Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cid And God Knows What Else


  • Please log in to reply
11 replies to this topic

#1 healingdread

healingdread

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 28 April 2007 - 05:11 AM

Morning all. any ideas guys. driving me mad here, tried all the usual stuff with no joy.......pop ups marked CID on IE; various other pop ups on firefox winantispyware or somesuch, browser freezing, pc freezing needing restart, IE window "cannot display this page you are not connected to the internet" etc etc maybe i should stop my kids using it!!!!!!

Logfile of HijackThis v1.99.1
Scan saved at 11:01:13, on 28/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\aihapnkx.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

Edited by healingdread, 28 April 2007 - 06:44 AM.


BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 28 April 2007 - 06:52 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum healingdread :thumbsup:

Please download Combofix and save to the desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


*************************

Now go to:
C:\Program Files\HijackThis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Posted Image
Posted Image

#3 healingdread

healingdread
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 28 April 2007 - 06:32 PM

"john" - 07-04-29 0:05:27 Service Pack 2
ComboFix 07-04-28.V - Running from: "C:\Documents and Settings\john\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\aihapnkx.dll
C:\WINDOWS\system32\alutojmu.dll
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\bhcwudgx.dll
C:\WINDOWS\system32\dgwcxrrc.dll
C:\WINDOWS\system32\dssisfhl.dll
C:\WINDOWS\system32\eccihvgx.dll
C:\WINDOWS\system32\grxvfdto.dll
C:\WINDOWS\system32\hgggddb.dll
C:\WINDOWS\system32\hgjuhsea.dll
C:\WINDOWS\system32\jiwhfira.dll
C:\WINDOWS\system32\jyjwlqyn.dll
C:\WINDOWS\system32\kvwpvdne.dll
C:\WINDOWS\system32\lbrhhwgo.dll
C:\WINDOWS\system32\lokkkfyn.dll
C:\WINDOWS\system32\mstudvwc.dll
C:\WINDOWS\system32\ngycmhrc.dll
C:\WINDOWS\system32\oowvsdpe.dll
C:\WINDOWS\system32\opnolji.dll
C:\WINDOWS\system32\otojnveb.dll
C:\WINDOWS\system32\pcpstxcr.dll
C:\WINDOWS\system32\pmnmmmm.dll
C:\WINDOWS\system32\qomjkkk.dll
C:\WINDOWS\system32\teixltcg.dll
C:\WINDOWS\system32\tpmmgddy.dll
C:\WINDOWS\system32\tsxqjmin.dll
C:\WINDOWS\system32\tuvvuvv.dll
C:\WINDOWS\system32\twvsccok.dll
C:\WINDOWS\system32\ujcfnrix.dll
C:\WINDOWS\system32\urqpqoo.dll
C:\WINDOWS\system32\vtsidthw.dll
C:\WINDOWS\system32\vtuvwwv.dll
C:\WINDOWS\system32\worpjssj.dll
C:\WINDOWS\system32\xpetyjdy.dll
C:\WINDOWS\system32\yvdowwtd.dll
C:\WINDOWS\system32\xknpahia.ini
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utstv.bak1
C:\WINDOWS\system32\utstv.bak2
C:\WINDOWS\system32\utstv.ini
C:\WINDOWS\system32\utstv.ini2
C:\WINDOWS\system32\dtwwodvy.ini
C:\WINDOWS\system32\nnnkhgf.dll
C:\WINDOWS\system32\vtstu.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((( Files Created from 2007-03-28 to 2007-04-29 ))))))))))))))))))))))))))))))))))


2007-04-27 23:54 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-04-27 01:00 123,972 --a------ C:\WINDOWS\system32\gfqtromw.dll
2007-04-23 13:41 123,972 --a------ C:\WINDOWS\system32\xkgpoeex.dll
2007-04-23 11:20 123,972 --a------ C:\WINDOWS\system32\yghyvson.dll
2007-04-20 22:05 123,972 --a------ C:\WINDOWS\system32\exnvwvpj.dll
2007-04-20 12:20 <DIR> d-------- C:\Program Files\VideoEgg
2007-04-17 09:37 <DIR> d-------- C:\Program Files\DietMP3
2007-04-13 02:39 <DIR> d-------- C:\Program Files\Lavasoft
2007-04-13 02:39 <DIR> d-------- C:\DOCUME~1\drew\APPLIC~1\Lavasoft
2007-04-12 11:58 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-03-28 14:17 <DIR> d-------- C:\DOCUME~1\john\APPLIC~1\SuperAdBlocker.com
2007-03-28 04:04 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-03-28 04:04 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-03-28 04:01 <DIR> d-------- C:\WINDOWS\Internet Logs


