Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack Log- Need To Be Look At & Anaylized


  • This topic is locked This topic is locked
15 replies to this topic

#1 truvisions

truvisions

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 09:37 AM

Logfile of HijackThis v1.99.1
Scan saved at 9:32:44 AM, on 5/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Trirot.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}\Update.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\XWatDog.exe
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [Trirot] Trirot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{74E6974C-0AE6-1033-0930-040601200001}] "C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}\Update.exe" mc-110-12-0001670
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\anadbhmb.dll",realset
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs:
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

:thumbsup:

BC AdBot (Login to Remove)

 


m

#2 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 09:44 AM

I still have Powered by ZEDO popups

#3 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:17 AM

Posted 04 May 2007 - 10:13 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum truvisions :thumbsup:

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as..Save as Type: 'All Files' File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktop and agree to merge it into the registry,then reboot.

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=-

****************************

Please download Combofix and save to the desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


****************************

Now go to:
C:\Program Files\HijackThis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Posted Image
Posted Image

#4 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 10:38 AM

"petee" - 2007-05-04 10:20:07 Service Pack 2
ComboFix 07-05.04.3.V - Running from: "C:\Documents and Settings\petee\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\gebyy.dll
C:\WINDOWS\system32\jkhhe.dll
C:\WINDOWS\system32\jkklk.dll
C:\WINDOWS\system32\pmkjg.dll
C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\abudwivk.dll
C:\WINDOWS\system32\anadbhmb.dll
C:\WINDOWS\system32\awtqp.dll
C:\WINDOWS\system32\awtrpno.dll
C:\WINDOWS\system32\awtrsts.dll
C:\WINDOWS\system32\awttrss.dll
C:\WINDOWS\system32\awttstt.dll
C:\WINDOWS\system32\cbxwust.dll
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\ddcbcyy.dll
C:\WINDOWS\system32\ddccc.dll
C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\eiwossnj.dll
C:\WINDOWS\system32\euiakfbe.dll
C:\WINDOWS\system32\gebcccd.dll
C:\WINDOWS\system32\gebxvtu.dll
C:\WINDOWS\system32\hsdiefgn.dll
C:\WINDOWS\system32\iiccgcms.dll
C:\WINDOWS\system32\jkklklm.dll
C:\WINDOWS\system32\jpmpebxu.dll
C:\WINDOWS\system32\khfgfec.dll
C:\WINDOWS\system32\lgejcxre.dll
C:\WINDOWS\system32\mcexjtst.dll
C:\WINDOWS\system32\mljifdd.dll
C:\WINDOWS\system32\noxdeqvg.dll
C:\WINDOWS\system32\nqwyvutq.dll
C:\WINDOWS\system32\nwyckkok.dll
C:\WINDOWS\system32\opnkijg.dll
C:\WINDOWS\system32\opnmjgg.dll
C:\WINDOWS\system32\pfcvmjqy.dll
C:\WINDOWS\system32\pmnmnon.dll
C:\WINDOWS\system32\pmnnl.dll
C:\WINDOWS\system32\qomkklm.dll
C:\WINDOWS\system32\qpirjdll.dll
C:\WINDOWS\system32\qyqgvqiv.dll
C:\WINDOWS\system32\rblefghd.dll
C:\WINDOWS\system32\rqrpool.dll
C:\WINDOWS\system32\rqrpqrr.dll
C:\WINDOWS\system32\rqrqnlj.dll
C:\WINDOWS\system32\rqrrrop.dll
C:\WINDOWS\system32\rqrspml.dll
C:\WINDOWS\system32\sosoouqo.dll
C:\WINDOWS\system32\sqcalurb.dll
C:\WINDOWS\system32\sshpujai.dll
C:\WINDOWS\system32\ssqnmnn.dll
C:\WINDOWS\system32\ssqqolj.dll
C:\WINDOWS\system32\sujblxsc.dll
C:\WINDOWS\system32\totghlui.dll
C:\WINDOWS\system32\uqfsfpns.dll
C:\WINDOWS\system32\urqrsrs.dll
C:\WINDOWS\system32\vmvmtsgu.dll
C:\WINDOWS\system32\vtsqo.dll
C:\WINDOWS\system32\vtsqq.dll
C:\WINDOWS\system32\vtutqpo.dll
C:\WINDOWS\system32\vtuursq.dll
C:\WINDOWS\system32\wqyijdwl.dll
C:\WINDOWS\system32\wxhblpcf.dll
C:\WINDOWS\system32\xamuxdof.dll
C:\WINDOWS\system32\xvdlpitr.dll
C:\WINDOWS\system32\xxyyyxv.dll
C:\WINDOWS\system32\bmhbdana.ini
C:\WINDOWS\system32\stvwa.bak1
C:\WINDOWS\system32\stvwa.bak2
C:\WINDOWS\system32\stvwa.ini
C:\WINDOWS\system32\awvts.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\57412040.exe
C:\WINDOWS\system32\packet.dll
C:\Program Files\Common Files\{34E69~1\Bar888.dll
C:\Program Files\Common Files\{34E69~1\UnInstall.exe
C:\Program Files\Common Files\{74E69~1\system.dll
C:\Program Files\Common Files\{74E69~1\Update.exe
C:\windows\system32\explorer.exe
C:\WINDOWS\system32\IExplorer.dll .dbt
C:\WINDOWS\notedad.exe
C:\WINDOWS\system32\drivers\npf.sys
C:\Program Files\Common Files\{34E69~1
C:\Program Files\Common Files\{74E69~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\petee
C:\qoobox\purity\C\DOCUME~1\petee\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\petee\APPLIC~1\ICROSO~1

