Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Smitfraud-c.toolbar888


  • This topic is locked This topic is locked
19 replies to this topic

#1 gcrinsm

gcrinsm

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 22 December 2006 - 12:26 AM

I got infected with some adware a while back. I have run ad-aware, spybot and hijack this to remove most of the adware on my computer. However, I seem to be unable to get rid of this smitfraud-c toolbar thing. Please help! Thank you in advance.

Here's the hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 8:06:41 PM, on 12/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {023B1249-0C88-4BA7-B6DE-B0ACE838653B} - E:\WINDOWS\Config\svscm.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Picaboo.lnk = E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Qshelf.lnk = E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\WINDOWS\System32\msjava.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O20 - Winlogon Notify: ModuleUsage - E:\WINDOWS\system32\h44mleh11h4.dll (file missing)
O20 - Winlogon Notify: WebCheck - E:\WINDOWS\system32\q6nulg5916.dll (file missing)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE



Here's the latest Spybot - Search & Destroy report which constantly shows the same issue for the last several scans:

--- Report generated: 2006-12-21 20:01 ---

Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan

Smitfraud-C.Toolbar888: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{74DD705D-6834-439C-A735-A6DBE2677452}

Smitfraud-C.Toolbar888: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-606747145-484763869-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{74DD705D-6834-439C-A735-A6DBE2677452}

Smitfraud-C.Toolbar888: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{74DD705D-6834-439C-A735-A6DBE2677452}

Smitfraud-C.Toolbar888: IE toolbar (Registry value, nothing done)
HKEY_USERS\S-1-5-21-606747145-484763869-1343024091-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{74DD705D-6834-439C-A735-A6DBE2677452}


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-10-07 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-12-15 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2006-12-15 Includes\DialerC.sbi (*)
2006-11-24 Includes\Hijackers.sbi (*)
2006-12-15 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-12-15 Includes\KeyloggersC.sbi (*)
2006-12-15 Includes\Malware.sbi (*)
2006-12-15 Includes\MalwareC.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)
2006-12-15 Includes\PUPSC.sbi (*)
2006-12-15 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2006-12-15 Includes\SecurityC.sbi (*)
2006-10-13 Includes\Spybots.sbi (*)
2006-12-15 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-12-08 Includes\Trojans.sbi (*)
2006-12-15 Includes\TrojansC.sbi (*)

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 22 December 2006 - 01:24 AM

Hello gcrinsm,

I am SifuMike and I will be helping you. :thumbsup:

Let's see if there are any parts of Smitfraud left...

Please download SmitfraudFix

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

***************


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language jre-6-windows-i586.exe and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

Edited by SifuMike, 22 December 2006 - 01:31 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 22 December 2006 - 01:32 AM

Okay, this is what the search said:

SmitFraudFix v2.131

Scan done at 22:27:50.91, Thu 12/21/2006
Run from E:\Documents and Settings\Tee\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» E:\


»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\Tee


»»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\Tee\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» E:\DOCUME~1\Tee\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» E:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

What next? Thanks for the help!

#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 22 December 2006 - 01:35 AM

I am not seeing an antivirus on this computer? :thumbsup: Are you using one?

This is somewhat suicidal in today's digital world. :flowers:

You need to install an antivirus program as soon as you can and run a complete scan of the computer.
I recommend you download the free
AntiVir or
AVG antivirus or
Avast

Never install more than one antivirus scanner or firewall on your system! Several together can give you problems and decrease the reliability of it seriously!

Edited by SifuMike, 22 December 2006 - 01:42 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 22 December 2006 - 01:45 AM

Okay - we never used this computer much so never installed anti virus software. I'll do that tomorrow and get back to, need to get to bed.

Thanks!

#6 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 23 December 2006 - 02:33 PM

Hi all,
With the holidays I wasn't able to get to this quickly, however but since the last post, I have:
1) Updated Java
2) Installed AVG.
3) Ran AVG and it discovered the following:
"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031462.hta"
"12/22/2006 11:52:45 PM" "A0031462.hta" "1.74 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031463.hta"
"12/22/2006 11:52:49 PM" "A0031463.hta" "1.74 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031464.hta"
"12/22/2006 11:52:52 PM" "A0031464.hta" "1.73 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031465.hta"
"12/22/2006 11:52:54 PM" "A0031465.hta" "1.74 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031466.hta"
"12/22/2006 11:52:57 PM" "A0031466.hta" "1.74 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031467.hta"
"12/22/2006 11:52:59 PM" "A0031467.hta" "1.74 KB"

"Virus found VBS/Psyme"
"C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031468.hta"
"12/22/2006 11:53:02 PM" "A0031468.hta" "1.73 KB"

"Trojan horse Downloader.Generic2.TUJ"
"E:\Program Files\Common Files\Yazzle1281OinAdmin.exe"
"12/22/2006 10:53:59 PM" "Yazzle1281OinAdmin.exe" "153.5 KB"

"Trojan horse Generic2.ETW"
"E:\VundoFix Backups\moubagse.dll.bad"
"12/22/2006 10:53:59 PM" "moubagse.dll.bad" "96 KB"

"Trojan horse Generic2.IKG"
"E:\VundoFix Backups\svscm.dll.bad"
"12/22/2006 10:53:59 PM" "svscm.dll.bad" "696 KB"

"Trojan horse Look2me"
"E:\WINDOWS\system32\enlul1391.dll"
"12/22/2006 10:53:59 PM" "enlul1391.dll" "230.45 KB"

What's the next step?

