Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack This Log Need Help


  • This topic is locked This topic is locked
8 replies to this topic

#1 Zack Ex-Soldier

Zack Ex-Soldier

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:21 PM

Posted 04 November 2005 - 11:35 PM

My computer seemed to be running rather well a few weeks ago then slowly but surely it started acting up and it effected my computer pretty bad. So I would like help from anyone telling me which ones I need to fix or whatever, thanks :thumbsup: .

Hijack This log

Logfile of HijackThis v1.99.1
Scan saved at 9:33:46 PM, on 11/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Alias\Maya6.0\docs\jre\bin\java.exe
H:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
H:\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
D:\Program Files\NetPumper\NetPumperIEProxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
H:\Program Files\D-Tools\daemon.exe
H:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\l?ass.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\sice\eabc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3781C8A5-5414-74E3-42B1-57A029F7FF9D} - C:\WINDOWS\system32\yss.dll (file missing)
O2 - BHO: XBTB00429 - {6A54D6FF-F96C-47bb-93BD-9E758B86E3EF} - H:\Programs\Limewire\Files\CRAMTO~1\untitled.dll (file missing)
O2 - BHO: (no name) - {9C126404-F6E5-8C47-E718-F87AE4EA0EC3} - C:\WINDOWS\system32\mgmjq.dll
O2 - BHO: (no name) - {A8E92C07-E5EE-CB19-E27E-BBBE487264C6} - C:\WINDOWS\system32\ugtbmt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {FABC0C9C-917B-B2DD-2E70-CE891B073F92} - C:\WINDOWS\system32\pmzyzhwu.dll (file missing)
O3 - Toolbar: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [NBPHU] C:\WINDOWS\NBPHU.exe
O4 - HKLM\..\Run: [rcf] C:\WINDOWS\rcf.exe
O4 - HKLM\..\Run: [3vnswG] C:\windows\temp\3vnswG.exe
O4 - HKLM\..\Run: [betqr] C:\WINDOWS\betqr.exe
O4 - HKLM\..\Run: [jcbuhmh] C:\WINDOWS\jcbuhmh.exe
O4 - HKLM\..\Run: [stsx] C:\WINDOWS\stsx.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SMr] C:\documents and settings\chase\local settings\temp\SMr.exe
O4 - HKLM\..\Run: [85vC2zQb] C:\documents and settings\chase\local settings\temp\85vC2zQb.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TP] C:\documents and settings\chase\local settings\temp\TP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [NetPumper] "D:\Program Files\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "H:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\RunServices: [windows] iexplore.exe
O4 - HKCU\..\Run: [AIM] C:\Documents and Settings\Chase\My Documents\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programs\Yahoo Messenger\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Xmkknis] C:\WINDOWS\system32\l?ass.exe
O4 - HKCU\..\Run: [startkey] C:\WINDOWS\system32\server.exe
O4 - HKCU\..\Run: [Euto] "C:\Program Files\sice\eabc.exe" -vt ndrv
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with NetPumper - D:\Program Files\NetPumper\AddUrl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend Engine\bin\ZendIEToolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\Program Files\Zend Engine\bin\ZendIEToolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Chase\My Documents\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128140820473
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...356/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E9D538C6-3D6B-40AF-8883-0F3A788A1301}: NameServer = 198.60.22.2,198.60.22.22
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "D:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - H:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - H:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Posted Image

BC AdBot (Login to Remove)

 


m

#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:21 AM

Posted 05 November 2005 - 03:42 AM

Hi and Welcome to bleeping computer!! Posted Image

My name is David Posted Image

Please do both of the following before we start if possible!:

1) Please print off these intructions - they will be needed later when internet access is not available.
2) Save these instructions in word/notepad to the desktop where they can be easily found for the same reasons as above.

There is a bit to do on the log - i can almost guaruntee ewido will remove something - it's also a good free tool to keep in your arsenal! :thumbsup:

Please download ewido security suite it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck.
    • Install background guard
    • Install scan via context menu
  • Launch ewido, there should be an icon on your desktop, double-click it.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful") Posted Image
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido security suite.

Post a new HJT log and the ewido log at the end! :flowers:
David

#3 Zack Ex-Soldier

Zack Ex-Soldier
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:21 PM

Posted 05 November 2005 - 12:37 PM

Thank you very much for helping David :thumbsup:. I have done every instruction listed and here are my results.

