Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Winstall.exe Infection


  • Please log in to reply
11 replies to this topic

#1 FrenchConnection

FrenchConnection

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 03 December 2006 - 04:43 PM

Here is the log file from the hijackthis program. I was infected when my girlfriend downloaded a link in MSN and opened the file. Computer has been awful ever since then.

Logfile of HijackThis v1.99.1
Scan saved at 4:19:09 PM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\desk98.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Common Files\{C86E55E8-06C5-1033-0828-020204160001}\Update.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{386E5~1\888Bar.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [HGTXPEI] C:\WINDOWS\system32\FirstReboot.exe
O4 - HKLM\..\Run: [SoundFusion] RunDll32 hercplgs.cpl,BootEntryPoint
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk98.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\winstall.exe
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

BC AdBot (Login to Remove)

 


m

#2 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 03 December 2006 - 05:10 PM

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new hijack log.

The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning: running option #2 on a non infected computer will remove your Desktop background.
=========================

Download AVG Anti-Spyware from http://www.ewido.net/en/download/ and save that file to your desktop. Note: This is NOT the Anti Virus from AVG.

When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.
1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.
2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
3. On the main screen select the icon "Update" then select the "Update now" link.
o Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.
4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
6. Under "Reports"
o Select "Automatically generate report after every scan"
o Un-Select "Only if threats were found"
Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.
1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:
2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.
3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
4. AVG will now begin the scanning process. Please be patient as this may take a little time.
Once the scan is complete, do the following:
5. If you have any infections you will be prompted. Then select "Apply all actions."
6. Next select the "Reports" icon at the top.
7. Select the "Save report as" button in the lower lef- hand of the screen and save it to a text file on your system (make sure to remember where you saved that file. This is important).
8. Close AVG Anti-Spyware and reboot your system back into Normal Mode.
Post the log from AVG and a new HiJack log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#3 FrenchConnection

FrenchConnection
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 03 December 2006 - 08:45 PM

this is the hijack scan

Logfile of HijackThis v1.99.1
Scan saved at 8:39:53 PM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\desk98.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\{C86E55E8-06C5-1033-0828-020204160001}\Update.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [HGTXPEI] C:\WINDOWS\system32\FirstReboot.exe
O4 - HKLM\..\Run: [SoundFusion] RunDll32 hercplgs.cpl,BootEntryPoint
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk98.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\winstall.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)



this is the avg scan log


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:34:45 PM 12/3/2006

+ Scan result:



C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022387.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022206.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022337.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022397.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022398.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022165.pif -> Backdoor.MSNMaker.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022166.pif -> Backdoor.MSNMaker.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022167.pif -> Backdoor.MSNMaker.ab : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022351.rbf -> Backdoor.MSNMaker.ab : Cleaned with backup (quarantined).
C:\Documents and Settings\Sean\Local Settings\Temp\winC.tmp.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022204.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022239.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022338.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022342.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\WINDOWS\mcc.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mcc.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
:mozilla.714:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.715:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.149:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.150:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.151:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.152:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.153:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.154:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.155:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.157:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.158:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.159:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.160:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.161:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.162:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.163:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.164:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.165:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.166:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.167:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.168:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.169:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.307:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.382:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.887:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.917:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.958:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.110:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.111:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.558:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.316:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.319:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.320:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.334:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.335:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.336:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.337:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.338:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.339:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.871:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.582:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.583:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.170:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.171:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.172:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.173:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.174:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.761:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.16:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.537:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.538:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.188:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.440:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.441:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.210:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.211:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.212:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.213:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.214:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.215:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.117:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.332:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.196:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.197:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.751:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.147:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.419:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.58:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.257:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.260:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.262:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.236:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.237:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.424:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.425:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.461:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.473:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.474:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.592:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.654:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.655:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.659:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.660:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.677:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.709:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.710:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.711:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.712:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.726:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.772:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.888:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.951:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.952:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.970:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.973:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.978:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.773:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.774:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.775:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.776:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.623:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.295:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.296:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.297:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.789:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.790:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.791:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.859:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.860:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.924:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.925:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.202:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.203:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.331:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.959:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.733:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.734:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.735:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.736:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.793:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.794:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.324:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.325:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.45:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.46:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.48:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.52:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.53:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.355:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.356:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.727:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.728:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.729:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.730:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.731:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.928:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.929:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.280:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.92:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.967:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.968:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.969:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.245:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.246:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.247:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.248:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.249:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.250:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.251:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.252:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.253:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.254:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.255:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.349:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.350:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.560:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.504:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.505:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.506:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.70:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.71:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.72:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.341:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.343:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.344:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.345:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.347:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.348:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.351:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.352:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.353:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.354:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.78:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.624:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.268:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.269:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.270:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.271:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.340:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.342:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.346:C:\Documents and Settings\Sean\Application Data\Mozilla\Firefox\Profiles\d79h9b8j.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022203.exe -> Trojan.ProcKill.DJ : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022241.exe -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022402.exe -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msasvc.ex3 -> Trojan.Sinowal.bh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022205.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022238.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022336.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022341.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\gotgo.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gotgo.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP212\A0022240.exe -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{4467D862-8029-4136-9EFA-F63D7236EF42}\RP213\A0022343.exe -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\WINDOWS\telebos.exe -> Worm.Banwarum.f : Cleaned with backup (quarantined).


