Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

please help me!


  • This topic is locked This topic is locked
21 replies to this topic

#1 mister sinister

mister sinister

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 26 July 2005 - 08:51 PM

hi i am new here....i am getting so much damn popups....i close about 20 a minute....here is my hijack this log please help me out....


Logfile of HijackThis v1.99.1
Scan saved at 6:36:43 PM, on 7/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\Smtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\eDonkey2000\eDonkey2000.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
c:\windows\system32\yvboveu.exe
C:\WINDOWS\System32\winis.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\tcmedump.exe
C:\WINDOWS\System32\pbpbab.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\system\ikvocmkeoq.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\synemui.exe
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\ebre\rhrc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {44761085-8B4B-F5CD-6391-810D80FBF1EA} - C:\WINDOWS\System32\rleqbm.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [slrdgte] C:\WINDOWS\System32\octxhnj.exe
O4 - HKLM\..\Run: [dmyuilvd] C:\WINDOWS\System32\tidwnvk.exe
O4 - HKLM\..\Run: [zgscgk] C:\WINDOWS\System32\ckcyhz.exe
O4 - HKLM\..\Run: [jyjq] C:\WINDOWS\System32\waua.exe
O4 - HKLM\..\Run: [ubovd] C:\WINDOWS\System32\nkxir.exe
O4 - HKLM\..\Run: [pjlmzq] C:\WINDOWS\System32\ischx.exe
O4 - HKLM\..\Run: [utincchz] C:\WINDOWS\System32\jjqx.exe
O4 - HKLM\..\Run: [jlcqqu] C:\WINDOWS\System32\yzcpabw.exe
O4 - HKLM\..\Run: [qhlvha] C:\WINDOWS\System32\phudjvf.exe
O4 - HKLM\..\Run: [qmkif] C:\WINDOWS\System32\dglk.exe
O4 - HKLM\..\Run: [azpy] C:\WINDOWS\System32\gvat.exe
O4 - HKLM\..\Run: [arjzpy] C:\WINDOWS\System32\dqqxna.exe
O4 - HKLM\..\Run: [zgqfsf] C:\WINDOWS\System32\soohynk.exe
O4 - HKLM\..\Run: [yddf] C:\WINDOWS\System32\gxvyo.exe
O4 - HKLM\..\Run: [lvnw] C:\WINDOWS\System32\cknh.exe
O4 - HKLM\..\Run: [mreerbbu] C:\WINDOWS\System32\goma.exe
O4 - HKLM\..\Run: [kniutan] C:\WINDOWS\System32\gaano.exe
O4 - HKLM\..\Run: [afjc] C:\WINDOWS\System32\atnqm.exe
O4 - HKLM\..\Run: [kymmtwai] C:\WINDOWS\System32\jbcmub.exe
O4 - HKLM\..\Run: [vwou] C:\WINDOWS\System32\fkwdg.exe
O4 - HKLM\..\Run: [pzwzookf] C:\WINDOWS\System32\ruljw.exe
O4 - HKLM\..\Run: [uqmxz] C:\WINDOWS\System32\llflg.exe
O4 - HKLM\..\Run: [udqdsx] C:\WINDOWS\System32\bcjhaz.exe
O4 - HKLM\..\Run: [cqkl] C:\WINDOWS\System32\gcgbrpx.exe
O4 - HKLM\..\Run: [gwumzbd] C:\WINDOWS\System32\xzbrwzx.exe
O4 - HKLM\..\Run: [gnjo] C:\WINDOWS\System32\qrzwfws.exe
O4 - HKLM\..\Run: [xzrazldp] C:\WINDOWS\System32\hizdyf.exe
O4 - HKLM\..\Run: [qeeqlnbw] C:\WINDOWS\System32\lpmuw.exe
O4 - HKLM\..\Run: [wjqqyrun] C:\WINDOWS\System32\wwzo.exe
O4 - HKLM\..\Run: [aupgmgml] C:\WINDOWS\System32\iypuft.exe
O4 - HKLM\..\Run: [xkkxpn] C:\WINDOWS\System32\scwc.exe
O4 - HKLM\..\Run: [bagakqs] C:\WINDOWS\System32\wplr.exe
O4 - HKLM\..\Run: [irxyhnu] C:\WINDOWS\System32\vmyks.exe