Logfile of HijackThis v1.99.1
Scan saved at 10:33:36 AM, on 11/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
H:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
D:\Program Files\Alias\Maya6.0\docs\jre\bin\java.exe
H:\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
D:\Program Files\NetPumper\NetPumperIEProxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
H:\Program Files\D-Tools\daemon.exe
H:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\l?ass.exe
C:\Program Files\sice\eabc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
H:\Programs\ewido\security suite\ewidoctrl.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3781C8A5-5414-74E3-42B1-57A029F7FF9D} - C:\WINDOWS\system32\yss.dll (file missing)
O2 - BHO: XBTB00429 - {6A54D6FF-F96C-47bb-93BD-9E758B86E3EF} - H:\Programs\Limewire\Files\CRAMTO~1\untitled.dll (file missing)
O2 - BHO: (no name) - {9C126404-F6E5-8C47-E718-F87AE4EA0EC3} - C:\WINDOWS\system32\mgmjq.dll
O2 - BHO: (no name) - {A8E92C07-E5EE-CB19-E27E-BBBE487264C6} - C:\WINDOWS\system32\ugtbmt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - H:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {FABC0C9C-917B-B2DD-2E70-CE891B073F92} - C:\WINDOWS\system32\pmzyzhwu.dll (file missing)
O3 - Toolbar: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - H:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [NBPHU] C:\WINDOWS\NBPHU.exe
O4 - HKLM\..\Run: [rcf] C:\WINDOWS\rcf.exe
O4 - HKLM\..\Run: [3vnswG] C:\windows\temp\3vnswG.exe
O4 - HKLM\..\Run: [betqr] C:\WINDOWS\betqr.exe
O4 - HKLM\..\Run: [jcbuhmh] C:\WINDOWS\jcbuhmh.exe
O4 - HKLM\..\Run: [stsx] C:\WINDOWS\stsx.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SMr] C:\documents and settings\chase\local settings\temp\SMr.exe
O4 - HKLM\..\Run: [85vC2zQb] C:\documents and settings\chase\local settings\temp\85vC2zQb.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TP] C:\documents and settings\chase\local settings\temp\TP.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [NetPumper] "D:\Program Files\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "H:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\RunServices: [windows] iexplore.exe
O4 - HKCU\..\Run: [AIM] C:\Documents and Settings\Chase\My Documents\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programs\Yahoo Messenger\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Xmkknis] C:\WINDOWS\system32\l?ass.exe
O4 - HKCU\..\Run: [Euto] "C:\Program Files\sice\eabc.exe" -vt ndrv
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with NetPumper - D:\Program Files\NetPumper\AddUrl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Chase\My Documents\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128140820473
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...356/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E9D538C6-3D6B-40AF-8883-0F3A788A1301}: NameServer = 198.60.22.2,198.60.22.22
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "D:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - H:\Programs\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - H:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - H:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - H:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 10:32:33 AM, 11/5/2005
+ Report-Checksum: 4EA79898

+ Scan result:

HKLM\SOFTWARE\Classes\Bar.WebBar\CLSID\\ -> Spyware.NewtonKnows : Cleaned with backup
HKLM\SOFTWARE\Classes\Bar.WebBar.1\CLSID\\ -> Spyware.NewtonKnows : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4E1075F4-EEC4-4a86-ADD7-CD5F52858C31} -> Spyware.2020Search : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8940E505-72C6-44DE-BE85-1D746780EFBF}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{0F2A4ADC-DABF-4980-8DB4-19F67D7B1F95} -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{0F2A4ADC-DABF-4980-8DB4-19F67D7B1F95}\TypeLib\\ -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{AA4939C3-DECA-4A48-A454-97CD587C0EF5}\TypeLib\\ -> Spyware.SafeSurfing : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EEE4A2E5-9F56-432F-A6ED-F6F625B551E0}\TypeLib\\ -> Spyware.SafeSurfing : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\SearchRelevant\CLSID\\ -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Update.Redirector\CLSID\\ -> Spyware.Xupiter : Cleaned with backup
HKLM\SOFTWARE\Classes\Update.Redirector.1\CLSID\\ -> Spyware.Xupiter : Cleaned with backup
HKLM\SOFTWARE\Classes\Updater.BHO\CLSID\\ -> Spyware.BlazeFind : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtensi.1 -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtensi.1\CLSID\\ -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension\CLSID -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension\CLSID\\ -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Classes\WinAffiliateBHO.WinAffiliateIEExtension\CurVer -> Spyware.MidAddle : Cleaned with backup
HKLM\SOFTWARE\Dsi -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} -> Spyware.Locators : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy -> Spyware.SearchRelevancy : Cleaned with backup
HKLM\SOFTWARE\SearchRelevancy\Update -> Spyware.SearchRelevancy : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} -> Spyware.Locators : Cleaned with backup
HKU\S-1-5-21-299502267-1343024091-854245398-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} -> Spyware.Locators : Cleaned with backup
HKU\S-1-5-21-299502267-1343024091-854245398-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-299502267-1343024091-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A26ABCF0-1C8F-46E7-A67C-0489DC21B9CC} -> Spyware.Locators : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} -> Spyware.Locators : Error during cleaning
:mozilla.12:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.194:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.198:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.199:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.200:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.213:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.226:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.228:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.230:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.282:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.300:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.302:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.307:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.350:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.351:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.352:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.370:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.371:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.372:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.373:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.374:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.457:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.458:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.459:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
:mozilla.461:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.462:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.520:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.521:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.522:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.523:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.542:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.573:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.575:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.589:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.txt -> Spyware.Cookie.Hotlog : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Chase\Application Data\Mozilla\Firefox\Profiles\ejj6gdwv.default\cookies.tx
Posted Image