Edited by gcrinsm, 23 December 2006 - 02:34 PM.


#7 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 23 December 2006 - 02:37 PM

Hi gcrinsm,

Since AVG antivirus found look2me on your computer, let's run AVG antispwyare.

Are you seeing any popups?


Download ATF (Atribune Temp File) Cleaner© by Atribune DO NOT run it yet.

Download and install AVG Anti-Spyware 7.5 (formerly Ewido)
This is a 30 day trial of the program

1. After download, double click on the file to launch the install process.
2. Choose a language, click "OK" and then click "Next".
3. Read the "License Agreement" and click "I Agree".
4. Accept the default installation path: C:\Program Files\AVG Anti-Spyware 7.5 and click "Next", then click "Install".
5. After setup completes, click "Finish" to start the program automatically or launch ewido by double-clicking its icon on your desktop or in the system tray.
6. The main "Status" menu will appear. You can select "Change state" to inactivate 'Resident Sheild' and 'Automatic Updates'. If you choose to do this, then right click on ewdio in the system tray and uncheck "Start with Windows".
7. Select the "Update" button and click "Start update". If you are having problems with the updater, manually update with the Ewido Full database installer from here.
8. Exit AVG Anti-Spyware 7.5 when done - DO NOT perform a scan yet.

Reboot your computer in "SAFE MODE" using the F8 method so Windows will start with minimal drivers and running processes.
To do this restart your computer and after hearing your computer beep once during startup [but before the Windows icon appears] press the F8 key repeatedly.
A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

1.) Double-click the small BLUE Garbage Can ATF-Cleaner.exe file to run the program.
2.) At the top, under Main choose: Select All
3.) Click the Empty Selected button.

If you use the Firefox browser:
1.) At the top, click Firefox and choose: Select All
2.) Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use the Opera browser:
1.) At the top, click Opera and choose: Select All
2.) Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.


Scan with AVG Anti-Spyware 7.5 as follows:

1. Launch AVG Anti-Spyware 7.5, click on the "Scanner" button and choose the "Settings" tab.

Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.

Under "How to Scan?" check all (default).

Under "Possibly unwanted software" check all (default).

Under "What to Scan?" make sure "Scan every file" is selected (default).

Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".

2. Click the "Scan" tab to return to scanning options.
3. Click "Complete System Scan" to start.
4. When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
5. Click on "Save Report" to view all completed scans.
Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\AVG Anti-Spyware 7.5\Reports\
6. Exit AVG Anti-Spyware 7.5

Reboot.

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Notes:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Disable script blocking if you have Norton Antivirus installed so it will not interfere with the fix. Trojan Hunter has been reported to detect combofix as Worm.Qiv.100.




When done, submit the AVG Anti-Spyware 7.5 log, ComboFix log  and a  fresh Hijackthis log.

Edited by SifuMike, 23 December 2006 - 02:42 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#8 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 27 December 2006 - 01:47 AM

Hi SifuMike,

The popups have stopped!

Here's the logs:

AVG ANTI-SPYWARE LOG

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:40:04 PM 12/23/2006

+ Scan result:



E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP362\A0029864.dll -> Adware.Agent : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029644.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031471.exe/AutoSearch.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\Classes\AutoSearch.AutoSearchObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\Classes\AutoSearch.AutoSearchObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\Classes\AutoSearch.AutoSearchObj\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\Classes\AutoSearch.AutoSearchObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
HKU\S-1-5-21-606747145-484763869-1343024091-1003\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP347\A0025918.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP373\A0031839.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029637.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029640.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031475.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP373\A0031892.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP347\A0025952.dll -> Adware.Searchcolor : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029331.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029654.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
E:\VundoFix Backups\xcwopevj.exe.bad -> Adware.Searchcolor : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031473.dll -> Adware.Searchcolours : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029638.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029652.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029651.DLL -> Adware.WebHancer : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029645.exe -> Backdoor.IP_Protect : Cleaned with backup (quarantined).
F:\Temp - downloads\Bullet Proof FTP\Bullet Proof FTP 1.02\BPFTP102.EXE -> Backdoor.NetSpy : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029642.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029643.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
E:\Documents and Settings\Tee\My Documents\Тasks\alg.exe -> Downloader.PurityScan.cx : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP373\A0031838.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029639.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031469.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029320.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP357\A0029549.exe -> Downloader.VB.apu : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031472.exe -> Downloader.VB.apu : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031474.exe -> Downloader.VB.apu : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029636.exe -> Downloader.VB.wz : Cleaned with backup (quarantined).
E:\WINDOWS\browser.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\WINME\Cookies\theresa@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[4].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[5].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[7].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@2o7[8].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINME\Cookies\theresa@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\WINME\Cookies\theresa@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.208:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Admonitor : Cleaned.
:mozilla.228:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Admonitor : Cleaned.
:mozilla.96:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Admonitor : Cleaned.
D:\WIN98\Cookies\tee2@ads_admonitor(1).txt -> TrackingCookie.Admonitor : Cleaned.
C:\WINME\Cookies\theresa@adorigin[1].txt -> TrackingCookie.Adorigin : Cleaned.
C:\WINME\Cookies\theresa@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.17:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.237:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.47:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\WINME\Cookies\theresa@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\WINME\Cookies\theresa@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\WINME\Cookies\theresa@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\WINME\Cookies\theresa@servedby.advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
D:\WIN98\Cookies\tee2@advertising(1).txt -> TrackingCookie.Advertising : Cleaned.
D:\WIN98\Cookies\tee2@servedby_advertising(1).txt -> TrackingCookie.Advertising : Cleaned.
C:\WINME\Cookies\theresa@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.19:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Bfast : Cleaned.
C:\WINME\Cookies\theresa@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
D:\WIN98\Cookies\tee2@bfast(1).txt -> TrackingCookie.Bfast : Cleaned.
D:\WIN98\Cookies\tee2@bfast.txt -> TrackingCookie.Bfast : Cleaned.
C:\WINME\Cookies\theresa@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\WINME\Cookies\theresa@bluestreak[3].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\WINME\Cookies\theresa@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\WINME\Cookies\theresa@casinodelrio[1].txt -> TrackingCookie.Casinodelrio : Cleaned.
C:\WINME\Cookies\theresa@casinotropez[2].txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.26:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned.
C:\WINME\Cookies\theresa@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
C:\WINME\Cookies\theresa@centrport[2].txt -> TrackingCookie.Centrport : Cleaned.
C:\WINME\Cookies\theresa@click2net[2].txt -> TrackingCookie.Click2net : Cleaned.
:mozilla.46:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Clickagents : Cleaned.
C:\WINME\Cookies\theresa@ads.clickagents[2].txt -> TrackingCookie.Clickagents : Cleaned.
C:\WINME\Cookies\theresa@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\WINME\Cookies\theresa@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\WINME\Cookies\theresa@download.com[2].txt -> TrackingCookie.Com : Cleaned.
C:\WINME\Cookies\theresa@news.com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.146:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
:mozilla.147:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
D:\WIN98\Cookies\tee2@www_commission-junction.txt -> TrackingCookie.Commission-junction : Cleaned.
C:\WINME\Cookies\theresa@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
D:\WIN98\Cookies\tee2@data_coremetrics.txt -> TrackingCookie.Coremetrics : Cleaned.
D:\WIN98\Cookies\tee2@bilbo_counted(1).txt -> TrackingCookie.Counted : Cleaned.
C:\WINME\Cookies\theresa@dbbsrv[1].txt -> TrackingCookie.Dbbsrv : Cleaned.
:mozilla.10:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.214:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\WINME\Cookies\theresa@ad.doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\WINME\Cookies\theresa@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
D:\WIN98\Cookies\tee2@doubleclick(1).txt -> TrackingCookie.Doubleclick : Cleaned.
D:\WIN98\Cookies\tee2@engage.txt -> TrackingCookie.Engage : Cleaned.
:mozilla.221:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Enliven : Cleaned.
D:\WIN98\Cookies\tee2@ads_enliven.txt -> TrackingCookie.Enliven : Cleaned.
D:\WIN98\Cookies\tee2@enliven.txt -> TrackingCookie.Enliven : Cleaned.
C:\WINME\Cookies\theresa@-1shz2prbmdj6wvny-1sez2pra2dj6wjkokndzkaqq-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\WINME\Cookies\theresa@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4soajwhowidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\WINME\Cookies\theresa@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliglazigqqidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\WINME\Cookies\theresa@a.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\WINME\Cookies\theresa@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\WINME\Cookies\theresa@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\WINME\Cookies\theresa@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.14:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Flycast : Cleaned.
D:\WIN98\Cookies\tee2@flycast(1).txt -> TrackingCookie.Flycast : Cleaned.
:mozilla.25:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Focalink : Cleaned.
D:\WIN98\Cookies\tee2@focalink(1).txt -> TrackingCookie.Focalink : Cleaned.
C:\WINME\Cookies\theresa@gator[1].txt -> TrackingCookie.Gator : Cleaned.
C:\WINME\Cookies\theresa@ehg-acdsystems.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-aol.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-aubuchonhardware.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-cbs.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-fitness.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-groceryworks.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-hearingplanet.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-reunion.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-ti.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg-tickleinc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@ehg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@hg1.hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
