Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Many Pop Ups And Other Virus Thigs


  • Please log in to reply
11 replies to this topic

#1 Bozotclown

Bozotclown

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 14 May 2007 - 11:36 AM

i dont know what has happened but there are many pop-ups and applications keep trying to access the internet. may be something to do with outerinfo. also i cannot seem to save anything using firefox

example of program winC4.tmp.exe

Logfile of HijackThis v1.99.1
Scan saved at 17:30:54, on 5/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\WINDOWS\svchost.exe
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\WINDOWS\system32\wscntfy.exe
I:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [translitewebreadme] I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Copy flap] I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

i have run virus scans such as avast and spybot search and destroy

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 14 May 2007 - 03:38 PM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Bozotclown :thumbsup:

Download KillBox,unzip/extract it to your desktop.
http://download.bleepingcomputer.com/spyware/KillBox.zip
Start up Killbox and place a check in 'Delete on Reboot'.
In the 'Full path of file to delete' box,copy and paste:

I:\WINDOWS\system32\systl.dll

Then press the red button with the white cross.
It will then provide a window for you to confirm the delete.
Next it will ask if you now wish to reboot,select YES.
Allow it to reboot.
If it does'nt reboot automatically,reboot manually.

****************************

Go here:http://virusscan.jotti.org/
Using the 'Browse' button,browse to:
I:\WINDOWS\svchost.exe
Then press the 'Submit' button.
Wait while the file is scanned.
Post the results into your next reply please.

If Jotti's too busy,try here:
Go here:http://www.virustotal.com/en/virustotalf.html
Using the 'Browse' button,browse to:
I:\WINDOWS\svchost.exe
Then click on 'Send'.
Post the results into your next reply please.

****************************

Click on Start>Control Panel>Add/Remove Programs.
Uninstall/remove any of the following programs if listed:
Netpumper
Bitroll
Bitgrabber
CiD Help / CiD Manager
Download Plugin for Internet Explorer
Zone Media

This is because they are often bundled with the malware you are dealing with.
Don't worry if none of them are present.
If you happened to remove any of them please restart your pc.

******************************

Download NoLop.exe to your desktop.

* First close any other programs you have running as this will require a reboot.
* Double click NoLop.exe to run it.
* Then click the button labelled "Search and Destroy".
* When scanning is finished you will be prompted to reboot only if infected,click 'OK'.
* Now click the "REBOOT" Button.
* A Message should popup from NoLop, if not,double click the program again and it will finish.
Post the contents of C:\NoLop.log and a new Hijack This log into your next reply.

If you receive the error,that mscomctl.ocx or one of its dependencies are not correctly registered, please download this file to your 'System32' folder then rerun the program: http://www.boletrice.com/downloads/mscomctl.ocx

******************************

Now go to:
I:\hijackthis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Posted Image
Posted Image

#3 Bozotclown

Bozotclown
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 12:01 PM

ok i think i have done every thing

for svchost.exe on http://www.virustotal.com/en/virustotalf.html

Antivirus Version Update Result
AhnLab-V3 2007.5.15.1 05.15.2007 no virus found
AntiVir 7.4.0.15 05.15.2007 TR/Spy.Agent.OR.6
Authentium 4.93.8 05.14.2007 W32/Trojan.ZIF
Avast 4.7.997.0 05.15.2007 Win32:Agent-ECD
AVG 7.5.0.467 05.15.2007 PSW.Agent.FKD
BitDefender 7.2 05.15.2007 Trojan.Agent.AIM
CAT-QuickHeal 9.00 05.15.2007 TrojanSpy.Agent.or
ClamAV devel-20070416 05.15.2007 Trojan.Agent-2307
DrWeb 4.33 05.15.2007 no virus found
eSafe 7.0.15.0 05.15.2007 Win32.Agent.or
eTrust-Vet 30.7.3634 05.15.2007 no virus found
Ewido 4.0 05.15.2007 Logger.Agent.or
FileAdvisor 1 05.15.2007 Not analyzed yet
Fortinet 2.85.0.0 05.15.2007 Spy/Agent
F-Prot 4.3.2.48 05.14.2007 W32/Trojan.ZIF
F-Secure 6.70.13030.0 05.15.2007 Trojan-Spy.Win32.Agent.or
Ikarus T3.1.1.7 05.15.2007 Trojan-Spy.Win32.Agent.or
Kaspersky 4.0.2.24 05.15.2007 Trojan-Spy.Win32.Agent.or
McAfee 5030 05.14.2007 Generic Spy.b
Microsoft 1.2503 05.15.2007 no virus found
NOD32v2 2268 05.15.2007 no virus found
Norman 5.80.02 05.15.2007 W32/Agent.BBCG
Panda 9.0.0.4 05.15.2007 Adware/CWS.Searchmeup
Prevx1 V2 05.15.2007 Dialer.GlobalAccess
Sophos 4.17.0 05.11.2007 Troj/Agent-FOS
Sunbelt 2.2.907.0 05.12.2007 Trojan-Spy.Win32.Agent.or
Symantec 10 05.15.2007 Downloader.Trojan
TheHacker 6.1.6.115 05.15.2007 Trojan/Spy.Agent.or
VBA32 3.12.0 05.15.2007 Trojan-Spy.Win32.Agent.or
VirusBuster 4.3.7:9 05.15.2007 TrojanSpy.Agent.TBY
Webwasher-Gateway 6.0.1 05.15.2007 Trojan.Spy.Agent.OR.6