O4 - HKLM\..\Run: [uyfsvlu] C:\WINDOWS\System32\krevq.exe
O4 - HKLM\..\Run: [lhngqjf] C:\WINDOWS\System32\afomsiyz.exe
O4 - HKLM\..\Run: [tbgk] C:\WINDOWS\System32\mllfy.exe
O4 - HKLM\..\Run: [vlmbhex] C:\WINDOWS\System32\rwwog.exe
O4 - HKLM\..\Run: [rnzdjai] C:\WINDOWS\System32\lafi.exe
O4 - HKLM\..\Run: [iqdp] C:\WINDOWS\System32\ferseif.exe
O4 - HKLM\..\Run: [hzvd] C:\WINDOWS\System32\wiusgg.exe
O4 - HKLM\..\Run: [pytvufw] C:\WINDOWS\System32\xehb.exe
O4 - HKLM\..\Run: [wzjlqxa] C:\WINDOWS\System32\zdzny.exe
O4 - HKLM\..\Run: [mvbr] C:\WINDOWS\System32\ezgwflvs.exe
O4 - HKLM\..\Run: [bwaipl] C:\WINDOWS\System32\mpuvy.exe
O4 - HKLM\..\Run: [emhtc] C:\WINDOWS\System32\ikqberyo.exe
O4 - HKLM\..\Run: [psar] C:\WINDOWS\System32\dpuo.exe
O4 - HKLM\..\Run: [hmbh] C:\WINDOWS\System32\vnnhtmvk.exe
O4 - HKLM\..\Run: [gcyued] C:\WINDOWS\System32\lrxbku.exe
O4 - HKLM\..\Run: [xyzf] C:\WINDOWS\System32\crvs.exe
O4 - HKLM\..\Run: [tzrdm] C:\WINDOWS\System32\qhbjyx.exe
O4 - HKLM\..\Run: [coul] C:\WINDOWS\System32\thwqhazt.exe
O4 - HKLM\..\Run: [eaniiem] C:\WINDOWS\System32\vouas.exe
O4 - HKLM\..\Run: [esrzb] C:\WINDOWS\System32\jvcdc.exe
O4 - HKLM\..\Run: [hwcg] C:\WINDOWS\System32\elwll.exe
O4 - HKLM\..\Run: [oclza] C:\WINDOWS\System32\tfadqlo.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IE Runtimes] winis.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [Services] C:\Documents and Settings\Administrator\socks.exe
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitetis32.exe
O4 - HKLM\..\Run: [o52Q36R] tcmedump.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\pbpbab.exe reg_run
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [kyuebsc] c:\windows\system32\yvboveu.exe r
O4 - HKLM\..\RunServices: [IE Runtimes] winis.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Z2t4RWdni] synemui.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {15A0BCA7-0557-4BAC-9B4C-7CE9172BB9CF} (MuzMakeIconCtrl Class) - http://image.muzcast.com/activex/muzicon/MuzIcon.cab
O16 - DPF: {298E1FE9-B230-4620-89E1-F821FF81F870} (ONCLUB Control) - http://onclub.co.kr/onclub/ONCLUB.cab
O16 - DPF: {2C197E55-080B-42A4-BFD0-9595B3534CF4} (KVPplugin00 Control) - https://www.vpay.co.kr/KVPplugin01.cab
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://www.seemedia.co.kr/products/lu/sm22/185/SVPorsche.cab
O16 - DPF: {8EEB54D5-CC70-40E4-B015-AC478C02ECC8} (SLViewer Control) - http://www.seemedia.co.kr/products/lu/sm120/157/SLViewer.cab
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/mv/XTools.cab
O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) - http://player.bugs.co.kr/install/bugsLoader20041018.cab
O16 - DPF: {CF362BDB-4EA2-11D5-AB47-000102913414} (SetGlb Control) - http://touch.imbc.com/ocx/Touch.cab
O16 - DPF: {D837FF65-FE98-44D9-B90A-74E61EB7801B} - http://showbox.dis.sholink.co.kr/sholink/s...ox/SBXPSASW.cab
O16 - DPF: {DDE6FED7-88AB-405B-9D77-FD4CDA8B9EB5} (Qbic Control) - http://qbic.hanafos.com/component/Qbic.CAB
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\modtcuiu.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