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-18 17:16 733824 --a------ C:\WINDOWS\system32\aswboot.exe
2007-04-18 17:12 94552 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-18 17:12 85952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-18 17:10 23416 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-18 17:09 43176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-18 17:07 26888 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-18 17:06 90112 --a------ C:\WINDOWS\system32\avastss.scr
2007-04-13 11:28 -------- d-------- C:\Program Files\limewire
2007-04-13 00:49 -------- d-------- C:\Program Files\msn messenger
2007-04-12 09:32 -------- d-------- C:\Program Files\windows live safety center
2007-04-02 01:00 -------- d-------- C:\Program Files\soulseek
2007-03-18 01:45 -------- d-------- C:\Program Files\itunes
2007-03-18 01:44 -------- d-------- C:\Program Files\ipod
2007-03-17 14:43 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-16 16:59 -------- d-------- C:\Program Files\multi part joy
2007-03-08 16:36 577536 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 16:36 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 16:36 281600 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 14:47 1843584 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-06 22:20 -------- d-------- C:\Program Files\quicktime
2007-03-01 01:42 -------- d-------- C:\Program Files\windows defender
2007-02-16 18:55 2891 --a--c--- C:\WINDOWS\mozver.dat
2007-02-12 18:29 59232 --a------ C:\WINDOWS\system32\sourceplug.dll
2007-02-12 18:29 257376 --a------ C:\WINDOWS\system32\medialogic.dll
2007-02-05 21:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll
2007-02-01 05:56 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2007-02-01 05:56 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll
2007-02-01 05:56 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll
2007-02-01 05:56 639066 --a------ C:\WINDOWS\system32\divx.dll
2007-01-31 22:27 524288 --a------ C:\WINDOWS\system32\divxsm.exe
2007-01-31 00:15 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe
2007-01-30 06:03 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-01-30 06:03 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-01-30 06:03 129784 --------- C:\WINDOWS\system32\pxafs.dll
2007-01-30 06:03 118520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-01-30 06:03 116472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-01-30 06:03 1044480 --a--c--- C:\WINDOWS\system32\libdivx.dll
2007-01-30 05:56 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2007-01-30 05:56 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2007-01-30 05:56 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2007-01-30 05:56 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2007-01-30 05:56 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2007-01-30 05:56 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2007-01-30 05:56 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2007-01-30 05:56 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2007-01-17 11:39 84480 --a------ C:\DOCUME~1\john\APPLIC~1\gdipfontcachev1.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{1557B435-8242-4686-9AA3-9265BF7525A4}"="C:\WINDOWS\system32\anultpvn.dll" [x]
"{1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A}"="C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll" [x]
"{53707962-6F74-2D53-2644-206D7942484F}"="C:\PROGRA~1\SPYBOT~1\SDHelper.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll"
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"="C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll"
"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\program files\google\googletoolbar4.dll"
"{D651AFF4-9590-424d-BD1E-8E33E090DFB3}"="C:\WINDOWS\system32\rftfifuq.dll" [x]
"{FF20D9A2-C5E4-454E-B2D5-EAB0390C5891}"="C:\WINDOWS\system32\qugqbmuu.dll" [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NWEReboot"=""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"EPSON Stylus CX3200"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S10IC2.EXE /P19 \"EPSON Stylus CX3200\" /O6 \"USB001\" /M \"Stylus CX3200\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
bthsvcs REG_MULTI_SZ BthServ\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\B4C8C008957B7200.job
C:\WINDOWS\tasks\chkdsk.job
C:\WINDOWS\tasks\defrag.job
C:\WINDOWS\tasks\Disk Cleanup.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-29 00:12:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-04-29 0:15:11 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-29 00:15



Logfile of HijackThis v1.99.1
Scan saved at 00:27:15, on 29/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\abc.bat.exe

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\anultpvn.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\rftfifuq.dll (file missing)
O2 - BHO: (no name) - {FF20D9A2-C5E4-454E-B2D5-EAB0390C5891} - C:\WINDOWS\system32\qugqbmuu.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

as requested richieUK. thanks

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 02:46 AM

First disable Windows Defender's real-time protection,or it will interfere.
* Open Microsoft Windows Defender. Click Start>All Programs>Windows Defender.
* Click on 'Tools'>'Options'.
* Under 'Real-time protection options', unselect the 'Turn on real-time protection' check box
* Click 'Save'.