For nolop.exe this is the log
NoLop! Log by Skate_Punk_21

Fix running from: I:\Documents and Settings\Dom2\Desktop
[5/15/2007]
[17:23:10]

---Infection Files Found/Removed---
I:\WINDOWS\tasks\AD7F948791840A5F.job

Beginning Removal...
Rebooting...
Removing Lop's Leftover Files/Folders...
Editing Registry...
**Fix Complete!**

---Listing AppData sub directories---

I:\Documents and Settings\Administrator\Application Data\Google
I:\Documents and Settings\Administrator\Application Data\Lavasoft
I:\Documents and Settings\Administrator\Application Data\Macromedia
I:\Documents and Settings\Administrator\Application Data\Microsoft
I:\Documents and Settings\Administrator\Application Data\Mozilla
I:\Documents and Settings\Administrator\Application Data\Real
I:\Documents and Settings\Administrator\Application Data\Sun
I:\Documents and Settings\Administrator\Application Data\Talkback
I:\Documents and Settings\All Users\Application Data\Adobe
I:\Documents and Settings\All Users\Application Data\Age Of Empires 3 Xpack Trial
I:\Documents and Settings\All Users\Application Data\Apple Computer
I:\Documents and Settings\All Users\Application Data\Avg7 -- EMPTY Directory
I:\Documents and Settings\All Users\Application Data\Boonty
I:\Documents and Settings\All Users\Application Data\Creative
I:\Documents and Settings\All Users\Application Data\Google
I:\Documents and Settings\All Users\Application Data\Insight Software Solutions
I:\Documents and Settings\All Users\Application Data\Installshield
I:\Documents and Settings\All Users\Application Data\Ksp
I:\Documents and Settings\All Users\Application Data\Messenger Plus!
I:\Documents and Settings\All Users\Application Data\Microsoft
I:\Documents and Settings\All Users\Application Data\Microsoft Help
I:\Documents and Settings\All Users\Application Data\Motive -- EMPTY Directory
I:\Documents and Settings\All Users\Application Data\Sony Ericsson
I:\Documents and Settings\All Users\Application Data\Spieleentwicklungskombinat
I:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
I:\Documents and Settings\All Users\Application Data\Superantispyware.com
I:\Documents and Settings\All Users\Application Data\Symantec
I:\Documents and Settings\All Users\Application Data\Temp -- EMPTY Directory
I:\Documents and Settings\All Users\Application Data\Test Ref Trans Lite
I:\Documents and Settings\All Users\Application Data\Trymedia
I:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
I:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
I:\Documents and Settings\All Users\Application Data\Yahoo!
I:\Documents and Settings\All Users\Application Data\Yahoo! Companion
I:\Documents and Settings\Default User\Application Data\Microsoft
I:\Documents and Settings\D2\Application Data\Adobe
I:\Documents and Settings\D2\Application Data\Adobeum
I:\Documents and Settings\D2\Application Data\Apple Computer
I:\Documents and Settings\D2\Application Data\Creative
I:\Documents and Settings\D2\Application Data\Flashget
I:\Documents and Settings\D2\Application Data\Getrighttogo
I:\Documents and Settings\D2\Application Data\Google
I:\Documents and Settings\D2\Application Data\Hamachi
I:\Documents and Settings\D2\Application Data\Help -- EMPTY Directory
I:\Documents and Settings\D2\Application Data\Identities
I:\Documents and Settings\D2\Application Data\Installshield
I:\Documents and Settings\D2\Application Data\Lavasoft
I:\Documents and Settings\D2\Application Data\Leadertech
I:\Documents and Settings\D2\Application Data\Macromedia
I:\Documents and Settings\D2\Application Data\Media Player Classic
I:\Documents and Settings\D2\Application Data\Microsoft
I:\Documents and Settings\D2\Application Data\Mozilla
I:\Documents and Settings\D2\Application Data\Myphoneexplorer
I:\Documents and Settings\D2\Application Data\Opensl
I:\Documents and Settings\D2\Application Data\Opera
I:\Documents and Settings\D2\Application Data\Petroglyph