::Report end

#4 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 04 December 2006 - 04:28 PM

I don't see that you ran smitfraudfix nor the log

run it and also do this

1. Download this file :

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log and a HiJack log in your next reply

Note:
Do not mouseclick combofix's window while its running. That may cause it to stall
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#5 FrenchConnection

FrenchConnection
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 05 December 2006 - 02:13 AM

Combofix log

Sean - 06-12-05 2:01:37.70 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Sean\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\Inetget2
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{C86E55E8-06C5-1033-0828-020204160001}


((((((((((((((((((((((((((((((( Files Created from 2006-11-05 to 2006-12-05 ))))))))))))))))))))))))))))))))))


2006-12-03 20:46 72,704 --a------ C:\WINDOWS\system32\drvbaw.dll
2006-12-03 20:46 40,973 ---hs---- C:\WINDOWS\system32\cbxwttr.dll
2006-12-03 19:07 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-03 19:07 <DIR> d-------- C:\Program Files\Grisoft
2006-12-03 19:01 126,996 --a------ C:\WINDOWS\system32\bgelncnu.dll
2006-12-03 18:48 1,582 --a------ C:\WINDOWS\system32\tmp.reg
2006-12-03 16:48 1,196,015 ---hs---- C:\WINDOWS\system32\yybeg.bak2
2006-12-02 18:49 <DIR> d-------- C:\Documents and Settings\Sean\.housecall6.6
2006-12-02 18:10 <DIR> d-------- C:\SmitfraudFix
2006-12-02 17:47 <DIR> d--hs---- C:\Config.Msi
2006-12-02 17:43 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2006-12-02 17:36 <DIR> d-------- C:\WINDOWS\CSC
2006-12-02 17:17 732,746 ---hs---- C:\WINDOWS\system32\yybeg.ini2
2006-12-02 17:17 68,968 --a------ C:\WINDOWS\system32\lzx32.sys
2006-12-02 16:48 732,008 ---hs---- C:\WINDOWS\system32\yybeg.bak1
2006-12-02 16:48 <DIR> d-------- C:\Documents and Settings\Sean\Application Data\SearchToolbarCorp
2006-12-02 16:47 274,484 ---hs---- C:\WINDOWS\system32\gebyy.dll
2006-12-02 16:41 93,696 --a------ C:\WINDOWS\system32\hnclse.dll
2006-12-02 16:41 72,704 --a------ C:\WINDOWS\system32\drvraw.dll
2006-12-02 16:41 71,168 --a------ C:\WINDOWS\system32\yhyydtn.dll
2006-12-02 16:41 40,973 ---hs---- C:\WINDOWS\system32\awttqnl.dll
2006-12-02 16:20 <DIR> d--h----- C:\WINDOWS\PIF
2006-11-19 04:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2006-11-11 14:36 <DIR> d-------- C:\Documents and Settings\Sean\Contacts
2006-11-06 22:43 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2006-11-06 22:42 <DIR> d-------- C:\Program Files\MSN Messenger