Infected copy of C:\WINDOWS\system32\winlogon.exe was found & disinfected
Restored copy from - "C:\WINDOWS\system32\dllcache\winlogon.exe"



((((((((((((((((((((((((((((((( Files Created from 2007-04-04 to 2007-05-04 ))))))))))))))))))))))))))))))))))


2007-05-04 09:27 82,096 --a------ C:\DOCUME~1\petee\APPLIC~1\sysprotectscannerinstall[1].exe
2007-05-04 09:26 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
2007-05-04 09:16 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-05-04 09:16 4,212 --ah----- C:\WINDOWS\system32\zllictbl.dat
2007-05-04 09:16 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-05-04 09:15 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-05-04 09:15 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-05-04 09:15 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-05-04 08:20 <DIR> d-------- C:\DOCUME~1\petee\.housecall6.6
2007-05-03 22:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-01 12:04 32,768 --a------ C:\WINDOWS\system32\mp43.exe
2007-04-19 23:54 212 --a------ C:\delete.bat
2007-04-18 14:24 <DIR> d-------- C:\pcx1100u usb drivers
2007-04-18 11:54 <DIR> d-------- C:\Program Files\Common Files\ParetoLogic
2007-04-18 11:20 <DIR> d-------- C:\Program Files\support.com
2007-04-18 11:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Support.com
2007-04-10 13:19 <DIR> d-------- C:\HJT
2007-04-10 13:16 <DIR> d-------- C:\Avenger


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-04 14:54:50 -------- d-----w C:\Program Files\FriendBlasterPro
2007-05-04 14:27:28 82,096 ----a-w C:\DOCUME~1\petee\APPLIC~1.\sysprotectscannerinstall[1].exe
2007-04-20 05:36:31 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-04-20 05:36:27 -------- d-----w C:\Program Files\NETGEAR GA511 Adapter
2007-04-20 05:14:41 -------- d-----w C:\Program Files\WinFax
2007-04-20 05:14:35 -------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-04-20 04:38:35 -------- d-----w C:\Program Files\uTorrent
2007-04-20 04:37:25 -------- d-----w C:\DOCUME~1\petee\APPLIC~1.\LoadLiteNew
2007-04-10 14:14:32 1,227,522 --sha-w C:\WINDOWS\system32\ijjlm.bak1
2007-04-09 14:08:23 1,227,467 --sha-w C:\WINDOWS\system32\ijjlm.bak2
2007-04-02 15:38:29 -------- d-----w C:\DOCUME~1\petee\APPLIC~1.\uTorrent
2007-04-01 03:06:59 71,243 ----a-w C:\WINDOWS\system32\ddccb.dll
2007-03-31 06:28:40 38,725 ----a-w C:\lis.exe
2007-03-27 01:38:06 32,768 ----a-w C:\WINDOWS\system32\svchtoost.exe
2007-03-13 04:03:52 -------- d-----w C:\Program Files\Space Station
2007-02-23 17:59:40 41 ----a-w C:\WINDOWS\WFXDEL.BAT