BC AdBot (Login to Remove)

 


#2 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 26 July 2005 - 10:11 PM

here is my hijack this

Logfile of HijackThis v1.99.1
Scan saved at 6:36:43 PM, on 7/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\Smtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\eDonkey2000\eDonkey2000.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
c:\windows\system32\yvboveu.exe
C:\WINDOWS\System32\winis.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\tcmedump.exe
C:\WINDOWS\System32\pbpbab.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\system\ikvocmkeoq.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\synemui.exe
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\ebre\rhrc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {44761085-8B4B-F5CD-6391-810D80FBF1EA} - C:\WINDOWS\System32\rleqbm.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [slrdgte] C:\WINDOWS\System32\octxhnj.exe
O4 - HKLM\..\Run: [dmyuilvd] C:\WINDOWS\System32\tidwnvk.exe
O4 - HKLM\..\Run: [zgscgk] C:\WINDOWS\System32\ckcyhz.exe
O4 - HKLM\..\Run: [jyjq] C:\WINDOWS\System32\waua.exe
O4 - HKLM\..\Run: [ubovd] C:\WINDOWS\System32\nkxir.exe
O4 - HKLM\..\Run: [pjlmzq] C:\WINDOWS\System32\ischx.exe
O4 - HKLM\..\Run: [utincchz] C:\WINDOWS\System32\jjqx.exe
O4 - HKLM\..\Run: [jlcqqu] C:\WINDOWS\System32\yzcpabw.exe
O4 - HKLM\..\Run: [qhlvha] C:\WINDOWS\System32\phudjvf.exe
O4 - HKLM\..\Run: [qmkif] C:\WINDOWS\System32\dglk.exe
O4 - HKLM\..\Run: [azpy] C:\WINDOWS\System32\gvat.exe
O4 - HKLM\..\Run: [arjzpy] C:\WINDOWS\System32\dqqxna.exe
O4 - HKLM\..\Run: [zgqfsf] C:\WINDOWS\System32\soohynk.exe
O4 - HKLM\..\Run: [yddf] C:\WINDOWS\System32\gxvyo.exe
O4 - HKLM\..\Run: [lvnw] C:\WINDOWS\System32\cknh.exe
O4 - HKLM\..\Run: [mreerbbu] C:\WINDOWS\System32\goma.exe
O4 - HKLM\..\Run: [kniutan] C:\WINDOWS\System32\gaano.exe
O4 - HKLM\..\Run: [afjc] C:\WINDOWS\System32\atnqm.exe
O4 - HKLM\..\Run: [kymmtwai] C:\WINDOWS\System32\jbcmub.exe
O4 - HKLM\..\Run: [vwou] C:\WINDOWS\System32\fkwdg.exe
O4 - HKLM\..\Run: [pzwzookf] C:\WINDOWS\System32\ruljw.exe
O4 - HKLM\..\Run: [uqmxz] C:\WINDOWS\System32\llflg.exe
O4 - HKLM\..\Run: [udqdsx] C:\WINDOWS\System32\bcjhaz.exe
O4 - HKLM\..\Run: [cqkl] C:\WINDOWS\System32\gcgbrpx.exe
O4 - HKLM\..\Run: [gwumzbd] C:\WINDOWS\System32\xzbrwzx.exe
O4 - HKLM\..\Run: [gnjo] C:\WINDOWS\System32\qrzwfws.exe
O4 - HKLM\..\Run: [xzrazldp] C:\WINDOWS\System32\hizdyf.exe
O4 - HKLM\..\Run: [qeeqlnbw] C:\WINDOWS\System32\lpmuw.exe
O4 - HKLM\..\Run: [wjqqyrun] C:\WINDOWS\System32\wwzo.exe
O4 - HKLM\..\Run: [aupgmgml] C:\WINDOWS\System32\iypuft.exe
O4 - HKLM\..\Run: [xkkxpn] C:\WINDOWS\System32\scwc.exe
O4 - HKLM\..\Run: [bagakqs] C:\WINDOWS\System32\wplr.exe
O4 - HKLM\..\Run: [irxyhnu] C:\WINDOWS\System32\vmyks.exe
O4 - HKLM\..\Run: [uyfsvlu] C:\WINDOWS\System32\krevq.exe
O4 - HKLM\..\Run: [lhngqjf] C:\WINDOWS\System32\afomsiyz.exe
O4 - HKLM\..\Run: [tbgk] C:\WINDOWS\System32\mllfy.exe
O4 - HKLM\..\Run: [vlmbhex] C:\WINDOWS\System32\rwwog.exe