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

Rootkit driver pe386 is present. A rootkit scan is required

2006-12-05 02:03 -------- d-------- C:\Program Files\Common Files
2006-12-02 18:51 -------- d-------- C:\Program Files\Mozilla Firefox
2006-12-02 18:19 40 ---hs---- C:\Documents and Settings\Sean\Application Data\.zreglib
2006-12-02 17:47 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-12-02 17:41 -------- d-------- C:\Program Files\eGames
2006-11-26 20:51 -------- d-------- C:\Program Files\Absolute Poker
2006-11-20 12:48 -------- d-------- C:\Program Files\Steam
2006-11-19 04:00 -------- d-------- C:\Program Files\Internet Explorer
2006-11-11 14:36 -------- d---s---- C:\Documents and Settings\Sean\Application Data\Microsoft
2006-11-04 19:15 10752 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-11-04 19:14 -------- d-------- C:\Program Files\CyberEd
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-22 18:48 -------- d-------- C:\Program Files\_uninstallation_info
2006-10-21 23:59 -------- d-------- C:\Documents and Settings\Sean\Application Data\LimeWire
2006-10-16 20:35 -------- d-------- C:\Program Files\DVD Decrypter
2006-10-13 07:35 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 07:35 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 07:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 05:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-08 11:03 -------- d-------- C:\Program Files\DssEvolution.com
2006-09-18 21:23 1563 --a------ C:\Documents and Settings\Sean\Application Data\AdobeDLM.log
2006-09-18 21:23 0 --a------ C:\Documents and Settings\Sean\Application Data\dm.ini
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ATIRmtWndr"="C:\\Program Files\\ATI Multimedia\\RemCtrl\\ATIX10.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"D-Link AirPlus G"="C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"
"AtiPTA"="atiptaxx.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Lexmark X5100 Series"="\"C:\\Program Files\\Lexmark X5100 Series\\lxbabmgr.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{C671A733-A4AA-4B5F-8CEE-006242C457B5}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WZCSLDR2"
"hkey"="HKLM"
"command"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AnyDVD"
"hkey"="HKLM"
"command"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="drvbaw"
"hkey"="HKLM"
"command"="rundll32.exe C:\\WINDOWS\\system32\\drvbaw.dll,startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dvd43_tray"
"hkey"="HKLM"
"command"="C:\\Program Files\\dvd43\\dvd43_tray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HGTXPEI]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FirstReboot"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\FirstReboot.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hnclse.dll]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hnclse"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\hnclse.dll,omgmzn"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="desk98"
"hkey"="HKLM"
"command"="desk98.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ipwins"
"hkey"="HKLM"
"command"="C:\\Program Files\\ipwins\\ipwins.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DrgToDsc"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy Media Creator 7\\Drag to Disc\\DrgToDsc.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM1BG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SM1BG"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\SM1BG.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundFusion]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RunDll32 hercplgs"
"hkey"="HKLM"
"command"="RunDll32 hercplgs.cpl,BootEntryPoint"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDOWS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pdwpamt"
"hkey"="HKLM"
"command"="C:\\pdwpamt.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinLogon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="logon"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\logon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=dword:00000002
"iPodService"=dword:00000003
"IDriverT"=dword:00000003
"ANIWZCSdService"=dword:00000002

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxwttr
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyy
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineak32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-12-05 2:05:14.84
C:\ComboFix.txt ... 06-12-05 02:05

Hijackthis log


Logfile of HijackThis v1.99.1
Scan saved at 2:08:50 AM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00330010-0000-0000-0000-000020160026} - http://207.234.185.217/installer/ABoxInst_int26.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

#6 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 05 December 2006 - 10:30 AM

1. Download gmer from http://www.gmer.net
2. Save it somewhere safe & unzip it to desktop
3. Double click the gmer.exe to run it and select the rootkit tab, press scan
4. When it has finished, right-click the entry highlighted in red - [System] pe386
5. Select 'Delete the service' & then reboot your machine.
========================

Please download http://www.atribune.org/ccount/click.php?id=4 to C:\
Double-click VundoFix.exe to run it.
click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES.
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#7 FrenchConnection

FrenchConnection
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 05 December 2006 - 11:49 AM

vundo fix log

VundoFix V6.2.13

Checking Java version...

