folder C:\Program Files\Common Files\qrww not found.
File/Folder C:\WINDOWS\QVM\kpg.vbs not found.

Created on 08/12/2007 19:28:23




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:30:14 PM, on 8/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\TV EXPERT 350\T7Ir9x.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: DvdEncoderTvTray.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TV EXPERT 350 Remote control.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1106534118374
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax2622.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5676 bytes

#6 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 12 August 2007 - 10:53 PM

Hello alshaheen002,

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

Now close all windows other than HiJackThis, then click Fix Checked. Close HijackThis.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

Posted Image

#7 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 13 August 2007 - 08:29 AM

Incident Status Location

Potentially unwanted tool:application/bestoffer Not disinfected c:\windows\smdat32m.sys
Adware:adware/commad Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Adware:adware/instafinder Not disinfected Windows Registry
Potentially unwanted tool:application/myway Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.go.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt[.statcounter.com/]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Albert\Desktop\Virus\ComboFix.exe[nircmd.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Albert\Desktop\Virus\VirtumundoBeGone\VirtumundoBeGone.exe
Spyware:Cookie/Sandboxer Not disinfected C:\Program Files\True Sword 4\backuped\205\albert@0[3].txt
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\True Sword 4\backuped\206\albert@247realmedia[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Program Files\True Sword 4\backuped\207\albert@2o7[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Program Files\True Sword 4\backuped\210\albert@ads.pointroll[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Program Files\True Sword 4\backuped\211\albert@advertising[2].txt
Spyware:Cookie/nCase Not disinfected C:\Program Files\True Sword 4\backuped\213\albert@banners.searchingbooth[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Program Files\True Sword 4\backuped\214\albert@bravenet[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Program Files\True Sword 4\backuped\215\albert@casalemedia[2].txt
Spyware:Cookie/Kazaa Networks Not disinfected C:\Program Files\True Sword 4\backuped\218\albert@desktop.kazaa[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\True Sword 4\backuped\219\albert@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Program Files\True Sword 4\backuped\221\albert@fastclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Program Files\True Sword 4\backuped\222\albert@findwhat[2].txt
Spyware:Cookie/Humanclick Not disinfected C:\Program Files\True Sword 4\backuped\224\albert@hc2.humanclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Program Files\True Sword 4\backuped\228\albert@mediaplex[1].txt
Spyware:Cookie/Overture Not disinfected C:\Program Files\True Sword 4\backuped\233\albert@overture[1].txt
Spyware:Cookie/Overture Not disinfected C:\Program Files\True Sword 4\backuped\234\albert@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Program Files\True Sword 4\backuped\236\albert@questionmarket[1].txt
Potentially unwanted tool:Application/MyWay Not disinfected C:\Program Files\True Sword 4\backuped\24\mysearch.cab
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\True Sword 4\backuped\240\albert@realmedia[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Program Files\True Sword 4\backuped\247\albert@server.iad.liveperson[1].txt
Spyware:Cookie/Tickle Not disinfected C:\Program Files\True Sword 4\backuped\251\albert@tickle[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Program Files\True Sword 4\backuped\252\albert@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\True Sword 4\backuped\254\albert@tribalfusion[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Program Files\True Sword 4\backuped\255\albert@winantispyware[1].txt
Adware:Adware/Yazzle Not disinfected C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir[++\Yazzle1549OinAdmin.exe]
Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\Windows NT\qujawir.dll.vir
Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\Windows NT\qujawir515.dll.vir
Virus:Generic Malware Disinfected C:\QooBox\Quarantine\C\Program Files\Windows NT\qujawir548.dll.vir
Adware:Adware/Sqwire Not disinfected C:\QooBox\Quarantine\C\WINDOWS\b103.exe.vir
Virus:Generic Trojan Disinfected C:\QooBox\Quarantine\C\WINDOWS\b104.exe.vir
Adware:Adware/DeluxeComunications Not disinfected C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir
Adware:Adware/ActiveSearch Not disinfected C:\QooBox\Quarantine\C\WINDOWS\b138.exe.vir
Adware:Adware/Mirar Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\WinNB58.dll.vir
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe
Adware:Adware/CommAd Not disinfected C:\_OTMoveIt\MovedFiles\WINDOWS\QVM\kpg.vbs

#8 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 15 August 2007 - 12:27 AM

Hello alshaheen002,

Open notepad and copy (Ctrl C) and paste (Ctrl V) the following text in the quote:

REGEDIT4

[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}]

Save it to your desktop as fix133.reg and as Type "All files"
Double click on fix133.reg and allow when prompted to let it merge with the registry.