O4 - HKLM\..\Run: [rnzdjai] C:\WINDOWS\System32\lafi.exe
O4 - HKLM\..\Run: [iqdp] C:\WINDOWS\System32\ferseif.exe
O4 - HKLM\..\Run: [hzvd] C:\WINDOWS\System32\wiusgg.exe
O4 - HKLM\..\Run: [pytvufw] C:\WINDOWS\System32\xehb.exe
O4 - HKLM\..\Run: [wzjlqxa] C:\WINDOWS\System32\zdzny.exe
O4 - HKLM\..\Run: [mvbr] C:\WINDOWS\System32\ezgwflvs.exe
O4 - HKLM\..\Run: [bwaipl] C:\WINDOWS\System32\mpuvy.exe
O4 - HKLM\..\Run: [emhtc] C:\WINDOWS\System32\ikqberyo.exe
O4 - HKLM\..\Run: [psar] C:\WINDOWS\System32\dpuo.exe
O4 - HKLM\..\Run: [hmbh] C:\WINDOWS\System32\vnnhtmvk.exe
O4 - HKLM\..\Run: [gcyued] C:\WINDOWS\System32\lrxbku.exe
O4 - HKLM\..\Run: [xyzf] C:\WINDOWS\System32\crvs.exe
O4 - HKLM\..\Run: [tzrdm] C:\WINDOWS\System32\qhbjyx.exe
O4 - HKLM\..\Run: [coul] C:\WINDOWS\System32\thwqhazt.exe
O4 - HKLM\..\Run: [eaniiem] C:\WINDOWS\System32\vouas.exe
O4 - HKLM\..\Run: [esrzb] C:\WINDOWS\System32\jvcdc.exe
O4 - HKLM\..\Run: [hwcg] C:\WINDOWS\System32\elwll.exe
O4 - HKLM\..\Run: [oclza] C:\WINDOWS\System32\tfadqlo.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IE Runtimes] winis.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [Services] C:\Documents and Settings\Administrator\socks.exe
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitetis32.exe
O4 - HKLM\..\Run: [o52Q36R] tcmedump.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\pbpbab.exe reg_run
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [kyuebsc] c:\windows\system32\yvboveu.exe r
O4 - HKLM\..\RunServices: [IE Runtimes] winis.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BestPopUpKiller] C:\Program Files\BestPopUpKiller\BestPopupKiller.exe /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [Z2t4RWdni] synemui.exe
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {15A0BCA7-0557-4BAC-9B4C-7CE9172BB9CF} (MuzMakeIconCtrl Class) - http://image.muzcast.com/activex/muzicon/MuzIcon.cab
O16 - DPF: {298E1FE9-B230-4620-89E1-F821FF81F870} (ONCLUB Control) - http://onclub.co.kr/onclub/ONCLUB.cab
O16 - DPF: {2C197E55-080B-42A4-BFD0-9595B3534CF4} (KVPplugin00 Control) - https://www.vpay.co.kr/KVPplugin01.cab
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://www.seemedia.co.kr/products/lu/sm22/185/SVPorsche.cab
O16 - DPF: {8EEB54D5-CC70-40E4-B015-AC478C02ECC8} (SLViewer Control) - http://www.seemedia.co.kr/products/lu/sm120/157/SLViewer.cab
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/mv/XTools.cab
O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) - http://player.bugs.co.kr/install/bugsLoader20041018.cab
O16 - DPF: {CF362BDB-4EA2-11D5-AB47-000102913414} (SetGlb Control) - http://touch.imbc.com/ocx/Touch.cab
O16 - DPF: {D837FF65-FE98-44D9-B90A-74E61EB7801B} - http://showbox.dis.sholink.co.kr/sholink/s...ox/SBXPSASW.cab
O16 - DPF: {DDE6FED7-88AB-405B-9D77-FD4CDA8B9EB5} (Qbic Control) - http://qbic.hanafos.com/component/Qbic.CAB
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\modtcuiu.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#3 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 27 July 2005 - 03:44 PM