Java version is 1.5.0.3

Java version is 1.5.0.6

Scan started at 11:32:04 AM 12/5/2006

Listing files found while scanning....


VundoFix V6.2.13

Checking Java version...

Java version is 1.5.0.3

Java version is 1.5.0.6

Scan started at 11:35:32 AM 12/5/2006

Listing files found while scanning....

C:\WINDOWS\system32\gebyy.dll
C:\WINDOWS\system32\yybeg.ini
C:\WINDOWS\system32\yybeg.bak1
C:\WINDOWS\system32\yybeg.bak2
C:\WINDOWS\system32\yybeg.ini2
C:\WINDOWS\system32\yybeg.tmp

Beginning removal...

Attempting to delete C:\WINDOWS\system32\gebyy.dll
C:\WINDOWS\system32\gebyy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yybeg.ini
C:\WINDOWS\system32\yybeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\yybeg.bak1
C:\WINDOWS\system32\yybeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yybeg.bak2
C:\WINDOWS\system32\yybeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yybeg.ini2
C:\WINDOWS\system32\yybeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yybeg.tmp
C:\WINDOWS\system32\yybeg.tmp Has been deleted!

Performing Repairs to the registry.
Done!


Hijackthis log


Logfile of HijackThis v1.99.1
Scan saved at 11:44:40 AM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\hdteqlcf.dll (file missing)
O2 - BHO: (no name) - {70C45798-D7F6-F375-27C6-02890D2DFA61} - C:\WINDOWS\system32\yhyydtn.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {8B24A00E-C6F8-40ED-A938-49346D3CABFB} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: (no name) - {C671A733-A4AA-4B5F-8CEE-006242C457B5} - C:\WINDOWS\system32\cbxwttr.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00330010-0000-0000-0000-000020160026} - http://207.234.185.217/installer/ABoxInst_int26.exe
O20 - Winlogon Notify: cbxwttr - C:\WINDOWS\SYSTEM32\cbxwttr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wineak32 - wineak32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

#8 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 05 December 2006 - 12:57 PM

You may want to print this or save it to notepad as we will go to safe mode.

Fix these with HiJackThis – mark them, close IE, click fix checked

O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\hdteqlcf.dll (file missing)

O2 - BHO: (no name) - {70C45798-D7F6-F375-27C6-02890D2DFA61} - C:\WINDOWS\system32\yhyydtn.dll

O2 - BHO: (no name) - {8B24A00E-C6F8-40ED-A938-49346D3CABFB} - C:\WINDOWS\system32\gebyy.dll (file missing)

O2 - BHO: (no name) - {C671A733-A4AA-4B5F-8CEE-006242C457B5} - C:\WINDOWS\system32\cbxwttr.dll

O16 - DPF: {00330010-0000-0000-0000-000020160026} - http://207.234.185.217/installer/ABoxInst_int26.exe

O20 - Winlogon Notify: cbxwttr - C:\WINDOWS\SYSTEM32\cbxwttr.dll

O20 - Winlogon Notify: wineak32 - wineak32.dll (file missing)

O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
=========================
Click Start > Run > and type in:

services.msc

Click OK.

In the services window find this exact name

Microsoft authenticate service

Rightclick and choose "Properties". Beside "Startup Type" in the dropdown menu select "Disabled". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Click Apply then OK. File-Exit the Services utility.
========================


DownLoad http://www.downloads.subratam.org/KillBox.zip or
http://www.thespykiller.co.uk/files/killbox.exe

Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

C:\WINDOWS\SYSTEM32\cbxwttr.dll
C:\WINDOWS\system32\yhyydtn.dll


Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

START – RUN – type in %temp% - OK - Edit – Select all – File – Delete

Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

Not all temp files will delete and that is normal
Empty the recycle bin
Boot and post a new log from normal NOT safe mode

Please give feedback on what worked/didn’t work and the current status of your system
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#9 FrenchConnection

FrenchConnection
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 07 December 2006 - 02:25 AM

Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 2:19:15 AM, on 12/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)




now im not sure why but i can be on a web site with mozilla or IE and about a minute in it will go to another
site for anti spyware or anti virus any ideas??