Download and install AVG Anti-Spyware v7.5.
  • After download, double click on the file to launch the install process.
  • Choose a language, click "OK" and then click "Next".
  • Read the "License Agreement" and click "I Agree".
  • Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
  • After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
  • Connect to the Internet, go back to AVG Anti-Spyware, select the "Update" button and click "Start update". Wait until you see the "Update successful" message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
  • Exit AVG Anti-Spyware when done - DO NOT perform a scan yet.
Reboot your computer in "SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". (Note: When run in safe mode, sometimes the GUI is larger than the screen and the buttons at the bottom are partly or completely hidden, making them unaccessible for doing a scan. If this is the case, press the WINKEY + M key to "Minimize" the AVG display. Then right-click on AVG in the Task Bar and select "Maximize". If that does not help, then you may have to run your scan in normal mode and advise your helper afterwards.)

Scan with AVG Anti-Spyware as follows:
  • Click on the "Scanner" button and choose the "Settings" tab.
  • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
  • Under "How to Scan?", "Possibly unwanted software", and What to Scan?" leave all the default settings.
  • Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
  • Click the "Scan" tab to return to scanning options.
  • Click "Complete System Scan" to start.
  • When the scan has finished, it should automatically be set to Quarantine--if not click on Recommended Action and set it there.
  • You will also be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button.
  • Click on "Save Report" to view all completed scans. Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
  • Exit AVG Anti-Spyware when done, reboot normally and submit the log report in your next response.
Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. Doing so can hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection.

AVG Anti-Spyware is free for 30 days and all the extensions of the full version will be activated. After the 30 day trial, active protection extensions will be deactivated and the program will turn into a feature-limited freeware version that you can can continue to use as an on-demand scanner or you may purchase a license to use the full version.
Posted Image

#9 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 15 August 2007 - 08:07 PM

Alright I did what you said but I couldn't get my computer to prompt the screen to select safe mode so I ran the scan in normal mode as your directions said to do if I couldn't start up safe mode. I normally run Norton Anti-Virus Corporate Edition. Will AVG interfere with it or vice versa?

Here's the report thanks:


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:51:57 PM 8/15/2007

+ Scan result:



C:\QooBox\Quarantine\C\WINDOWS\b138.exe.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000880.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\poolsv\YazzleBundle-1549.exe.vir -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000886.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000878.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\_OTMoveIt\MovedFiles\Program Files\Common Files\qrww\qrwwd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b103.exe.vir -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000877.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir -> Downloader.VB.awj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000884.exe -> Downloader.VB.awj : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir -> Dropper.Agent.bfr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000879.exe -> Dropper.Agent.bfr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000881.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000882.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{F21220CB-3AAA-488F-B8F7-3C2B162B619C}\RP6\A0000883.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\Program Files\True Sword 4\backuped\206\albert@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.157:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.194:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.201:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.54:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@pandasoftware.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\True Sword 4\backuped\207\albert@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\True Sword 4\backuped\229\albert@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.79:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.82:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.46:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
C:\Program Files\True Sword 4\backuped\208\albert@adengage[1].txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.216:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.217:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.218:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.219:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.220:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.17:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.18:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.19:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.20:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.21:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\True Sword 4\backuped\211\albert@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.41:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.80:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.81:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.83:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.84:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.57:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.58:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.63:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.64:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\True Sword 4\backuped\215\albert@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.44:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\True Sword 4\backuped\250\albert@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.30:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\True Sword 4\backuped\219\albert@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\True Sword 4\backuped\209\albert@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.66:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.67:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.68:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.69:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.70:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.76:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\True Sword 4\backuped\221\albert@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\True Sword 4\backuped\222\albert@findwhat[2].txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.51:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
C:\Program Files\True Sword 4\backuped\247\albert@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.28:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.29:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\True Sword 4\backuped\228\albert@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\True Sword 4\backuped\233\albert@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Program Files\True Sword 4\backuped\234\albert@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.9:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.102:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.105:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.107:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.108:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\True Sword 4\backuped\210\albert@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\True Sword 4\backuped\235\albert@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.96:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.97:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\True Sword 4\backuped\236\albert@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\True Sword 4\backuped\239\albert@realguide.real[1].txt -> TrackingCookie.Real : Cleaned.
C:\Program Files\True Sword 4\backuped\243\albert@real[1].txt -> TrackingCookie.Real : Cleaned.
:mozilla.103:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.104:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.106:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\True Sword 4\backuped\240\albert@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\True Sword 4\backuped\245\albert@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Program Files\True Sword 4\backuped\220\albert@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\True Sword 4\backuped\213\albert@banners.searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned.
:mozilla.117:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.118:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.119:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.120:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.121:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.122:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.123:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.124:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.125:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.126:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.127:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.128:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Program Files\True Sword 4\backuped\249\albert@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.85:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.153:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.154:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.155:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.156:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.210:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.211:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.212:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.213:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.214:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.215:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\True Sword 4\backuped\252\albert@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.50:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\True Sword 4\backuped\254\albert@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.71:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.72:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.73:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.74:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.77:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Albert\Cookies\albert@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.39:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.40:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.42:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.43:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.45:C:\Documents and Settings\Albert\Application Data\Mozilla\Firefox\Profiles\8cbtjs4x.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\_OTMoveIt\MovedFiles\WINDOWS\QVM\kpg.vbs -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

#10 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 15 August 2007 - 11:53 PM

Hello alshaheen002,

AVG should not interfere since it isn't technically an anti-virus program, just an on demand scanner.

Please post back with a new HijackThis log and an update on how your computer is running.
Posted Image

#11 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 16 August 2007 - 01:53 PM

The computer seems to be running fine. I just completed a spybot scan and the Disk Cleaner 2006 was gone. Whenever I run one of these scans whether its spybot, true sword or whatever, they always come back finding a few tracking cookies or adware. Is that normal? Also as you are aware, during the AVG scan some malware was found. I figured after all the different bleep I used to clean the computer that would all be taken care of. Is there any cause for concern?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:36:44 PM, on 8/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\TV EXPERT 350\T7Ir9x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdsGone 2004.lnk = C:\Program Files\AdsGone\adsgone.exe
O4 - Global Startup: DvdEncoderTvTray.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TV EXPERT 350 Remote control.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1106534118374
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.com/client/msnmusax2622.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5820 bytes

#12 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 17 August 2007 - 12:02 AM

Hello alshaheen002,

Whenever I run one of these scans whether its spybot, true sword or whatever, they always come back finding a few tracking cookies or adware. Is that normal?

Yes, this is completely normal, almost all websites have some form of tracking cookie or another.

Also as you are aware, during the AVG scan some malware was found. I figured after all the different bleep I used to clean the computer that would all be taken care of.

It just found malware that was already quarantined from OTMoveIt and True Sword, nothing to be worried about.

Please open up OTMoveIt and click on the "CleanUp" option.

Congratulations, your computer is now clean of malware![/b]

Next, let's clean your restore points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. Turn off System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Restart your computer.

3. Turn ON System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
[/list]System Restore will now be active again.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources
  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

here are some additional utilities that will enhance your safety
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

Posted Image

#13 alshaheen002

alshaheen002
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:05:39 PM

Posted 17 August 2007 - 04:30 PM

Thank you very much for your help the computer is running great so far.

AL

#14 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 18 August 2007 - 02:04 AM

I'm glad to hear it :thumbsup:
Posted Image

#15 __RiP_ChAiN_

__RiP_ChAiN_

    Eh, whatever goes here.


  • Members
  • 1,592 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Omaha, Nebraska U.S.A
  • Local time:03:39 PM

Posted 06 September 2007 - 09:06 AM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users