Hello mister sinister and welcome to BleepingComputer.

Open the Control Panel then double click on Add/Remove Programs. Look for the following and uninstall them if found:
  • SurfSideKick


Download and install the trial version of Ewido Security Suite.
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
- Launch Ewido, there should be an icon on your desktop double-click it.
- When you run Ewido for the first time, you will get a warning "Database could not be found!".
- The program will prompt you to update; click the OK button.
- The program will now go to the main screen.
- On the left hand side of the main screen click update.
- Click on Start.
The update will start and a progress bar will show the updates being installed.
Once the updates are installed, close Ewido.

Reboot into Safe Mode.

Run Ewido:
- Click on scanner.
- Click on Complete System Scan.
- Let the program scan the machine.
When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
- Click Save report.
- Save the report to your desktop.

Reboot normally and post back a new HJT log and the contents of the ewido.txt log file.
Derfram
~~~~~~

#4 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 29 July 2005 - 01:56 AM

thanks ddeerrff here is my ewido log file

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 오후 11:47:09, 2005-07-28
+ Report-Checksum: 84BBC425

+ Scan result:

HKLM\SOFTWARE\Classes\WEBInstaller.CExecute -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CLSID -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CurVer -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\eXactUtil -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunWindowsUpdate -> Spyware.BrowserAid : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunWindowsUpdate\Active -> Spyware.BrowserAid : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BargainBuddy -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CashBack -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NaviSearch -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveNow -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virtual Bouncer -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\NaviSearch -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\WhenUSave -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\WhenUSave\Partners -> Spyware.SaveNow : Cleaned with backup
HKLM\SOFTWARE\WhenUSave\Partners\WUSV -> Spyware.SaveNow : Cleaned with backup
HKU\S-1-5-21-583907252-2049760794-725345543-500\Software\LQ -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-583907252-2049760794-725345543-500\Software\VB and VBA Program Settings\VBouncer -> Spyware.VirtualBouncer : Cleaned with backup
HKU\S-1-5-21-583907252-2049760794-725345543-500\Software\VB and VBA Program Settings\VBouncer\Settings -> Spyware.VirtualBouncer : Cleaned with backup
[720] VM_00EB0000 -> Adware.BetterInternet : Error during cleaning
C:\WINDOWS\system32\in10b6.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\system32\siae3123.exe -> Spyware.F1Organizer : Cleaned with backup
C:\WINDOWS\system32\ugrsdpia.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\ucpnpmgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\id113.exe -> Trojan.SecondThought.ak : Cleaned with backup
C:\WINDOWS\system32\Pneekl.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\Ktofgm.exe -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\nsf44.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\Ldsvzd.exe -> Trojan.Popmon.a : Cleaned with backup
C:\WINDOWS\system32\kxikqm.exe -> Backdoor.Agent.ec : Cleaned with backup
C:\WINDOWS\system32\ybojnal.exe -> Backdoor.Agent.ec : Cleaned with backup
C:\WINDOWS\system32\istinstall_adlogix.exe -> TrojanDownloader.IstBar.er : Cleaned with backup
C:\WINDOWS\system32\9znu.exe -> Trojan.Kolweb.a : Cleaned with backup
C:\WINDOWS\system32\PSof1.exe -> Spyware.Pacer : Cleaned with backup
C:\WINDOWS\system32\kgnhhei.exe -> Backdoor.Agent.ec : Cleaned with backup
C:\WINDOWS\system32\j3q3xb0.dll -> Trojan.Delf.cf : Cleaned with backup
C:\WINDOWS\system32\4nn4c3.exe -> Trojan.Delf.cf : Cleaned with backup
C:\WINDOWS\system32\redtrsha.dll -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\wknmp32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\d0ho9.sys -> Trojan.Delf.cf : Cleaned with backup
C:\WINDOWS\system32\richup.exe -> Spyware.SafeSurfing : Cleaned with backup
C:\WINDOWS\system32\rhrc.exe -> Spyware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\Rsdvzy.exe -> Trojan.Popmon.a : Cleaned with backup
C:\WINDOWS\system32\HookPopup.dll -> Spyware.DealHelper : Cleaned with backup
C:\WINDOWS\system32\e6f1873b.dll -> TrojanDownloader.Braidupdate.d : Cleaned with backup
C:\WINDOWS\system32\MMG4C32.DLL -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\dfmap.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\supdate.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\khkhjha.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\pbpbab.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\dmdmrmx.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\eaeao.dll -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\WINDOWS\system32\kddhe220.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nsp58.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\iijp81k.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\VVSNInst.exe/VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\system32\noprint.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\DrPMon.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\redit.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\dist001.exe -> TrojanDownloader.Agent.qg : Cleaned with backup
C:\WINDOWS\system32\datadx.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\elitetis32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\eliteghj32.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\adlinstallwin32.exe -> Spyware.Downloadware : Cleaned with backup
C:\WINDOWS\system32\conres.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\WINDOWS\system32\nso3E.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\pop.exe -> TrojanDropper.Agent.hl : Cleaned with backup
C:\WINDOWS\system32\exp -> TrojanDownloader.Small.abd : Cleaned with backup