#10 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 07 December 2006 - 04:49 PM

Run combofix again

===============

Go to the link below and download the trial version of SpySweeper:

SpySweeper http://www.webroot.com/consumer/products/s...4129&ac=tsg

(It's a 2 week trial.)

* Click the Try Spy Sweeper for FreeDownload the trial link.
* Install it. Once the program is installed, it will open.
* It will prompt you to update to the latest definitions, click Yes.
* Once the definitions are installed, click Options on the left side.
* Click the Sweep Options tab.
* Under What to Sweep please put a check next to the following:
o Sweep Memory
o Sweep Registry
o Sweep Cookies
o Sweep All User Accounts
o Enable Direct Disk Sweeping
o Sweep Contents of Compressed Files
o Sweep for Rootkits

o Please UNCHECK Do not Sweep System Restore Folder.

* Click Sweep Now on the left side.
* Click the Start button.
* When it's done scanning, click the Next button.
* Make sure everything has a check next to it, then click the Next button.
* It will remove all of the items found.
* Click Session Log in the upper right corner, copy everything in that window.
* Click the Summary tab and click Finish.
* Paste the contents of the session log you copied into your next reply.

Also post a new Hijack This log.
"Nothing could be finer than to be in South Carolina ............"

Member ASAP

#11 FrenchConnection

FrenchConnection
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 09 December 2006 - 11:02 AM

here is the combofix log


Sean - 06-12-09 10:52:21.84 Service Pack 2
ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Sean\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-11-09 to 2006-12-09 ))))))))))))))))))))))))))))))))))


2006-12-08 01:18 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-12-08 01:18 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-12-08 01:18 15,872 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2006-12-08 01:18 15,360 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2006-12-08 01:18 14,848 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2006-12-08 01:18 122,368 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2006-12-08 01:18 <DIR> d-------- C:\Program Files\Webroot
2006-12-08 01:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2006-12-08 01:15 <DIR> d-------- C:\Documents and Settings\Sean\Application Data\Webroot
2006-12-07 21:56 711,586 ---hs---- C:\WINDOWS\system32\stvwa.bak2
2006-12-07 02:12 <DIR> d-------- C:\!KillBox
2006-12-05 11:46 1,391,169 ---hs---- C:\WINDOWS\system32\stvwa.bak1
2006-12-05 11:45 274,484 ---hs---- C:\WINDOWS\system32\awvts.dll
2006-12-05 11:32 <DIR> d-------- C:\VundoFix Backups
2006-12-05 11:21 80 --a------ C:\WINDOWS\gmer_uninstall.cmd
2006-12-03 20:46 72,704 --a------ C:\WINDOWS\system32\drvbaw.dll
2006-12-03 19:07 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-03 19:07 <DIR> d-------- C:\Program Files\Grisoft
2006-12-03 19:01 126,996 --a------ C:\WINDOWS\system32\bgelncnu.dll
2006-12-03 18:48 1,582 --a------ C:\WINDOWS\system32\tmp.reg
2006-12-02 18:49 <DIR> d-------- C:\Documents and Settings\Sean\.housecall6.6
2006-12-02 18:10 <DIR> d-------- C:\SmitfraudFix
2006-12-02 17:47 <DIR> d--hs---- C:\Config.Msi
2006-12-02 17:43 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2006-12-02 17:36 <DIR> d-------- C:\WINDOWS\CSC
2006-12-02 16:48 <DIR> d-------- C:\Documents and Settings\Sean\Application Data\SearchToolbarCorp
2006-12-02 16:41 72,704 --a------ C:\WINDOWS\system32\drvraw.dll
2006-12-02 16:41 40,973 ---hs---- C:\WINDOWS\system32\awttqnl.dll
2006-12-02 16:20 <DIR> d--h----- C:\WINDOWS\PIF
2006-11-19 04:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2006-11-11 14:36 <DIR> d-------- C:\Documents and Settings\Sean\Contacts