D:\WIN98\Cookies\tee2@hitbox(2).txt -> TrackingCookie.Hitbox : Cleaned.
D:\WIN98\Cookies\tee2@hitbox.txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINME\Cookies\theresa@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\WINME\Cookies\theresa@hyperbanner[1].txt -> TrackingCookie.Hyperbanner : Cleaned.
D:\WIN98\Cookies\tee2@hyperbanner.txt -> TrackingCookie.Hyperbanner : Cleaned.
C:\WINME\Cookies\theresa@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\WINME\Cookies\theresa@ads.link4ads[1].txt -> TrackingCookie.Link4ads : Cleaned.
C:\WINME\Cookies\theresa@ads.link4ads[2].txt -> TrackingCookie.Link4ads : Cleaned.
C:\WINME\Cookies\theresa@ads.link4ads[3].txt -> TrackingCookie.Link4ads : Cleaned.
C:\WINME\Cookies\theresa@ads.link4ads[4].txt -> TrackingCookie.Link4ads : Cleaned.
D:\WIN98\Cookies\tee2@ads_link4ads(2).txt -> TrackingCookie.Link4ads : Cleaned.
D:\WIN98\Cookies\tee2@ads_link4ads.txt -> TrackingCookie.Link4ads : Cleaned.
:mozilla.23:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
D:\WIN98\Cookies\tee2@linksynergy(1).txt -> TrackingCookie.Linksynergy : Cleaned.
D:\WIN98\Cookies\tee2@linksynergy.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.15:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.18:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\WINME\Cookies\theresa@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\WINME\Cookies\theresa@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
D:\WIN98\Cookies\tee2@mediaplex(1).txt -> TrackingCookie.Mediaplex : Cleaned.
D:\WIN98\Cookies\tee2@mediaplex(2).txt -> TrackingCookie.Mediaplex : Cleaned.
D:\WIN98\Cookies\tee2@mediaplex.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\WINME\Cookies\theresa@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\WINME\Cookies\theresa@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\WINME\Cookies\theresa@www.myaffiliateprogram[3].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\WINME\Cookies\theresa@www.myaffiliateprogram[4].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\WINME\Cookies\theresa@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\WINME\Cookies\theresa@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\WINME\Cookies\theresa@www.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned.
C:\WINME\Cookies\theresa@www6.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned.
C:\WINME\Cookies\theresa@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\WINME\Cookies\theresa@ads.pointroll[3].txt -> TrackingCookie.Pointroll : Cleaned.
C:\WINME\Cookies\theresa@www.popuptraffic[1].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\WINME\Cookies\theresa@www.popuptraffic[2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\WINME\Cookies\theresa@c.porngraph[2].txt -> TrackingCookie.Porngraph : Cleaned.
:mozilla.115:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Preferences : Cleaned.
:mozilla.155:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.Preferences : Cleaned.
:mozilla.9:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Preferences : Cleaned.
C:\WINME\Cookies\theresa@gm.preferences[1].txt -> TrackingCookie.Preferences : Cleaned.
C:\WINME\Cookies\theresa@preferences[1].txt -> TrackingCookie.Preferences : Cleaned.
C:\WINME\Cookies\theresa@preferences[3].txt -> TrackingCookie.Preferences : Cleaned.
D:\WIN98\Cookies\anyuser@gm_preferences.txt -> TrackingCookie.Preferences : Cleaned.
D:\WIN98\Cookies\anyuser@preferences.txt -> TrackingCookie.Preferences : Cleaned.
D:\WIN98\Cookies\tee2@gm_preferences.txt -> TrackingCookie.Preferences : Cleaned.
D:\WIN98\Cookies\tee2@preferences.txt -> TrackingCookie.Preferences : Cleaned.
C:\WINME\Cookies\theresa@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\WINME\Cookies\theresa@qksrv[3].txt -> TrackingCookie.Qksrv : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[3].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[4].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[5].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[6].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@questionmarket[8].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\WINME\Cookies\theresa@www.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\WINME\Cookies\theresa@web4.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned.
C:\WINME\Cookies\theresa@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\WINME\Cookies\theresa@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\WINME\Cookies\theresa@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\WINME\Cookies\theresa@edge.ru4[4].txt -> TrackingCookie.Ru4 : Cleaned.
C:\WINME\Cookies\theresa@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@bs.serving-sys[4].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@ds.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\WINME\Cookies\theresa@ads.specificpop[1].txt -> TrackingCookie.Specificpop : Cleaned.
C:\WINME\Cookies\theresa@ads.specificpop[2].txt -> TrackingCookie.Specificpop : Cleaned.
C:\WINME\Cookies\theresa@specificpop[1].txt -> TrackingCookie.Specificpop : Cleaned.
C:\WINME\Cookies\theresa@spinbox[1].txt -> TrackingCookie.Spinbox : Cleaned.
C:\WINME\Cookies\theresa@www.statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\WINME\Cookies\theresa@track-star[1].txt -> TrackingCookie.Track-star : Cleaned.
C:\WINME\Cookies\theresa@track-star[2].txt -> TrackingCookie.Track-star : Cleaned.
C:\WINME\Cookies\theresa@track-star[3].txt -> TrackingCookie.Track-star : Cleaned.
C:\WINME\Cookies\theresa@track-star[4].txt -> TrackingCookie.Track-star : Cleaned.
:mozilla.20:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\WINME\Cookies\theresa@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\WINME\Cookies\theresa@trafficmp[3].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\WINME\Cookies\theresa@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\WINME\Cookies\theresa@tribalfusion[3].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\WINME\Cookies\theresa@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned.
D:\WIN98\Cookies\tee2@valueclick.txt -> TrackingCookie.Valueclick : Cleaned.
C:\WINME\Cookies\theresa@vegasred[1].txt -> TrackingCookie.Vegasred : Cleaned.
C:\WINME\Cookies\theresa@www.web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.23:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.31:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.32:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.33:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.34:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.35:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.36:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.38:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.39:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.40:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.41:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.48:C:\WINME\Application Data\Mozilla\Users50\default\uxmmbykv.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
D:\WIN98\Cookies\tee2@stats_webtrendslive(1).txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.284:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.X10 : Cleaned.
:mozilla.285:D:\WIN98\Application Data\Mozilla\Users50\Tee2\vvtbbscp.slt\cookies.txt -> TrackingCookie.X10 : Cleaned.
C:\WINME\Cookies\theresa@ads.x10[1].txt -> TrackingCookie.X10 : Cleaned.
C:\WINME\Cookies\theresa@ads.x10[2].txt -> TrackingCookie.X10 : Cleaned.
C:\WINME\Cookies\theresa@ads.x10[4].txt -> TrackingCookie.X10 : Cleaned.
D:\WIN98\Cookies\tee2@x10.txt -> TrackingCookie.X10 : Cleaned.
C:\WINME\Cookies\theresa@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\WINME\Cookies\theresa@zedo[3].txt -> TrackingCookie.Zedo : Cleaned.
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029329.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029330.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP362\A0029862.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
E:\WINDOWS\system32\wnscpcc.exe -> Trojan.Small : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP358\A0029641.exe -> Trojan.VB.atp : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029319.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP353\A0029321.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{820357DE-D23D-4784-BFC1-D95036C9FB83}\RP371\A0031470.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).