I:\Documents and Settings\D2\Application Data\Real
I:\Documents and Settings\D2\Application Data\Screenshot Sender
I:\Documents and Settings\D2\Application Data\Secondlife
I:\Documents and Settings\D2\Application Data\Sonic
I:\Documents and Settings\D2\Application Data\Spieleentwicklungskombinat
I:\Documents and Settings\D2\Application Data\Sun
I:\Documents and Settings\D2\Application Data\Superantispyware.com -- EMPTY Directory
I:\Documents and Settings\D2\Application Data\System Requirements Lab
I:\Documents and Settings\D2\Application Data\Talkback
I:\Documents and Settings\D2\Application Data\Thirdfrag
I:\Documents and Settings\D2\Application Data\Utorrent
I:\Documents and Settings\D2\Application Data\Vlc
I:\Documents and Settings\D2\Application Data\Yahoo!
I:\Documents and Settings\Dc\Application Data\Adobe
I:\Documents and Settings\Dc\Application Data\Adobeum -- EMPTY Directory
I:\Documents and Settings\Dc\Application Data\Apple Computer
I:\Documents and Settings\Dc\Application Data\Avg7 -- EMPTY Directory
I:\Documents and Settings\Dc\Application Data\Creative
I:\Documents and Settings\Dc\Application Data\Firaxis Games
I:\Documents and Settings\Dc\Application Data\Google -- EMPTY Directory
I:\Documents and Settings\Dc\Application Data\Help -- EMPTY Directory
I:\Documents and Settings\Dc\Application Data\Identities
I:\Documents and Settings\Dc\Application Data\Lavasoft
I:\Documents and Settings\Dc\Application Data\Leadertech
I:\Documents and Settings\Dc\Application Data\Macromedia
I:\Documents and Settings\Dc\Application Data\Microsoft
I:\Documents and Settings\Dc\Application Data\Motive
I:\Documents and Settings\Dc\Application Data\Mozilla
I:\Documents and Settings\Dc\Application Data\My Games -- EMPTY Directory
I:\Documents and Settings\Dc\Application Data\Real
I:\Documents and Settings\Dc\Application Data\Smart Recorder
I:\Documents and Settings\Dc\Application Data\Sonic
I:\Documents and Settings\Dc\Application Data\Sun
I:\Documents and Settings\Dc\Application Data\Symantec
I:\Documents and Settings\Dc\Application Data\Talkback
I:\Documents and Settings\Dc\Application Data\Utorrent
I:\Documents and Settings\Dc\Application Data\Yahoo!
I:\Documents and Settings\Jn\Application Data\Adobe
I:\Documents and Settings\Jn\Application Data\Adobeum -- EMPTY Directory
I:\Documents and Settings\Jn\Application Data\Avg7 -- EMPTY Directory
I:\Documents and Settings\Jn\Application Data\Creative
I:\Documents and Settings\Jn\Application Data\Google
I:\Documents and Settings\Jn\Application Data\Identities
I:\Documents and Settings\Jn\Application Data\Lavasoft
I:\Documents and Settings\Jn\Application Data\Leadertech
I:\Documents and Settings\Jn\Application Data\Macromedia
I:\Documents and Settings\Jn\Application Data\Microsoft
I:\Documents and Settings\Jn\Application Data\Mozilla
I:\Documents and Settings\Jn\Application Data\Myfamily.com
I:\Documents and Settings\Jn\Application Data\Real
I:\Documents and Settings\Jn\Application Data\Sonic
I:\Documents and Settings\Jn\Application Data\Sun
I:\Documents and Settings\Jn\Application Data\Talkback
I:\Documents and Settings\Jn\Application Data\Yahoo!
I:\Documents and Settings\Localservice\Application Data\Microsoft
I:\Documents and Settings\Networkservice\Application Data\Microsoft
I:\Documents and Settings\Networkservice\Application Data\Symantec
I:\Documents and Settings\Nya\Application Data\Adobe
I:\Documents and Settings\Nya\Application Data\Avg7 -- EMPTY Directory
I:\Documents and Settings\Nya\Application Data\Google
I:\Documents and Settings\Nya\Application Data\Identities
I:\Documents and Settings\Nya\Application Data\Macromedia
I:\Documents and Settings\Nya\Application Data\Microsoft
I:\Documents and Settings\Nya\Application Data\Mozilla
I:\Documents and Settings\Nya\Application Data\Real
I:\Documents and Settings\Nya\Application Data\Talkback
I:\Documents and Settings\Nya\Application Data\Yahoo!