**********************************

Please disable Spybot S&Dís protection,or it will interfere.
You can enable it after you're clean.
Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

**********************************

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\WINDOWS\system32\gfqtromw.dll
C:\WINDOWS\system32\xkgpoeex.dll
C:\WINDOWS\system32\yghyvson.dll
C:\WINDOWS\system32\exnvwvpj.dll

Folders to delete:
C:\Program Files\multi part joy

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.

*******************************

Click on Start>Control Panel>Add/Remove Programs.
Uninstall/remove any of the following programs if listed:
Netpumper
Bitroll
Bitgrabber
CiD Help / CiD Manager
Download Plugin for Internet Explorer
Zone Media

This is because they are often bundled with the malware you are dealing with.
Don't worry if none of them are present.
If you happened to remove any of them please restart your pc.

******************************

Download NoLop.exe to your desktop.

* First close any other programs you have running as this will require a reboot.
* Double click NoLop.exe to run it.
* Then click the button labelled "Search and Destroy".
* When scanning is finished you will be prompted to reboot only if infected,click 'OK'.
* Now click the "REBOOT" Button.
* A Message should popup from NoLop, if not,double click the program again and it will finish.
Post the contents of C:\NoLop.log,the Avenger output.txt, and a new Hijack This log into your next reply.

If you receive the error,that mscomctl.ocx or one of its dependencies are not correctly registered, please download this file to your 'System32' folder then rerun the program: http://www.boletrice.com/downloads/mscomctl.ocx
Posted Image
Posted Image

#5 healingdread

healingdread
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 06:42 AM

couldnt see "allow change" on the spybot after checking the tickbox. the tea timer seemed to stay on startup as the icon remained at bottom of screen. had to disable it from there.

NoLop! Log by Skate_Punk_21

Fix running from: C:\Documents and Settings\john\Desktop
[29/04/2007]
[12:12:01]

---Infection Files Found/Removed---
C:\WINDOWS\tasks\B4C8C008957B7200.job

Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**

---Listing AppData sub directories---

C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Adobe Systems
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Bleh Meal Wipe Owns
C:\Documents and Settings\All Users\Application Data\Driving Test Success
C:\Documents and Settings\All Users\Application Data\Google
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Microsoft Corporation -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Pixelstorm
C:\Documents and Settings\All Users\Application Data\Sony Ericsson
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Application Data\Starware347
C:\Documents and Settings\All Users\Application Data\Temp -- EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Videoegg
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Yahoo!
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Drew\Application Data\Adobe
C:\Documents and Settings\Drew\Application Data\Apple Computer
C:\Documents and Settings\Drew\Application Data\Arcsoft
C:\Documents and Settings\Drew\Application Data\Divx
C:\Documents and Settings\Drew\Application Data\Dvdcss
C:\Documents and Settings\Drew\Application Data\Epson
C:\Documents and Settings\Drew\Application Data\Google
C:\Documents and Settings\Drew\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\Drew\Application Data\Identities
C:\Documents and Settings\Drew\Application Data\Im-names
C:\Documents and Settings\Drew\Application Data\Lavasoft
C:\Documents and Settings\Drew\Application Data\Limewire
C:\Documents and Settings\Drew\Application Data\Macromedia
C:\Documents and Settings\Drew\Application Data\Microsoft
C:\Documents and Settings\Drew\Application Data\Mozilla
C:\Documents and Settings\Drew\Application Data\Msninstaller
C:\Documents and Settings\Drew\Application Data\Multi Part Joy
C:\Documents and Settings\Drew\Application Data\Screenshot Sender
C:\Documents and Settings\Drew\Application Data\Sun
C:\Documents and Settings\Drew\Application Data\Vlc
C:\Documents and Settings\Guest\Application Data\Adobe
C:\Documents and Settings\Guest\Application Data\Apple Computer
C:\Documents and Settings\Guest\Application Data\Google
C:\Documents and Settings\Guest\Application Data\Identities
C:\Documents and Settings\Guest\Application Data\Limewire
C:\Documents and Settings\Guest\Application Data\Macromedia
C:\Documents and Settings\Guest\Application Data\Microsoft
C:\Documents and Settings\Guest\Application Data\Mozilla
C:\Documents and Settings\John\Application Data\Adobe
C:\Documents and Settings\John\Application Data\Adobeum -- EMPTY Directory
C:\Documents and Settings\John\Application Data\Apple Computer
C:\Documents and Settings\John\Application Data\Divx
C:\Documents and Settings\John\Application Data\Dvdcss
C:\Documents and Settings\John\Application Data\Epson
C:\Documents and Settings\John\Application Data\Google
C:\Documents and Settings\John\Application Data\Help -- EMPTY Directory
C:\Documents and Settings\John\Application Data\Identities
C:\Documents and Settings\John\Application Data\Im-names
C:\Documents and Settings\John\Application Data\Lavasoft
C:\Documents and Settings\John\Application Data\Leadertech
C:\Documents and Settings\John\Application Data\Macromedia
C:\Documents and Settings\John\Application Data\Microsoft
C:\Documents and Settings\John\Application Data\Mozilla
C:\Documents and Settings\John\Application Data\Msn6
C:\Documents and Settings\John\Application Data\Msninstaller
C:\Documents and Settings\John\Application Data\Opera -- EMPTY Directory
C:\Documents and Settings\John\Application Data\Sun
C:\Documents and Settings\John\Application Data\Superadblocker.com
C:\Documents and Settings\John\Application Data\Talkback
C:\Documents and Settings\John\Application Data\Vlc
C:\Documents and Settings\John\Application Data\Zangotoolbar
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Networkservice\Application Data\Microsoft