C:\WINDOWS\system32\kcduk.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mbperf.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\sqorprop.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\tkrmmgr.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\AUNPS2.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\modtcuiu.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\adtapi.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\mfrle32.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\thin-138-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cxtpls_loader.exe -> TrojanDownloader.Apropo.ae : Cleaned with backup
C:\WINDOWS\system32\cbPasswd.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\nsh60.dll -> Spyware.HotSearchBar : Cleaned with backup
C:\WINDOWS\system32\exdl.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exul.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\javexulm.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\msbe.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\nvms.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\mscb.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exdl2.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exdl1.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\exul1.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system\ikvocmkeoq.exe -> TrojanDownloader.Small.ayh : Cleaned with backup
C:\WINDOWS\ohndfve.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\aacfnlnu.exe -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\oeunist.exe -> TrojanDownloader.IstBar.er : Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\d0ho9.sys -> Trojan.Delf.cf : Cleaned with backup
C:\WINDOWS\mssl23.exe -> TrojanDownloader.IstBar.er : Cleaned with backup
C:\WINDOWS\cfgmgr52.dll -> Spyware.BookedSpace : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\EliteToolBar\EliteToolBar version 60.dll -> Spyware.EliteBar : Cleaned with backup
C:\WINDOWS\AuroraHandler.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\ru.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\riri.exe -> TrojanDownloader.Qoologic.n : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\temp.frB839\BundleOuter.EXE -> Spyware.VirtualBouncer.j : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\temp.frB839\VBouncerInner.EXE -> Spyware.VirtualBouncer : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temp\temp.frB839\AdDestroyerInner.EXE -> Spyware.VirtualBouncer.j : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SL2F8XYN\toolbar3[1].cab/IExploreSkins.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SL2F8XYN\toolbar3[1].cab/toolbar.dll -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Administrator\Cookies\administrator@ads.addynamix[1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.182:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.261:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.262:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.266:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.267:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Etracker : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.297:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.370:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.371:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.373:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.374:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.376:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.377:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.381:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.384:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.386:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.389:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.390:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.391:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.392:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.393:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.394:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.395:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.396:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.397:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.398:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.399:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.400:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.401:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.402:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.403:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.410:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.412:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.413:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.414:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.415:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.416:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.418:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.419:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.426:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.427:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.428:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.433:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.434:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.435:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.436:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.437:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.438:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.439:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.440:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.441:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.442:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.460:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.470:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jhxkisvp.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.496:

#5 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 29 July 2005 - 01:57 AM

and here is my hijack this log


Logfile of HijackThis v1.99.1
Scan saved at 오후 11:55:12, on 2005-07-28
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\Smtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\eDonkey2000\eDonkey2000.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\System32\winis.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\WINDOWS\etb\pokapoka62.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: AuroraHandlerObj Class - {4AA870AC-8427-42a4-B92E-ECD956197489} - C:\WINDOWS\AuroraHandler.dll (file missing)
O2 - BHO: LANBridge Class - {71D1708F-973D-4600-AF01-AD86688403AE} - C:\WINDOWS\System32\wrnlpgzg.dll
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Smapp] Smtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [eDonkey2000] "C:\Program Files\eDonkey2000\eDonkey2000.exe" -t