Finally the hijack with the changed name

Logfile of HijackThis v1.99.1
Scan saved at 17:56:52, on 5/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\system32\wuauclt.exe
I:\hijackthis\abc.bat

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2720E224-DE25-42FE-9EB9-F7EC7971F1E9} - I:\WINDOWS\system32\gebyv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - I:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {5EA79C18-E12F-4AED-9630-70DDD95DCFBc} - I:\WINDOWS\system32\beqioxgg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {B5A2FE0A-844B-4EE9-A3D1-474B44E0496C} - I:\WINDOWS\system32\awtqqqn.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CFAD2704-4CB4-4130-8FA1-48E168AEB34D} - i:\windows\system32\kuvtb.dll
O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - I:\WINDOWS\system32\efkxgwfh.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [translitewebreadme] I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "I:\WINDOWS\system32\oxcyihhw.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Copy flap] I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll
O20 - Winlogon Notify: awtqqqn - I:\WINDOWS\SYSTEM32\awtqqqn.dll
O20 - Winlogon Notify: dwebwhde - I:\WINDOWS\SYSTEM32\kuvtb.dll
O20 - Winlogon Notify: gebyv - I:\WINDOWS\system32\gebyv.dll
O20 - Winlogon Notify: wintfj32 - I:\WINDOWS\SYSTEM32\wintfj32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

and thank you for your help

Edited by Bozotclown, 15 May 2007 - 12:02 PM.


#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 12:05 PM

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
When VundoFix re-opens,click the "Scan for Vundo" button.
Once it's done scanning,click the "Remove Vundo" button.
You will receive a prompt asking if you want to remove the files, click "YES".
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed,it will prompt that it will reboot your computer,click "OK".
Please post the contents of C:\vundofix.txt into your next reply.

Note:
It is possible that VundoFix encountered a file it could not remove.
In this case,VundoFix will run on reboot,simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

*******************************

Please download Combofix and save to your desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


Also post a new Hijackthis log please.
Posted Image
Posted Image

#5 Bozotclown

Bozotclown
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 01:09 PM

VundoFix V6.3.23

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 18:29:38 5/15/2007

Listing files found while scanning....

I:\WINDOWS\system32\awtqqqn.dll
I:\WINDOWS\system32\byxuvwx.dll
I:\WINDOWS\system32\efkxgwfh.dll
I:\WINDOWS\system32\gebyv.dll
I:\WINDOWS\system32\kuvtb.dll
I:\WINDOWS\system32\mljjkhh.dll
I:\WINDOWS\system32\vybeg.bak1
I:\WINDOWS\system32\vybeg.bak2
I:\WINDOWS\system32\vybeg.ini

Beginning removal...

Attempting to delete I:\WINDOWS\system32\awtqqqn.dll
I:\WINDOWS\system32\awtqqqn.dll Has been deleted!

Attempting to delete I:\WINDOWS\system32\byxuvwx.dll
I:\WINDOWS\system32\byxuvwx.dll Has been deleted!

Attempting to delete I:\WINDOWS\system32\efkxgwfh.dll
I:\WINDOWS\system32\efkxgwfh.dll Has been deleted!

Attempting to delete I:\WINDOWS\system32\gebyv.dll
I:\WINDOWS\system32\gebyv.dll Has been deleted!

Attempting to delete I:\WINDOWS\system32\kuvtb.dll
I:\WINDOWS\system32\kuvtb.dll Could not be deleted.