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\uqaqxdmx

*******************

Script file located at: \??\C:\Documents and Settings\rhfxpjkf.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\gfqtromw.dll deleted successfully.
File C:\WINDOWS\system32\xkgpoeex.dll deleted successfully.
File C:\WINDOWS\system32\yghyvson.dll deleted successfully.
File C:\WINDOWS\system32\exnvwvpj.dll deleted successfully.
Folder C:\Program Files\multi part joy deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Logfile of HijackThis v1.99.1
Scan saved at 12:24:49, on 29/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\abc.bat.exe

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\anultpvn.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\rftfifuq.dll (file missing)
O2 - BHO: (no name) - {FF20D9A2-C5E4-454E-B2D5-EAB0390C5891} - C:\WINDOWS\system32\qugqbmuu.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 07:13 AM

Please make sure all hidden files are showing:

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

*******************************

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\anultpvn.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\rftfifuq.dll (file missing)
O2 - BHO: (no name) - {FF20D9A2-C5E4-454E-B2D5-EAB0390C5891} - C:\WINDOWS\system32\qugqbmuu.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)


Exit Hijackthis,find and delete:
C:\Documents and Settings\All Users\Application Data\Bleh Meal Wipe Owns
C:\Documents and Settings\All Users\Application Data\Starware347
C:\Documents and Settings\Drew\Application Data\Multi Part Joy
C:\Documents and Settings\John\Application Data\Zangotoolbar

Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#7 healingdread

healingdread
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 01:00 PM

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 18:34:56 29/04/2007

+ Scan result:



C:\Program Files\Image ActiveX Object -> Adware.Generic : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\hgggddb.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\nnnkhgf.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\opnolji.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\pmnmmmm.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\qomjkkk.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tuvvuvv.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqpqoo.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\vtuvwwv.dll.vir -> Adware.Virtumonde : Cleaned.
:mozilla.142:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.118:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.124:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.125:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.126:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.174:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.257:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.290:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.482:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.509:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.510:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.525:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.526:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.527:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.529:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.576:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.608:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.633:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.721:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.774:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.94:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.97:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\john\Cookies\john@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\john\Cookies\john@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.813:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.814:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.815:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.52:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.53:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.54:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.55:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.56:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.72:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.73:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.74:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.75:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.76:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.82:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\john\Cookies\john@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.160:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.161:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.22:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.23:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.35:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.43:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\john\Cookies\john@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.120:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.129:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.130:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.131:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@cz7.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.155:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.156:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.161:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.259:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.263:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.264:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.265:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.266:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.48:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.49:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.50:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\john\Cookies\john@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\john\Cookies\john@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.37:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.57:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\john\Cookies\john@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.308:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.309:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.310:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.311:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.312:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.313:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.314:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.315:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.316:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.317:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.318:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.319:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.320:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.321:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.322:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.323:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.324:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.325:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.326:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.327:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.328:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.329:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.330:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.147:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.148:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.149:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.959:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.960:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.961:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.962:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.132:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.12:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.434:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.435:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.436:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.437:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
C:\Documents and Settings\john\Cookies\john@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.851:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Intelli-tracker : Cleaned.
:mozilla.458:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.671:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.672:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.673:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\john\Cookies\john@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.70:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.71:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.83:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
:mozilla.189:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.707:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.708:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\john\Cookies\john@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.603:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.604:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.618:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\john\Cookies\john@data3.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.884:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\john\Cookies\john@www.paypal[2].txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.157:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.158:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.159:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.639:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.640:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.183:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.184:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.641:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.642:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.646:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.761:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.133:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.134:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.134:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.135:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.136:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.137:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.138:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.652:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.185:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.186:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.187:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.188:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.653:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.654:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.655:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.656:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.657:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.658:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.114:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.115:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.116:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.117:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.118:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.119:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.58:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.59:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.60:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.61:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.62:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.63:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\john\Cookies\john@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\john\Cookies\john@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.762:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
C:\Documents and Settings\john\Cookies\john@site.skype[1].txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\john\Cookies\john@skype[2].txt -> TrackingCookie.Skype : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@statistik-gallup[1].txt -> TrackingCookie.Statistik-gallup : Cleaned.
:mozilla.732:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.733:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.193:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.744:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\john\Cookies\john@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.112:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.113:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.94:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\john\Cookies\john@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.128:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.51:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.790:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.791:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.101:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.107:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.200:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\john\Cookies\john@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.142:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.944:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.24:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.29:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.31:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.32:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.33:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.34:C:\Documents and Settings\drew\Application Data\Mozilla\Firefox\Profiles\o6fyfma3.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.951:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.957:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.958:C:\Documents and Settings\john\Application Data\Mozilla\Firefox\Profiles\6jtns7x4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\drew\Cookies\drew@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 18:49:20, on 29/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HijackThis\abc.bat.exe