::Report end

HIJACK THIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 1:42:16 PM, on 12/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {023B1249-0C88-4BA7-B6DE-B0ACE838653B} - E:\WINDOWS\Config\svscm.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Picaboo.lnk = E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Qshelf.lnk = E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O20 - Winlogon Notify: ModuleUsage - E:\WINDOWS\system32\h44mleh11h4.dll (file missing)
O20 - Winlogon Notify: WebCheck - E:\WINDOWS\system32\q6nulg5916.dll (file missing)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE


COMBOFIX LOG
Tee - 06-12-24 13:50:42.82 Service Pack 2
ComboFix 06.11.27 - Running from: "E:\Documents and Settings\Tee\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{BA571938-9CB2-4887-80B6-0C5B8ED5F568}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BA571938-9CB2-4887-80B6-0C5B8ED5F568}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{BA571938-9CB2-4887-80B6-0C5B8ED5F568}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{BA571938-9CB2-4887-80B6-0C5B8ED5F568}\InprocServer32]
@="E:\\WINDOWS\\system32\\kldgr.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


Granting sedebugprivilege to Administrators ... successful


((((((((((((((((((((((((((((((((((((((((((( E-Give / Ssk's Log )))))))))))))))))))))))))))))))))))))))))))))))))


E:\Documents and Settings\Tee\Application Data\Dxccwrd.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


E:\Program Files\Common Files\Yazzle1281OinUninstaller.exe

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

E:\QooBox\Purity\Documents and Settings\Tee\My Documents\ASKS~1
E:\QooBox\Purity\Documents and Settings\Tee\My Documents\YSTEM3~1
E:\QooBox\Purity\Documents and Settings\Tee\My Documents\ASKS~1\?asks
E:\QooBox\Purity\Documents and Settings\Tee\My Documents\ASKS~1\?asks\ctxad-477.0000
E:\QooBox\Purity\Documents and Settings\Tee\My Documents\ASKS~1\?asks\ctxad-477.0001


((((((((((((((((((((((((((((((( Files Created from 2006-11-24 to 2006-12-24 ))))))))))))))))))))))))))))))))))