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-12-07 02:01 -------- d-------- C:\Program Files\Internet Explorer
2006-12-07 00:53 -------- d-------- C:\Program Files\Steam
2006-12-05 02:03 -------- d-------- C:\Program Files\Common Files
2006-12-02 18:51 -------- d-------- C:\Program Files\Mozilla Firefox
2006-12-02 18:19 40 ---hs---- C:\Documents and Settings\Sean\Application Data\.zreglib
2006-12-02 17:47 -------- d-------- C:\Program Files\MSN Messenger
2006-12-02 17:47 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-12-02 17:41 -------- d-------- C:\Program Files\eGames
2006-11-26 20:51 -------- d-------- C:\Program Files\Absolute Poker
2006-11-11 14:36 -------- d---s---- C:\Documents and Settings\Sean\Application Data\Microsoft
2006-11-04 19:15 10752 --a------ C:\WINDOWS\system32\BASSMOD.dll
2006-11-04 19:14 -------- d-------- C:\Program Files\CyberEd
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-22 18:48 -------- d-------- C:\Program Files\_uninstallation_info
2006-10-21 23:59 -------- d-------- C:\Documents and Settings\Sean\Application Data\LimeWire
2006-10-16 20:35 -------- d-------- C:\Program Files\DVD Decrypter
2006-10-13 07:35 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 07:35 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 07:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 05:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-09-25 11:45 666240 --a------ C:\WINDOWS\system32\aswBoot.exe
2006-09-25 11:37 90112 --a------ C:\WINDOWS\system32\AVASTSS.scr
2006-09-18 21:23 1563 --a------ C:\Documents and Settings\Sean\Application Data\AdobeDLM.log
2006-09-18 21:23 0 --a------ C:\Documents and Settings\Sean\Application Data\dm.ini
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ATIRmtWndr"="\"C:\\Program Files\\ATI Multimedia\\RemCtrl\\ATIX10.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"D-Link AirPlus G"="\"C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe\""
"AtiPTA"="atiptaxx.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Lexmark X5100 Series"="\"C:\\Program Files\\Lexmark X5100 Series\\lxbabmgr.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SpySweeper"="\"C:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeperUI.exe\" /startintray"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WZCSLDR2"
"hkey"="HKLM"
"command"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AnyDVD"
"hkey"="HKLM"
"command"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="drvbaw"
"hkey"="HKLM"
"command"="rundll32.exe C:\\WINDOWS\\system32\\drvbaw.dll,startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dvd43_tray"
"hkey"="HKLM"
"command"="C:\\Program Files\\dvd43\\dvd43_tray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HGTXPEI]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="FirstReboot"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\FirstReboot.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hnclse.dll]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hnclse"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\hnclse.dll,omgmzn"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HydraVisionDesktopManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="desk98"
"hkey"="HKLM"
"command"="desk98.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ipwins"
"hkey"="HKLM"
"command"="C:\\Program Files\\ipwins\\ipwins.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DrgToDsc"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy Media Creator 7\\Drag to Disc\\DrgToDsc.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM1BG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SM1BG"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\SM1BG.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundFusion]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RunDll32 hercplgs"
"hkey"="HKLM"
"command"="RunDll32 hercplgs.cpl,BootEntryPoint"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDOWS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pdwpamt"
"hkey"="HKLM"
"command"="C:\\pdwpamt.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinLogon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="logon"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\logon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=dword:00000002
"iPodService"=dword:00000003
"IDriverT"=dword:00000003
"ANIWZCSdService"=dword:00000002

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvts

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService
Completion time: 06-12-09 10:54:08.03
C:\ComboFix.txt ... 06-12-09 10:54
C:\ComboFix2.txt ... 06-12-05 02:05




here is the hijack log



Logfile of HijackThis v1.99.1
Scan saved at 10:58:16 AM, on 12/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Sean\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [D-Link AirPlus G] "C:\Program Files\D-Link\AirPlus G\AirGCFG.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ATIRmtWndr] "C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

#12 MFDnSC

MFDnSC

    Ret. Director I/T


  • Members
  • 4,310 posts
  • OFFLINE
  •  
  • Local time:08:26 PM

Posted 09 December 2006 - 03:09 PM

Run Vundo again (post #6)

Where is the Spysweeper log
"Nothing could be finer than to be in South Carolina ............"

Member ASAP




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users