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\anultpvn.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\rftfifuq.dll (file missing)
O2 - BHO: (no name) - {FF20D9A2-C5E4-454E-B2D5-EAB0390C5891} - C:\WINDOWS\system32\qugqbmuu.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

just used IE for 5 minutes without any CIDs or other inconveniences.bit slow to open IE but otherwise so far so good. seems that according to the hijackthis log that the files(?) ticked and removed are still there. is this right? otherwise thanks big time

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 01:53 PM

seems that according to the hijackthis log that the files(?) ticked and removed are still there. is this right?

Thats correct,Spybots Tea-Timer and Windows Defender are both still running,you have'nt disabled them correctly.
Click on Start/Control Panel/Add or Remove Programs and remove/uninstall Spybot Search and Destroy and Windows Defender,then restart your pc.
You can reinstall them after you're clean.

***********************************

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\anultpvn.dll (file missing)
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\rftfifuq.dll (file missing)
O2 - BHO: (no name) - {FF20D9A2-C5E4-454E-B2D5-EAB0390C5891} - C:\WINDOWS\system32\qugqbmuu.dll (file missing)
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)


Exit Hijackthis,make sure the following are indeed deleted:

C:\Documents and Settings\All Users\Application Data\Bleh Meal Wipe Owns
C:\Documents and Settings\All Users\Application Data\Starware347
C:\Documents and Settings\Drew\Application Data\Multi Part Joy
C:\Documents and Settings\John\Application Data\Zangotoolbar

Restart your pc,post a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#9 healingdread

healingdread
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 05:20 PM

Logfile of HijackThis v1.99.1
Scan saved at 23:06:25, on 29/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HijackThis\abc.bat.exe

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by124w.bay124.mail.live.com/mail/re...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

no obvious problems far as i can see. does that R3/ SweetIM entry need to go too? all clear in the Docs and Settings.

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 29 April 2007 - 05:41 PM

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
Exit Hijackthis.

****************************

Download\install Spybot - Search and Destroy:
http://www.snapfiles.com/get/spybot.html

Download\install Windows Defender:
http://www.microsoft.com/athome/security/s...re/default.mspx

****************************

Your log is clean :thumbsup:
If all's ok,please do the following:

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading unselect 'Show hidden files and folders'.
* Re-check the 'Hide file extensions for known types' option.
* Re-check the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

Please Note:
Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u1'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.
Posted Image
Posted Image

#11 healingdread

healingdread
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 30 April 2007 - 05:42 PM

huge thanks dude. all seems good. i have read that one anti virus is best. am minded to remove the avg. should i leave all the downloaded programs, logs and files intact. :thumbsup:

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 01 May 2007 - 03:46 AM

You're welcome :thumbsup:

You can now remove/uninstall AVG Anti-Spyware and Hijackthis if you wish,via Control Panel/Add or Remove Programs.

Find and delete:
C:\QooBox
C:\NoLop
C:\Avenger
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users