2006-12-23 11:42 3,968 --a------ E:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-22 22:53 <DIR> dr-h----- E:\$VAULT$.AVG
2006-12-22 21:15 816,672 --a------ E:\WINDOWS\system32\drivers\avg7core.sys
2006-12-22 21:15 4,960 --a------ E:\WINDOWS\system32\drivers\avgtdi.sys
2006-12-22 21:15 4,224 --a------ E:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-22 21:15 3,968 --a------ E:\WINDOWS\system32\drivers\avgclean.sys
2006-12-22 21:15 28,416 --a------ E:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-22 21:15 18,240 --a------ E:\WINDOWS\system32\drivers\avgmfx86.sys
2006-12-22 21:15 <DIR> d-------- E:\Program Files\Grisoft
2006-12-22 21:15 <DIR> d-------- E:\Documents and Settings\Tee\Application Data\AVG7
2006-12-22 21:15 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Grisoft
2006-12-22 21:15 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\avg7
2006-12-22 19:59 <DIR> d-------- E:\Program Files\Java
2006-12-22 19:59 <DIR> d-------- E:\Program Files\Common Files\Java
2006-12-21 22:27 79,360 --a------ E:\WINDOWS\system32\swxcacls.exe
2006-12-21 22:27 53,248 --a------ E:\WINDOWS\system32\Process.exe
2006-12-21 22:27 51,200 --a------ E:\WINDOWS\system32\dumphive.exe
2006-12-21 22:27 40,960 --a------ E:\WINDOWS\system32\swsc.exe
2006-12-21 22:27 288,417 --a------ E:\WINDOWS\system32\SrchSTS.exe
2006-12-21 22:27 135,168 --a------ E:\WINDOWS\system32\swreg.exe
2006-12-21 21:51 76,560 --a------ E:\WINDOWS\system32\drivers\tmcomm.sys
2006-12-21 20:15 <DIR> d-------- E:\Documents and Settings\Tee\.housecall6.6
2006-12-16 15:24 <DIR> d-------- E:\Documents and Settings\Tee\Application Data\Picaboo
2006-12-16 15:17 <DIR> dr--s---- E:\WINDOWS\assembly
2006-12-16 15:17 <DIR> d-------- E:\WINDOWS\system32\URTTemp
2006-12-16 15:17 <DIR> d-------- E:\WINDOWS\Microsoft.NET
2006-12-16 15:10 <DIR> d-------- E:\Program Files\Picaboo
2006-12-02 12:45 1,654 --a------ E:\WINDOWS\system32\tmp.reg
2006-12-02 12:42 <DIR> d-------- E:\Program Files\a-squared HiJackFree