#4 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:21 AM

Posted 06 November 2005 - 05:53 AM

Please do both of the following before we start if possible!:

1) Please print off these intructions - they will be needed later when internet access is not available.
2) Save these instructions in word/notepad to the desktop where they can be easily found for the same reasons as above.
At the moment you may feel like you battling with your computer to keep it running smoothly, but doing the following things should most certainly help getting it back to how it was

_____________________

Make sure that you can see hidden files (Windows XP).
  • Click "Start".
  • Click "My Computer".
  • Select the "Tools" menu and click "Folder Options".
  • Select the "View" tab.
  • Under the "Hidden files and folders" heading, select "Show hidden files and folders".
  • Uncheck the "Hide protected operating system files (recommended)" option.
  • Click "Yes" to confirm.
  • Uncheck the "Hide file extensions for known file types".
  • Click "OK".
_____________________

Please go to:
  • Start
  • Control panel
  • Add/remove programs
Find and remove these programs (if they are present)
  • NetPumper
  • WhenU
  • Save!
  • ViewpointManager
_________________

Download KillBox here: http://www.downloads.subratam.org/KillBox.zip
Save it to your desktop.
DO NOT run it yet.
_____________________


With IE closed, run Hijack This again.
Put a checkmark on these entries and hit "fix checked":

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O2 - BHO: (no name) - {3781C8A5-5414-74E3-42B1-57A029F7FF9D} - C:\WINDOWS\system32\yss.dll (file missing)
O2 - BHO: XBTB00429 - {6A54D6FF-F96C-47bb-93BD-9E758B86E3EF} - H:\Programs\Limewire\Files\CRAMTO~1\untitled.dll (file missing)
O2 - BHO: (no name) - {9C126404-F6E5-8C47-E718-F87AE4EA0EC3} - C:\WINDOWS\system32\mgmjq.dll
O2 - BHO: (no name) - {A8E92C07-E5EE-CB19-E27E-BBBE487264C6} - C:\WINDOWS\system32\ugtbmt.dll (file missing)
O2 - BHO: (no name) - {FABC0C9C-917B-B2DD-2E70-CE891B073F92} - C:\WINDOWS\system32\pmzyzhwu.dll (file missing)
O3 - Toolbar: Cram Toolbar - {20929603-21DB-477C-BA6F-0B8E70B3C8A0} - H:\Programs\Limewire\Files\Cram Toolbar\untitled.dll (file missing)
O4 - HKLM\..\Run: [NBPHU] C:\WINDOWS\NBPHU.exe
O4 - HKLM\..\Run: [rcf] C:\WINDOWS\rcf.exe
O4 - HKLM\..\Run: [3vnswG] C:\windows\temp\3vnswG.exe
O4 - HKLM\..\Run: [betqr] C:\WINDOWS\betqr.exe
O4 - HKLM\..\Run: [jcbuhmh] C:\WINDOWS\jcbuhmh.exe
O4 - HKLM\..\Run: [stsx] C:\WINDOWS\stsx.exe
O4 - HKLM\..\Run: [SMr] C:\documents and settings\chase\local settings\temp\SMr.exe
O4 - HKLM\..\Run: [85vC2zQb] C:\documents and settings\chase\local settings\temp\85vC2zQb.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TP] C:\documents and settings\chase\local settings\temp\TP.exe
O4 - HKLM\..\Run: [NetPumper] "D:\Program Files\NetPumper\NetPumperIEProxy.exe"
O4 - HKLM\..\RunServices: [windows] iexplore.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [Xmkknis] C:\WINDOWS\system32\l?ass.exe
O4 - HKCU\..\Run: [Euto] "C:\Program Files\sice\eabc.exe" -vt ndrv
O16 - DPF: {2B36F775-8CF5-4489-B454-2D1B80984CF2} (FXPluginCtl Object) - http://www.powerflasher.de/plugin/powerres.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