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{53707962-6F74-2D53-2644-206D7942484F}"="C:\PROGRA~1\SPYBOT~1\SDHelper.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll"
"{C830A8B5-506C-457C-B507-E507C2FF326F}"="C:\WINDOWS\system32\mljji.dll" [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"XGIWatchDog"="C:\\Program Files\\XGI\\XWatDog.exe"
"RegServer"="regserve.exe"
"Trirot"="Trirot.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"SSBkgdUpdate"="\"C:\\Program Files\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot"
"PaperPort PTD"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe"
"IndexSearch"="C:\\Program Files\\ScanSoft\\PaperPort\\IndexSearch.exe"
"BrMfcWnd"="C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe /AUTORUN"
"SetDefPrt"="C:\\Program Files\\Brother\\Brmfl06a\\BrStDvPt.exe"
"ControlCenter3"="C:\\Program Files\\Brother\\ControlCenter3\\brctrcen.exe /autorun"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Aim6"=""
"ParetoLogic Anti-Spyware"="\"C:\\Program Files\\ParetoLogic\\Anti-Spyware\\Pareto_AS.exe\" -NM -hidesplash"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{51C55F9E-C308-4c95-89AB-8858D8AFD819}"="C:\Program Files\ParetoLogic\Anti-Spyware\PASShlExt.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebxvtu
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqrqnlj
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnmnn

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\0\0
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
DcomLaunch DcomLaunch\0TermService\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\ParetoLogic Anti-Spyware.job
C:\WINDOWS\tasks\ParetoLogic Update.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-04 10:28:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-04 10:29:17 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-04 10:29

#5 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 10:40 AM

Logfile of HijackThis v1.99.1
Scan saved at 10:36:53 AM, on 5/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Trirot.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HijackThis\abc.bat.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O2 - BHO: (no name) - {058DB58B-1A37-44F6-8910-04332FECADCB} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68F77687-E89C-4D57-B17E-6AF7FFE7DF08} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {8EC3DE0E-3E4F-4E36-BB13-EE24AB07B1D7} - (no file)
O2 - BHO: (no name) - {B0BDAF5A-E9B6-472D-B10E-1AA5C0EC59A6} - (no file)
O2 - BHO: (no name) - {C830A8B5-506C-457C-B507-E507C2FF326F} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {CE771055-5E6C-4BC3-8E27-DB3DD4574C88} - (no file)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - (no file)
O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\XWatDog.exe
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [Trirot] Trirot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{74E6974C-0AE6-1033-0930-040601200001}] "C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}\Update.exe" mc-110-12-0001670
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: awvts - C:\WINDOWS\
O20 - Winlogon Notify: gebxvtu - C:\WINDOWS\
O20 - Winlogon Notify: rqrqnlj - C:\WINDOWS\
O20 - Winlogon Notify: ssqnmnn - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#6 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 10:41 AM

I had a program that i used all the time..

Friendblaster Pro for MySpace.. & now when i click on it..

it says.. check for INTERNET CONNECTION.. anyideas??

#7 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:17 AM

Posted 04 May 2007 - 10:57 AM

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
C:\lis.exe
C:\WINDOWS\system32\mp43.exe
C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.bak2
C:\WINDOWS\system32\ddccb.dll
C:\WINDOWS\system32\svchtoost.exe
C:\Documents and Settings\petee\Application Data\sysprotectscannerinstall[1].exe

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.
Also post a new Hijackthis log please.
Posted Image
Posted Image

#8 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 11:06 AM

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bqhjwuil

*******************

Script file located at: \??\C:\Program Files\cwidlweh.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\lis.exe deleted successfully.
File C:\WINDOWS\system32\mp43.exe deleted successfully.
File C:\WINDOWS\system32\ijjlm.bak1 deleted successfully.
File C:\WINDOWS\system32\ijjlm.bak2 deleted successfully.
File C:\WINDOWS\system32\ddccb.dll deleted successfully.
File C:\WINDOWS\system32\svchtoost.exe deleted successfully.
File C:\Documents and Settings\petee\Application Data\sysprotectscannerinstall[1].exe deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

#9 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 11:07 AM

Logfile of HijackThis v1.99.1
Scan saved at 11:04:32 AM, on 5/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Trirot.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\HijackThis\abc.bat.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O2 - BHO: (no name) - {058DB58B-1A37-44F6-8910-04332FECADCB} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68F77687-E89C-4D57-B17E-6AF7FFE7DF08} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {8EC3DE0E-3E4F-4E36-BB13-EE24AB07B1D7} - (no file)
O2 - BHO: (no name) - {B0BDAF5A-E9B6-472D-B10E-1AA5C0EC59A6} - (no file)
O2 - BHO: (no name) - {C830A8B5-506C-457C-B507-E507C2FF326F} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {CE771055-5E6C-4BC3-8E27-DB3DD4574C88} - (no file)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - (no file)
O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\XWatDog.exe
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [Trirot] Trirot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{74E6974C-0AE6-1033-0930-040601200001}] "C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}\Update.exe" mc-110-12-0001670
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: awvts - C:\WINDOWS\
O20 - Winlogon Notify: gebxvtu - C:\WINDOWS\
O20 - Winlogon Notify: rqrqnlj - C:\WINDOWS\
O20 - Winlogon Notify: ssqnmnn - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

:thumbsup:

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:17 AM

Posted 04 May 2007 - 12:03 PM

Please disable Spybot S&Dís protection,or it will interfere.
You can enable it after you're clean.
Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Reboot the computer.