Attempting to delete I:\WINDOWS\system32\mljjkhh.dll
I:\WINDOWS\system32\mljjkhh.dll Has been deleted!

Attempting to delete I:\WINDOWS\system32\vybeg.bak1
I:\WINDOWS\system32\vybeg.bak1 Has been deleted!

Attempting to delete I:\WINDOWS\system32\vybeg.bak2
I:\WINDOWS\system32\vybeg.bak2 Has been deleted!

Attempting to delete I:\WINDOWS\system32\vybeg.ini
I:\WINDOWS\system32\vybeg.ini Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete I:\WINDOWS\system32\kuvtb.dll
I:\WINDOWS\system32\kuvtb.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...






"Dom2" - 2007-05-15 18:46:35 Service Pack 2
ComboFix 07-05.15.5.V - Running from: "I:\Documents and Settings\Dom2\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


I:\WINDOWS\system32\khfddaa.dll
I:\WINDOWS\system32\wintfj32.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


I:\Program Files\Common Files\svchost.exe
I:\WINDOWS\hook.txt
I:\WINDOWS\ie-hook.txt
I:\WINDOWS\svchost.exe
I:\WINDOWS\system32\drivers\tveymjpx.sys
I:\WINDOWS\system32\kuvtb.dll" . . . . failed to delete
I:\WINDOWS\system32\kuvtb.dll.bak" . . . . failed to delete


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_AHBYNQAL
-------\LEGACY_ZORFTHSO
-------\ahbynqal
-------\zorfthso


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-15 ))))))))))))))))))))))))))))))))))


2007-05-15 17:32 106 --a------ I:\delete.bat
2007-05-15 17:28 <DIR> d-------- I:\NoLopBackups
2007-05-15 17:09 <DIR> d-------- I:\!KillBox
2007-05-15 15:12 684,567 --a------ I:\WINDOWS\system32\libeay32.dll
2007-05-15 15:12 147,729 --a------ I:\WINDOWS\system32\libssl32.dll
2007-05-15 15:08 587,264 --a------ I:\WINDOWS\system32\vaghfvli.dll
2007-05-15 11:51 132,660 --a------ I:\WINDOWS\system32\oxcyihhw.dll
2007-05-14 20:06 16 --a------ I:\WINDOWS\popcinfot.dat
2007-05-14 20:06 0 --a------ I:\WINDOWS\popcreg.dat
2007-05-14 20:06 <DIR> d-------- I:\Program Files\PopCap Games
2007-05-14 19:53 <DIR> d-------- I:\Program Files\City of Heroes
2007-05-14 19:10 <DIR> d-------- I:\Battleships Forever
2007-05-14 17:56 <DIR> d-------- I:\Program Files\dtp entertainment AG
2007-05-14 16:17 71,168 ---h----- I:\DOCUME~1\ALLUSE~1\APPLIC~1\svchost.exe
2007-05-14 13:56 40,183 ---hs---- I:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
2007-05-14 13:55 93,696 --a------ I:\WINDOWS\system32\drvpit.dll
2007-05-14 09:17 132,660 --a------ I:\WINDOWS\system32\pnrffhbl.dll
2007-05-14 09:02 93,696 --a------ I:\WINDOWS\system32\drvsuz.dll
2007-05-13 20:42 <DIR> d-------- I:\Program Files\genises
2007-05-13 19:20 <DIR> d-------- I:\Program Files\DreamCatcher
2007-05-13 19:09 <DIR> d-------- I:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-05-11 17:44 <DIR> d-------- I:\DOCUME~1\Dom2\APPLIC~1\FlashGet
2007-05-09 18:35 80,384 --a------ I:\WINDOWS\system32\charmap.exe
2007-05-09 18:35 73,216 --a------ I:\WINDOWS\system32\avwav.dll
2007-05-09 18:35 605,696 --a------ I:\WINDOWS\system32\getuname.dll
2007-05-09 18:35 56,832 --a------ I:\WINDOWS\system32\sol.exe
2007-05-09 18:35 55,296 --a------ I:\WINDOWS\system32\freecell.exe
2007-05-09 18:35 538,624 --a------ I:\WINDOWS\system32\spider.exe
2007-05-09 18:35 5,632 --a------ I:\WINDOWS\system32\write.exe
2007-05-09 18:35 44,544 --a------ I:\WINDOWS\system32\hticons.dll
2007-05-09 18:35 35,328 --a------ I:\WINDOWS\system32\winchat.exe
2007-05-09 18:35 345,088 --a------ I:\WINDOWS\system32\hypertrm.dll
2007-05-09 18:35 343,040 --a------ I:\WINDOWS\system32\mspaint.exe
2007-05-09 18:35 227,840 --a------ I:\WINDOWS\system32\avtapi.dll
2007-05-09 18:35 183,808 --a------ I:\WINDOWS\system32\accwiz.exe
2007-05-09 18:35 16,384 --a------ I:\WINDOWS\system32\avmeter.dll
2007-05-09 18:35 138,752 --a------ I:\WINDOWS\system32\sndvol32.exe
2007-05-09 18:35 131,584 --a------ I:\WINDOWS\system32\sndrec32.exe
2007-05-09 18:35 126,976 --a------ I:\WINDOWS\system32\mshearts.exe
2007-05-09 18:35 123,392 --a------ I:\WINDOWS\system32\mplay32.exe
2007-05-09 18:35 119,808 --a------ I:\WINDOWS\system32\winmine.exe
2007-05-09 18:35 114,688 --a------ I:\WINDOWS\system32\calc.exe
2007-05-09 18:35 102,912 --a------ I:\WINDOWS\system32\clipbrd.exe
2007-04-29 12:19 660 --a------ I:\WINDOWS\unins000.dat
2007-04-29 12:09 26,056 --a------ I:\WINDOWS\system32\drivers\hamachi.sys
2007-04-29 12:09 <DIR> d-------- I:\DOCUME~1\Dom2\APPLIC~1\Hamachi
2007-04-29 11:59 <DIR> d-------- I:\Program Files\SUPERAntiSpyware
2007-04-29 11:59 <DIR> d-------- I:\DOCUME~1\Dom2\APPLIC~1\SUPERAntiSpyware.com
2007-04-29 11:59 <DIR> d-------- I:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-04-16 17:36 <DIR> d-------- I:\Program Files\Microsoft Windows Vista Upgrade Advisor
2007-04-16 17:29 <DIR> d-------- I:\Program Files\Windows Defender
2007-04-16 17:21 <DIR> d-------- I:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
2007-04-16 17:20 <DIR> d-------- I:\Program Files\Windows Live Toolbar
2007-04-15 10:52 <DIR> d-------- I:\DOCUME~1\ALLUSE~1\APPLIC~1\KSP