_____________________


Boot into Safe Mode

Double-click on Killbox.exe to run it.
Now put a tick by Standard File Kill.
In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file.
It will ask for confimation to delete the file.
Click Yes.
Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\system32\mgmjq.dll
C:\WINDOWS\NBPHU.exe
C:\WINDOWS\rcf.exe
C:\windows\temp\3vnswG.exe
C:\WINDOWS\betqr.exe
C:\WINDOWS\jcbuhmh.exe
C:\WINDOWS\stsx.exe
C:\documents and settings\chase\local settings\temp\SMr.exe
C:\documents and settings\chase\local settings\temp\85vC2zQb.exe
C:\documents and settings\chase\local settings\temp\TP.exe
D:\Program Files\NetPumper\NetPumperIEProxy.exe
C:\Program Files\CLOCKS~1\Sync.exe
C:\WINDOWS\system32\l?ass.exe
C:\Program Files\sice\eabc.exe

_____________________

Manually delete this folder:

D:\Program Files\NetPumper
C:\Program Files\CLOCKS~1
C:\Program Files\sice
C:\Program Files\Viewpoint

_____________________

Please Navigate to the C:\Windows\Temp folder.
Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder. (if you cannot delete some items it's fine!)
_____________________

Then go to Start > Run and type %temp% in the Run box.
The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
_____________________

Finally go to Control Panel > Internet Options.
On the General tab under "Temporary Internet Files" Click "Delete Files".
Put a check by "Delete Offline Content" and click OK.
Click on the Programs tab then click the "Reset Web Settings" button.
Click Apply then OK.
_____________________


Empty the Recycle Bin.
_____________________


Reboot to normal mode and post a new HJT log
David

#5 Zack Ex-Soldier

Zack Ex-Soldier
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:21 PM

Posted 06 November 2005 - 03:15 PM

I have done all instructed, but for some reason my Internet Options folder was not in the control panel so I simply went into IE then into internet options under tools (I hope that works the exact same).

Here are my results.

Logfile of HijackThis v1.99.1
Scan saved at 1:11:42 PM, on 11/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe
H:\Programs\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Alias\Maya6.0\docs\jre\bin\java.exe
H:\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMNET~1\SNDMon.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {FABC0C9C-917B-B2DD-2E70-CE891B073F92} - C:\WINDOWS\system32\pmzyzhwu.dll (file missing)
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\Cyb2k.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [DAEMON Tools-1033] "H:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [AIM] C:\Documents and Settings\Chase\My Documents\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] H:\Programs\Yahoo Messenger\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Documents and Settings\Chase\My Documents\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab30149.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1128140820473
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures04.aim.com/ygp/aol/plugin/u...AIM.9.5.1.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...356/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E9D538C6-3D6B-40AF-8883-0F3A788A1301}: NameServer = 198.60.22.2,198.60.22.22
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: Alias Documentation Server (aliasdocserver) - Unknown owner - D:\Program Files\Alias\Maya6.0\docs\Wrapper.exe" -s "D:\Program Files\Alias\Maya6.0\docs/Wrapper.conf (file missing)
O23 - Service: ewido security suite control - ewido networks - H:\Programs\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Pml Driver - HP - C:\WINDOWS\System32\HPHipm09.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - H:\Alcohol 120\StarWind\StarWindService.exe
Posted Image

#6 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:21 AM

Posted 06 November 2005 - 03:45 PM

Click Start > Run > and type in:

services.msc

Click OK.

In the services window find

.NET Framework Service

Rightclick and choose "Properties". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Beside "Startup Type" in the dropdown menu select "Disabled". Click Apply then OK. File-Exit the Services utility.

Note: You may get an error here when trying to access the properties of the service. If you do get an error, just select the service and look there in the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.

Fix this entry with HJT:

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Boot to safe mode and killbox this like you did before:

C:\WINDOWS\svchost.exe

Boot to normal mode and post new log

David

#7 Zack Ex-Soldier

Zack Ex-Soldier
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:10:21 PM

Posted 06 November 2005 - 04:01 PM

I am not finding the file: O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing) when I scan in HJT. So do I just proceed with booting to safe mode ? Or must I first somehow make that file showup?
Posted Image

#8 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:21 AM

Posted 06 November 2005 - 04:04 PM

No that's fine.....continue

#9 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:21 AM

Posted 13 November 2005 - 04:49 PM

Due to the lack of feedback, I will close this thread. :thumbsup:

If you want to thread to be re-opened at any point, please PM me or any other staff with a link to it!

If anyone else is reading this with a similar problem that you would like help with, please post it in a new thread in the security section!

:flowers: David :trumpet:





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users