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-12-24 13:51 -------- d-------- E:\Program Files\Common Files
2006-12-21 21:51 -------- d-------- E:\Program Files\Internet Explorer
2006-12-17 13:10 -------- d-------- E:\Program Files\Outlook Express
2006-12-17 13:09 -------- d-------- E:\Program Files\Common Files\System
2006-12-16 15:24 -------- d---s---- E:\Documents and Settings\Tee\Application Data\Microsoft
2006-12-07 17:02 2174976 --a------ E:\WINDOWS\system32\wmvcore.dll
2006-12-02 12:42 502272 --a------ E:\WINDOWS\system32\winlogon.exe
2006-12-02 12:39 -------- d-------- E:\Program Files\a-squared Free
2006-11-22 21:33 -------- d-------- E:\Program Files\Citrix
2006-11-22 21:33 -------- d-------- E:\Documents and Settings\Tee\Application Data\ICAClient
2006-11-16 12:55 -------- d-------- E:\Documents and Settings\Tee\Application Data\AdobeUM
2006-11-07 21:06 679424 --a------ E:\WINDOWS\system32\inetcomm.dll
2006-10-25 21:45 -------- d-------- E:\Program Files\MSN Games
2006-10-19 05:56 713216 --a------ E:\WINDOWS\system32\sxs.dll
2006-10-13 04:35 65536 --a------ E:\WINDOWS\system32\nwwks.dll
2006-10-13 04:35 64000 --a------ E:\WINDOWS\system32\nwapi32.dll
2006-10-13 04:35 142336 --a------ E:\WINDOWS\system32\nwprovau.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"D-Link AirPlus G"="E:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"
"YBrowser"="E:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe"
"Motive SmartBridge"="E:\\PROGRA~1\\SBCSEL~1\\SMARTB~1\\MotiveSB.exe"
"SunJavaUpdateSched"="\"E:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"AVG7_CC"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="E:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20061111-204616-129
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
backup-20061111-204616-826
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - E:\Program Files\VSAdd-in\VSAdd-in.dll
backup-20061007-200504-188
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
backup-20061007-153838-922
O15 - Trusted Zone: *.media-motor.com (HKLM)
backup-20061007-153838-171
O15 - Trusted Zone: *.mediatickets.net (HKLM)
backup-20061007-153838-886
O15 - Trusted Zone: *.winantivirus.com (HKLM)
backup-20061007-153838-882
O15 - Trusted Zone: *.snipernet.biz (HKLM)
backup-20061007-153838-747
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
backup-20061007-153838-719
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
backup-20061007-153838-106
O15 - Trusted Zone: *.media-motor.net (HKLM)
backup-20061007-153838-470
O15 - Trusted Zone: *.winfixer.com (HKLM)
backup-20061007-153838-313
O15 - Trusted Zone: *.matcash.com (HKLM)
backup-20061007-153838-733
O4 - HKCU\..\Run: [Uult] "E:\DOCUME~1\Tee\MYDOCU~1\ASKS~1\alg.exe" -vt yazb
backup-20061007-153838-291
O15 - Trusted Zone: *.sxload.com
backup-20061007-153838-348
O15 - Trusted Zone: *.adsextend.net
backup-20061007-153838-355
O15 - Trusted Zone: *.errorsafe.com
backup-20061007-153838-965
O4 - HKLM\..\Run: [1pop06apelt2] E:\WINDOWS\elitepop06.exe
backup-20061007-153838-430
O15 - Trusted Zone: *.adsextend.net (HKLM)
backup-20061007-153838-438
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
backup-20061007-153838-128
O15 - Trusted Zone: *.adgate.info (HKLM)
backup-20061007-153838-280
O15 - Trusted Zone: *.imagesrvr.com
backup-20061007-153838-472
O15 - Trusted Zone: *.systemdoctor.com
backup-20061007-153838-504
O15 - Trusted Zone: *.matcash.com
backup-20061007-153838-513
O4 - HKLM\..\Run: [win3206520742071] E:\WINDOWS\win3206520742071.exe
backup-20061007-153838-547
O15 - Trusted Zone: *.errorsafe.com (HKLM)
backup-20061007-153838-562
O15 - Trusted Zone: *.winfixer.com
backup-20061007-153838-263
O15 - Trusted Zone: *.snipernet.biz
backup-20061007-153838-615
O4 - HKCU\..\Run: [Vhjkcna] E:\Documents and Settings\Tee\My Documents\?ystem32\??chost.exe
backup-20061007-153838-662
O15 - Trusted Zone: *.winantivirus.com
backup-20061007-153838-910
O15 - Trusted Zone: *.adgate.info
backup-20061007-153838-177
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
backup-20061007-153838-850
O15 - Trusted Zone: *.mediatickets.net
backup-20061007-153838-566
O15 - Trusted Zone: *.media-motor.com
backup-20061007-153838-241
O15 - Trusted Zone: *.elitemediagroup.net
backup-20061007-153838-769
O15 - Trusted Zone: *.dollarrevenue.com
backup-20061007-153838-782
O4 - HKLM\..\Run: [TheMonitor] E:\WINDOWS\Duce6.exe
backup-20061007-153838-790
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
backup-20061007-153838-257
O4 - HKLM\..\Run: [defender] C:\\dfndrff_e24.exe
backup-20061007-153838-236
O4 - HKLM\..\Run: [xload] "E:\WINDOWS\xload.exe"
backup-20061007-153838-901
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e24.exe
backup-20061007-153838-982
O4 - HKLM\..\Run: [rii7119a] RUNDLL32.EXE w003881c.dll,n 0057119500000012003881c
backup-20061007-153838-722
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
backup-20061007-153838-107
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
backup-20061007-153838-459
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
backup-20061007-153838-124
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
backup-20061007-153838-413
O4 - HKLM\..\Run: [BJCFD] E:\Program Files\BroadJump\Client Foundation\CFD.exe
backup-20061007-153838-968
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
backup-20061007-153838-975
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
backup-20061007-153838-840
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
backup-20061007-153838-983
O4 - HKLM\..\Run: [ANIWZCS2Service] E:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
backup-20061007-153838-306
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
backup-20061007-153838-729
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
backup-20061007-153838-950
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html

Contents of the 'Scheduled Tasks' folder
E:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job

Completion time: 06-12-24 13:57:38.46
E:\ComboFix.txt ... 06-12-24 13:57

I also ran hijack this after combofix ran. The results were different as seen below:
POST COMBOFIX HIJACK THIS LOG
Logfile of HijackThis v1.99.1
Scan saved at 10:44:36 PM, on 12/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\Program Files\Java\jre1.6.0\bin\jusched.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\WINDOWS\system32\NOTEPAD.EXE
E:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {023B1249-0C88-4BA7-B6DE-B0ACE838653B} - E:\WINDOWS\Config\svscm.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Picaboo.lnk = E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Qshelf.lnk = E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE



Let me know if there's more to do. But I got to say, things seem to be running better and no popups too!

#9 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 27 December 2006 - 08:55 AM

Hi gcrinsm,

The popups have stopped!



