Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

difficultypc hjt log


  • Please log in to reply
1 reply to this topic

#1 difficultypc

difficultypc

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:48 AM

Posted 22 December 2005 - 09:20 AM

Hi, I have a similar virus I think, it's srshost.exe detected in Norton and using the Ewido it's srshostu.exe in Windows\System32\. Ewido deleted it, i believe. can you tell me if my system's clean? Here's the hijack log:

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://note.amherst.edu/planworld
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 38.119.66.205:80
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/..._1/axofupld.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj...ploadClient.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Here is the ewido log:

ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 9:06:00 AM, 12/22/2005
+ Report-Checksum: 84C6E3C1

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
:mozilla.15:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.48:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.58:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.59:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.68:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.69:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.70:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.71:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.122:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.130:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.131:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.136:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.137:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.150:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.151:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.154:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.155:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.175:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.176:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.177:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.178:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.179:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.180:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.181:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.182:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.183:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.185:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.186:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.187:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.188:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.189:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.190:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.191:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.192:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.193:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.194:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.197:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.200:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.201:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.202:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.203:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.204:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.206:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.207:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.208:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.210:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.211:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.212:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.213:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.214:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.215:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.216:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.217:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.218:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.219:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.220:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.221:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.222:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.223:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.224:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.225:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.226:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.227:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.228:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.229:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.248:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.253:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.254:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Adtech : Cleaned with backup
:mozilla.255:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.266:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\default.pnf\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup

C:\Documents and Settings\User\Cookies\user@cs.sexcounter[2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\User\Local Settings\Temp\Cookies\user@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\system32\splcore.dll.tcf -> Spyware.MediaBack : Cleaned with backup
C:\WINDOWS\system32\srshostu.exe -> Proxy.Agent.bz : Cleaned with backup
C:\WINDOWS\system32\winl0gon.exe -> Dropper.Small.na : Cleaned with backup


::Report End

BC AdBot (Login to Remove)

 


#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:09:48 AM

Posted 22 December 2005 - 09:42 PM

Download Hoster from here:
www.funkytoad.com/download/hoster.zip
Run the program Hoster and press Restore Original Hosts, OK, and Exit Program.


Boot - how are things - if not good post a new log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users