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EXE -r
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [slrdgte] C:\WINDOWS\System32\octxhnj.exe
O4 - HKLM\..\Run: [dmyuilvd] C:\WINDOWS\System32\tidwnvk.exe
O4 - HKLM\..\Run: [zgscgk] C:\WINDOWS\System32\ckcyhz.exe
O4 - HKLM\..\Run: [jyjq] C:\WINDOWS\System32\waua.exe
O4 - HKLM\..\Run: [ubovd] C:\WINDOWS\System32\nkxir.exe
O4 - HKLM\..\Run: [pjlmzq] C:\WINDOWS\System32\ischx.exe
O4 - HKLM\..\Run: [utincchz] C:\WINDOWS\System32\jjqx.exe
O4 - HKLM\..\Run: [jlcqqu] C:\WINDOWS\System32\yzcpabw.exe
O4 - HKLM\..\Run: [qhlvha] C:\WINDOWS\System32\phudjvf.exe
O4 - HKLM\..\Run: [qmkif] C:\WINDOWS\System32\dglk.exe
O4 - HKLM\..\Run: [azpy] C:\WINDOWS\System32\gvat.exe
O4 - HKLM\..\Run: [arjzpy] C:\WINDOWS\System32\dqqxna.exe
O4 - HKLM\..\Run: [zgqfsf] C:\WINDOWS\System32\soohynk.exe
O4 - HKLM\..\Run: [yddf] C:\WINDOWS\System32\gxvyo.exe
O4 - HKLM\..\Run: [lvnw] C:\WINDOWS\System32\cknh.exe
O4 - HKLM\..\Run: [mreerbbu] C:\WINDOWS\System32\goma.exe
O4 - HKLM\..\Run: [kniutan] C:\WINDOWS\System32\gaano.exe
O4 - HKLM\..\Run: [afjc] C:\WINDOWS\System32\atnqm.exe
O4 - HKLM\..\Run: [kymmtwai] C:\WINDOWS\System32\jbcmub.exe
O4 - HKLM\..\Run: [vwou] C:\WINDOWS\System32\fkwdg.exe
O4 - HKLM\..\Run: [pzwzookf] C:\WINDOWS\System32\ruljw.exe
O4 - HKLM\..\Run: [uqmxz] C:\WINDOWS\System32\llflg.exe
O4 - HKLM\..\Run: [udqdsx] C:\WINDOWS\System32\bcjhaz.exe
O4 - HKLM\..\Run: [cqkl] C:\WINDOWS\System32\gcgbrpx.exe
O4 - HKLM\..\Run: [gwumzbd] C:\WINDOWS\System32\xzbrwzx.exe
O4 - HKLM\..\Run: [gnjo] C:\WINDOWS\System32\qrzwfws.exe
O4 - HKLM\..\Run: [xzrazldp] C:\WINDOWS\System32\hizdyf.exe
O4 - HKLM\..\Run: [qeeqlnbw] C:\WINDOWS\System32\lpmuw.exe
O4 - HKLM\..\Run: [wjqqyrun] C:\WINDOWS\System32\wwzo.exe
O4 - HKLM\..\Run: [aupgmgml] C:\WINDOWS\System32\iypuft.exe
O4 - HKLM\..\Run: [xkkxpn] C:\WINDOWS\System32\scwc.exe
O4 - HKLM\..\Run: [bagakqs] C:\WINDOWS\System32\wplr.exe
O4 - HKLM\..\Run: [irxyhnu] C:\WINDOWS\System32\vmyks.exe
O4 - HKLM\..\Run: [uyfsvlu] C:\WINDOWS\System32\krevq.exe
O4 - HKLM\..\Run: [lhngqjf] C:\WINDOWS\System32\afomsiyz.exe
O4 - HKLM\..\Run: [tbgk] C:\WINDOWS\System32\mllfy.exe
O4 - HKLM\..\Run: [vlmbhex] C:\WINDOWS\System32\rwwog.exe
O4 - HKLM\..\Run: [rnzdjai] C:\WINDOWS\System32\lafi.exe
O4 - HKLM\..\Run: [iqdp] C:\WINDOWS\System32\ferseif.exe
O4 - HKLM\..\Run: [hzvd] C:\WINDOWS\System32\wiusgg.exe
O4 - HKLM\..\Run: [pytvufw] C:\WINDOWS\System32\xehb.exe
O4 - HKLM\..\Run: [wzjlqxa] C:\WINDOWS\System32\zdzny.exe
O4 - HKLM\..\Run: [mvbr] C:\WINDOWS\System32\ezgwflvs.exe
O4 - HKLM\..\Run: [bwaipl] C:\WINDOWS\System32\mpuvy.exe
O4 - HKLM\..\Run: [emhtc] C:\WINDOWS\System32\ikqberyo.exe
O4 - HKLM\..\Run: [psar] C:\WINDOWS\System32\dpuo.exe
O4 - HKLM\..\Run: [hmbh] C:\WINDOWS\System32\vnnhtmvk.exe
O4 - HKLM\..\Run: [gcyued] C:\WINDOWS\System32\lrxbku.exe
O4 - HKLM\..\Run: [xyzf] C:\WINDOWS\System32\crvs.exe
O4 - HKLM\..\Run: [tzrdm] C:\WINDOWS\System32\qhbjyx.exe
O4 - HKLM\..\Run: [coul] C:\WINDOWS\System32\thwqhazt.exe
O4 - HKLM\..\Run: [eaniiem] C:\WINDOWS\System32\vouas.exe
O4 - HKLM\..\Run: [esrzb] C:\WINDOWS\System32\jvcdc.exe
O4 - HKLM\..\Run: [hwcg] C:\WINDOWS\System32\elwll.exe
O4 - HKLM\..\Run: [oclza] C:\WINDOWS\System32\tfadqlo.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IE Runtimes] winis.exe
O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
O4 - HKLM\..\Run: [Services] C:\Documents and Settings\Administrator\socks.exe
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBOUNCER\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitetis32.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\pbpbab.exe reg_run
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [o52Q36R] rsaedsvc.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [SystemService] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [lanbrup] C:\WINDOWS\System32\lanbrup.exe
O4 - HKLM\..\Run: [psnalym] c:\windows\system32\abdtqsh.exe r
O4 - HKLM\..\Run: [System service62] C:\WINDOWS\etb\pokapoka62.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\RunServices: [IE Runtimes] winis.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {15A0BCA7-0557-4BAC-9B4C-7CE9172BB9CF} (MuzMakeIconCtrl Class) - http://image.muzcast.com/activex/muzicon/MuzIcon.cab
O16 - DPF: {298E1FE9-B230-4620-89E1-F821FF81F870} (ONCLUB Control) - http://onclub.co.kr/onclub/ONCLUB.cab
O16 - DPF: {2C197E55-080B-42A4-BFD0-9595B3534CF4} (KVPplugin00 Control) - https://www.vpay.co.kr/KVPplugin01.cab
O16 - DPF: {68253470-5D4F-4CDF-8D9C-353C14A2F013} (SVPorsche Control) - http://www.seemedia.co.kr/products/lu/sm22/185/SVPorsche.cab
O16 - DPF: {8EEB54D5-CC70-40E4-B015-AC478C02ECC8} (SLViewer Control) - http://www.seemedia.co.kr/products/lu/sm120/157/SLViewer.cab
O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/mv/XTools.cab
O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) - http://player.bugs.co.kr/install/bugsLoader20041018.cab
O16 - DPF: {CF362BDB-4EA2-11D5-AB47-000102913414} (SetGlb Control) - http://touch.imbc.com/ocx/Touch.cab
O16 - DPF: {D837FF65-FE98-44D9-B90A-74E61EB7801B} - http://showbox.dis.sholink.co.kr/sholink/s...ox/SBXPSASW.cab
O16 - DPF: {DDE6FED7-88AB-405B-9D77-FD4CDA8B9EB5} (Qbic Control) - http://qbic.hanafos.com/component/Qbic.CAB
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O18 - Filter: text/html - {8293D547-38DD-4325-B35A-F1817EDFA5FC} - C:\Program Files\Cas\Client\casmf.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

#6 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 29 July 2005 - 01:05 PM

You have at least 3 major infections here, plus a number of other more 'minor' problems. This may take a bit.....


You have HijackThis running from a temporary or zip folder. Any backup files HJT creates during the repair process will not be secure if left in this folder.

Create a folder on the C: drive called "C:\HJT". You can do this by opening My Computer then double click on Local Disk (C:). In a clear area right click and select New then Folder and name it "HJT". Unzip HijackThis into this folder. Please delete any other copies of HijackThis and run HJT only from this new folder.


Trojan Hunter appears to be running some form of active protection (THGuard). Trojan Hunter is a good program but it's active protection at this time may prevent some of the fixes we will be applying. Please configure Trojan Hunter to disable the active protection until we get you fully clear.


Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
Derfram
~~~~~~