That is great. :thumbsup: Looks like you had a number of infections on your computer.

You ran the Hijackthis log in the Safe Mode, and it will not show all the running proceeses in that mode.
Please restart your computer to the Normal Mode, post a fresh Hijackthis log and I will see if the log is clean.
Thanks. :flowers:

Edited by SifuMike, 27 December 2006 - 08:56 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#10 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 27 December 2006 - 10:57 PM

Here's the fresh HiJack This log that was created in normal mode.

Logfile of HijackThis v1.99.1
Scan saved at 7:56:10 PM, on 12/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\Program Files\Java\jre1.6.0\bin\jusched.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {023B1249-0C88-4BA7-B6DE-B0ACE838653B} - E:\WINDOWS\Config\svscm.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Picaboo.lnk = E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Qshelf.lnk = E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE

#11 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 27 December 2006 - 11:17 PM

Hi gcrinsm,

Smitfraud-C.Toolbar888 item Spybot S&D finds is a false positive, you can ignore it. :flowers: Read about it here: http://forums.spybot.info/showthread.php?t=8668


I only see one item to fix in your log. :thumbsup:

Please disable AVG antispyware Guard, as it may hinder the removal of some HijackThis entries.
You can re-enable it after your computer is clean.
Launch AVG antispyware and in the main window click "Realtime protection" (in green indicating "Active") to change to inactive.



Download CCleaner and install it. (default location is best). Do not run it yet!

CCleaner Tutorial


*******************************************

In Normal Mode, select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix".

O2 - BHO: (no name) - {023B1249-0C88-4BA7-B6DE-B0ACE838653B} - E:\WINDOWS\Config\svscm.dll (file missing)


*******************************************

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders and does not make backups.

Let's empty the temp files:

Run CCleaner.

1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbarfree Basic version instead of the Standard Build.


2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
• Clean all entries in the "Internet Explorer" section except Cookies.
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section.
• Clean all entries in the "Advanced" section.
• Clean any others that you choose.

In the Applications Tab:
• Clean all except cookies in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

If it asks you to reboot at the end, click NO.

CCleaner should be run with the above settings for each User Account!

*******************************************


Finally, reboot to the Normal Mode and post a new Hijackthis log, and tell me how your computer is running.

Edited by SifuMike, 27 December 2006 - 11:19 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#12 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 01 January 2007 - 11:19 PM

Hi SifuMike,
Hope you had a excellent New Year's.

I tried to disable the AVG antispyware Guard and did not find the "realtime protection" control. What I can tell you is that the resident shield is inactive. I do not know if that is the same thing.

Could you give me a few more pointers?

Thank you!

#13 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 02 January 2007 - 10:52 AM

Hi gcrinsm,

What I can tell you is that the resident shield is inactive. I do not know if that is the same thing.


It is the same thing. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#14 gcrinsm

gcrinsm
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:28 PM

Posted 03 January 2007 - 12:26 AM

Hello,
I disabled AVG Antispy, downloaded CCleaner, ran Hijack This, removed the entry, ran CCleaner, and now, I give you the new HiJack This log:

Logfile of HijackThis v1.99.1
Scan saved at 9:22:33 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\wuauclt.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
E:\Program Files\Java\jre1.6.0\bin\jusched.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
E:\PROGRA~1\Yahoo!\browser\ycommon.exe
E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
E:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] E:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [YBrowser] E:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Picaboo.lnk = E:\Program Files\Picaboo\Picaboo\PicabooMain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Qshelf.lnk = E:\Program Files\MS reference\Bookshelf 98\qshelf98.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - E:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - E:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: GhostStartService - Symantec Corporation - E:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE

The computer is running good, and with all the temp files deleted, searches are performing much faster. Who knew I had all of that junk on this disk?!

Thank you for your help. Let me know if there's more.

#15 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:04:28 PM

Posted 03 January 2007 - 12:37 AM

Hi gcrinsm,

Your log looks clean of malware, but we can remove some items to speed up startup time. :thumbsup:


In Normal Mode, select the following with HijackThis.
With all windows (including this one!) closed (close browser/explorer windows), please select "fix.”

The following are not necessarily spyware/malware, but I suggest you place a check mark next to the following entries, as these programs may be taking up system resources. These fixes are optional

O4 - HKLM\..\Run: [SunJavaUpdateSched] \"E:\Program Files\Java\jre1.6.0\bin\jusched.exe\"
(Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)

O4 - Global Startup: Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
(Description: Adjusts monitor colours across all programs, including Photoshop. It is needed by some graphics professionals who want their monitor calibrated. Most home users will not need it, and thus should remove this entry. )

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
(Description: Microsoft Office startup assistant. Not necessary. Removing this entry will free up a significant amount of system resources.)

Run CCleaner to delete the temp files.

Reboot and post a fresh Hijackthis log.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users