*************************

Click on Start>Run and type Services.msc then hit Ok.
Scroll down and find the service called:
Viewpoint Manager Service
When you find it, double-click on it.
In the next window that opens, click the 'Stop' button.
Then change the 'Startup Type:' to 'Disabled'.
Now press Apply and then Ok and close any open windows.

*************************

Please make sure all hidden files are showing:

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.
* Uncheck the 'Hide file extensions for known types' option.
* Uncheck the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

*******************************

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

O2 - BHO: (no name) - {058DB58B-1A37-44F6-8910-04332FECADCB} - (no file)
O2 - BHO: (no name) - {68F77687-E89C-4D57-B17E-6AF7FFE7DF08} - (no file)
O2 - BHO: (no name) - {8EC3DE0E-3E4F-4E36-BB13-EE24AB07B1D7} - (no file)
O2 - BHO: (no name) - {B0BDAF5A-E9B6-472D-B10E-1AA5C0EC59A6} - (no file)
O2 - BHO: (no name) - {C830A8B5-506C-457C-B507-E507C2FF326F} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {CE771055-5E6C-4BC3-8E27-DB3DD4574C88} - (no file)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - (no file)
O4 - HKLM\..\Run: [{74E6974C-0AE6-1033-0930-040601200001}] "C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}\Update.exe" mc-110-12-0001670
O20 - Winlogon Notify: awvts - C:\WINDOWS\
O20 - Winlogon Notify: gebxvtu - C:\WINDOWS\
O20 - Winlogon Notify: rqrqnlj - C:\WINDOWS\
O20 - Winlogon Notify: ssqnmnn - C:\WINDOWS\
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)


Exit Hijackthis,find and delete if present:
C:\Program Files\Common Files\{74E6974C-0AE6-1033-0930-040601200001}

Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

******************************

You've no virus protection installed.
Download\install one of the following freeware options from the choice below.
Once installed update its definitions and then run a full system virus scan.

AVG7 Free Edition Antivirus:
http://free.grisoft.com/softw/70free/setup...ree_446a965.exe

Avast! 4 Home Edition:
http://files.avast.com/iavs4pro/setupeng.exe

Active Virus Shield
There's a nice setup tutorial Here:
http://www.activevirusshield.com/antivirus/freeav/

******************************

Restart your pc.
Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#11 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 04 May 2007 - 05:41 PM

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:30:36 PM 5/4/2007

+ Scan result:



C:\QooBox\Quarantine\C\WINDOWS\system32\pfcvmjqy.dll.vir -> Adware.BHO : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\qyqgvqiv.dll.vir -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017601.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017606.dll -> Adware.BHO : Cleaned with backup (quarantined).
HKLM\SYSTEM\ControlSet001\Enum\IDE\CdRomSONY_DVD+RW_DW-R56A_____________________QDS1____\5&7ee737c&0&0.0.0\\LowerFilters -> Adware.eScorcher : Error during cleaning.
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0010528.dll -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0010529.exe -> Adware.Maxifiles : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP59\A0006130.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP59\A0006131.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{74E69~1\Update.exe.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{74E69~1\system.dll.vir -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0010513.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0016002.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0016003.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP82\A0017204.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP82\A0017205.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017356.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017357.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017358.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017359.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017560.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017561.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017757.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/lis.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP63\A0006320.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\awtrpno.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\awtrsts.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\awttrss.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\awttstt.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\cbxwust.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcbcyy.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\gebcccd.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\gebxvtu.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\jkklklm.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\khfgfec.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\mljifdd.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\opnkijg.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\opnmjgg.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\pmnmnon.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\qomkklm.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrpool.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrpqrr.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrqnlj.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrrrop.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\rqrspml.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ssqnmnn.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ssqqolj.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\urqrsrs.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\vtutqpo.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\vtuursq.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\xxyyyxv.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017575.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017576.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017577.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017578.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017579.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017581.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017586.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017587.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017590.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017592.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017595.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017599.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017600.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017602.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017604.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017608.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017609.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017610.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017611.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017612.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017616.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017617.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017621.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017625.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017626.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017631.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0010462.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0010463.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011603.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011604.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011606.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011607.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\SDFix\SDFix\backups\backups.zip/backups/msngr.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011548.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011559.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
D:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP73\A0008597.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\SDFix\SDFix\backups\backups.zip/backups/setup.exe -> Downloader.Agent.aii : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011561.exe -> Downloader.Agent.aii : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011473.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP81\A0016074.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP82\A0017166.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
D:\Software\AdbeRdr80_en_US.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1122OinAdmin.exe.vir -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017554.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\57412040.exe.vir -> Downloader.Tiny.fy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017556.exe -> Downloader.Tiny.fy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP63\A0006323.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP63\A0006319.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP63\A0006322.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP63\A0006321.exe -> Downloader.TSUpdate.p : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP82\A0017261.EXE -> Downloader.VB.ahq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017759.exe -> Downloader.VB.ahq : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/svchtoost.exe -> Downloader.VB.ahq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP83\A0017760.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\avenger\backup.zip/avenger/sysprotectscannerinstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\Documents and Settings\petee\Cookies\petee@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@dminsite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@4.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adengage[1].txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adengage[2].txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@epilot[2].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@e-2dj6wfkiclczoko.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@e-2dj6wjlosncpcho.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@cdn.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@hit.gemius[1].txt -> TrackingCookie.Gemius : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@linkbuddies[1].txt -> TrackingCookie.Linkbuddies : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@www.popuptraffic[2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@roispy[1].txt -> TrackingCookie.Roispy : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\system32\config\systemprofile\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\petee\Cookies\petee@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
D:\Software\osadobephotoshopcs2tryouttofullactivationkeygenoscaria\crack.exe -> Trojan.Agent.aae : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\Bolt film acid platform\CloseGreat.exe -> Trojan.Obfuscated.bk : Cleaned with backup (quarantined).
C:\Documents and Settings\petee\Application Data\LoadLiteNew\xdqgneup.exe -> Trojan.Obfuscated.bk : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\Bolt film acid platform\grammapi.exe -> Trojan.Obfuscated.en : Cleaned with backup (quarantined).
C:\Documents and Settings\petee\Application Data\LoadLiteNew\gjcnazbs.exe -> Trojan.Obfuscated.en : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0009457.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0009458.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP79\A0009459.dll -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP59\A0006113.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{63FE7BB4-DB2E-4BD4-ADFC-9C3BA9D8A63C}\RP80\A0011472.exe -> Trojan.Small.mf : Cleaned with backup (quarantined).


::Report end



this is some crazy high tech stuff.. i hope i did everything ok??

i have pareto spyware??

is that good??

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:17 AM

Posted 05 May 2007 - 02:09 AM

Could you post the new Hijackthis log please,also let me know how your pc is running now.
Posted Image
Posted Image

#13 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 05 May 2007 - 09:56 AM

Logfile of HijackThis v1.99.1
Scan saved at 9:51:45 AM, on 5/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Trirot.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\abc.bat.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = actsvr.comcastonline.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [XGIWatchDog] C:\Program Files\XGI\XWatDog.exe
O4 - HKLM\..\Run: [RegServer] regserve.exe
O4 - HKLM\..\Run: [Trirot] Trirot.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Could you post the new Hijackthis log please,also let me know how your pc is running now.


PC is running fine.. my Internet Explorer has very small fonts on couple pages.. when i log on Hotmail or Yahoo..

Do you know Y??

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:10:17 AM

Posted 05 May 2007 - 12:34 PM

Your log is clean :thumbsup:
If all's ok,please do the following:

Find and delete:
C:\QooBox

* Click 'Start'.
* Open 'My Computer'.
* Select the 'Tools' menu and click 'Folder Options'.
* Select the 'View' tab.
* Under the 'Hidden files and folders' heading unselect 'Show hidden files and folders'.
* Re-check the 'Hide file extensions for known types' option.
* Re-check the 'Hide protected operating system files (recommended)' option.
* Click Yes to confirm.
* Click OK.

Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html

Please Note:
Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u1'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.

PC is running fine.. my Internet Explorer has very small fonts on couple pages.. when i log on Hotmail or Yahoo..
Do you know Y??

You might want to start a new topic here regarding that issue.
All other Applications:
http://www.bleepingcomputer.com/forums/f/57/all-other-applications/

If you're asked,your system is free of malware.
Posted Image
Posted Image

#15 truvisions

truvisions
  • Topic Starter

  • Members
  • 109 posts
  • OFFLINE
  •  
  • Local time:04:17 AM

Posted 07 May 2007 - 09:23 AM

thank you.. Yeah i figure it out..


& once again thank you for fixing my cpu




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users