#7 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 29 July 2005 - 03:58 PM

i downloaded the l2mfix but i cant seem to do the #1 run find log thing....can you carefully go over the steps again....and i put hijack this into a new folder in my comp....

#8 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 29 July 2005 - 06:37 PM

Configure Windows to enable viewing of Hidden and System files. Under 'Tools', 'Folder Options', 'View', be sure "Hide extensions for known file types" is NOT checked.


Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop. You should now have a file named l2mfix.exe on your desk top.
- Double click l2mfix.exe. 'Accept' the disclaimer.
- 'Install To" should come up with your Desktop as the default. If not, click Browse and select Desktop.
- Click the Install button. There should now be a l2mfix folder on your desktop.

Double click to open the newly added l2mfix folder.
- Inside you will find a number of files including l2mfix.bat
- Double click l2mfix.bat and a command window will open. Press any key to continue.
- Select option #1 for Run Find Log by typing 1 and then pressing enter.

This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

If you get an error refering to "16 bit subsystem...", run option #5 then go back and run #1.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
Derfram
~~~~~~

#9 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 29 July 2005 - 07:00 PM

i opened the folder and this is the file right? l2mfix ms-dos batch file? i opened it typed 1 and enter and waited for about 20 minutes and nothing happened should i wait longer or something?

#10 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 29 July 2005 - 09:51 PM

i figured it out but can you please tell me how much longer? my comp is going crazy....well here is the log...

L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{C5F5F1C9-59B8-EE5B-C0CA-88C9325259DE}"=""
"iebar"=" "

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{4CCEFB41-18FA-11D3-9EF3-00A0C9E897FD}"="CorelDRAW Shell Extension Component"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{FB1BC078-00B9-4B5C-B8CF-00393A4430B6}"=""
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{E3BAD0F6-6F42-4AC1-89F6-5204B0595099}"=""
"{00B400A7-2F86-4D1A-BB1E-100176AC74D0}"=""
"{461C2E23-7DF8-4616-9A9E-81E3812F2A4A}"=""
"{9F01F567-F23C-4A1F-B863-01B2EE6A1954}"=""
"{2F3F2166-1BFE-41A0-ABD4-E1E8E4328B1E}"=""
"{EAC0AE31-EC19-4929-9352-4B61BDCC7ED7}"=""
"{CBFA471A-41E3-43DE-9632-B94A7706A984}"=""
"{5E05D772-7E3F-484E-93D5-01AD8AE0C189}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{FB1BC078-00B9-4B5C-B8CF-00393A4430B6}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FB1BC078-00B9-4B5C-B8CF-00393A4430B6}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FB1BC078-00B9-4B5C-B8CF-00393A4430B6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{FB1BC078-00B9-4B5C-B8CF-00393A4430B6}\InprocServer32]
@="C:\\WINDOWS\\system32\\ucpnpmgr.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{E3BAD0F6-6F42-4AC1-89F6-5204B0595099}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E3BAD0F6-6F42-4AC1-89F6-5204B0595099}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E3BAD0F6-6F42-4AC1-89F6-5204B0595099}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{E3BAD0F6-6F42-4AC1-89F6-5204B0595099}\InprocServer32]
@="C:\\WINDOWS\\system32\\ugrsdpia.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{00B400A7-2F86-4D1A-BB1E-100176AC74D0}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{00B400A7-2F86-4D1A-BB1E-100176AC74D0}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{00B400A7-2F86-4D1A-BB1E-100176AC74D0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{00B400A7-2F86-4D1A-BB1E-100176AC74D0}\InprocServer32]
@="C:\\WINDOWS\\system32\\cbPasswd.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{461C2E23-7DF8-4616-9A9E-81E3812F2A4A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{461C2E23-7DF8-4616-9A9E-81E3812F2A4A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{461C2E23-7DF8-4616-9A9E-81E3812F2A4A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{461C2E23-7DF8-4616-9A9E-81E3812F2A4A}\InprocServer32]
@="C:\\WINDOWS\\system32\\wknmp32.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9F01F567-F23C-4A1F-B863-01B2EE6A1954}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9F01F567-F23C-4A1F-B863-01B2EE6A1954}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9F01F567-F23C-4A1F-B863-01B2EE6A1954}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9F01F567-F23C-4A1F-B863-01B2EE6A1954}\InprocServer32]
@="C:\\WINDOWS\\system32\\MMG4C32.DLL"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{2F3F2166-1BFE-41A0-ABD4-E1E8E4328B1E}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2F3F2166-1BFE-41A0-ABD4-E1E8E4328B1E}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2F3F2166-1BFE-41A0-ABD4-E1E8E4328B1E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{2F3F2166-1BFE-41A0-ABD4-E1E8E4328B1E}\InprocServer32]
@="C:\\WINDOWS\\system32\\dfmap.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{EAC0AE31-EC19-4929-9352-4B61BDCC7ED7}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EAC0AE31-EC19-4929-9352-4B61BDCC7ED7}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EAC0AE31-EC19-4929-9352-4B61BDCC7ED7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{EAC0AE31-EC19-4929-9352-4B61BDCC7ED7}\InprocServer32]
@="C:\\WINDOWS\\system32\\iijp81k.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{CBFA471A-41E3-43DE-9632-B94A7706A984}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CBFA471A-41E3-43DE-9632-B94A7706A984}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CBFA471A-41E3-43DE-9632-B94A7706A984}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{CBFA471A-41E3-43DE-9632-B94A7706A984}\InprocServer32]
@="C:\\WINDOWS\\system32\\kddhe220.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{5E05D772-7E3F-484E-93D5-01AD8AE0C189}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5E05D772-7E3F-484E-93D5-01AD8AE0C189}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5E05D772-7E3F-484E-93D5-01AD8AE0C189}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{5E05D772-7E3F-484E-93D5-01AD8AE0C189}\InprocServer32]
@="C:\\WINDOWS\\system32\\noprint.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:
Locate .tmp files:
**********************************************************************************
Directory Listing of system files:
Volume in drive C is BELLCOM
Volume Serial Number is 1647-17DB

Directory of C:\WINDOWS\System32

2005-07-25 오후 07:10 417,792 guard.tmp
2005-07-21 오전 06:58 401,408 ?еrvices.exe
2004-10-25 오후 05:17 56 CE88EA53BB.sys
2004-01-28 오전 11:43 32 {E0E8EBD1-4338-4DA6-8C0C-16489F2581F7}.dat
2002-08-29 오전 02:41 88,144 winis.exe
2002-06-08 오후 12:04 <DIR> Microsoft
2002-06-07 오후 02:25 <DIR> dllcache
5 File(s) 907,432 bytes
2 Dir(s) 10,165,223,424 bytes free

#11 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 29 July 2005 - 10:17 PM

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder until you are asked to do so!
Derfram
~~~~~~

#12 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 30 July 2005 - 07:13 PM

um...i dont think the #2 run fix is working i did everything and waited for 10 hours straight and nothing.....am i doing something wrong??

#13 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 30 July 2005 - 09:29 PM

It shouldn't take more than a few minutes.

Did you get any error messages? Is there a file named lo2.txt in the l2mfix folder? If so copy/paste the contents to your next post.

Please post a fresh HJT log.
Derfram
~~~~~~

#14 mister sinister

mister sinister
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:30 PM

Posted 30 July 2005 - 11:31 PM

yes there is a file called lo2 here is the log

L2Mfix 1.03a

Running From:
C:\Documents and Settings\Administrator\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Administrator\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Administrator\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1800 'explorer.exe'
Killing PID 1800 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

#15 ddeerrff

ddeerrff

    Retired


  • Malware Response Team
  • 2,735 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Upper Midwest, US
  • Local time:07:30 PM

Posted 30 July 2005 - 11:37 PM

Looks like it hung up for some reason.

Let's attack from a different direction. Please post a fresh HJT log.
Derfram
~~~~~~




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users