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-15 14:08:39 126,464 ----a-w I:\WINDOWS\system32\foxuhzxs.dll
2007-05-15 10:47:03 -------- d--h--w I:\Program Files\InstallShield Installation Information
2007-05-14 17:51:52 108,144 ----a-w I:\WINDOWS\system32\CmdLineExt.dll
2007-05-13 20:17:59 79,872 ------w I:\WINDOWS\system32\kuvtb.dll
2007-05-11 16:32:24 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\uTorrent
2007-05-09 17:35:44 -------- d-----w I:\Program Files\Windows NT
2007-05-01 14:13:42 99,840 ----a-w I:\WINDOWS\system32\dlgfbsiv.dll
2007-05-01 14:13:41 43,520 ----a-w I:\WINDOWS\system32\haeonsox.dll
2007-04-29 13:16:30 -------- d-----w I:\Program Files\Common Files\Wise Installation Wizard
2007-04-29 11:49:26 -------- d-----w I:\Program Files\DAEMON Tools
2007-04-29 11:49:25 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\thirdfrag
2007-04-29 11:20:00 72,748 ----a-w I:\WINDOWS\unins000.exe
2007-04-16 21:52:18 -------- d-----w I:\Program Files\Microsoft Works
2007-04-15 09:08:41 -------- d-----w I:\Program Files\SMAC
2007-04-14 07:47:45 85,952 ----a-w I:\WINDOWS\system32\drivers\aswmon.sys
2007-04-14 07:47:32 94,552 ----a-w I:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-14 07:45:35 23,416 ----a-w I:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-14 07:44:52 43,176 ----a-w I:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-14 07:43:31 26,888 ----a-w I:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-14 07:42:43 90,112 ----a-w I:\WINDOWS\system32\AVASTSS.scr
2007-04-12 17:19:14 552 ----a-w I:\WINDOWS\system32\d3d8caps.dat
2007-04-12 15:24:32 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\Screenshot Sender
2007-04-12 14:07:10 -------- d-----w I:\Program Files\Online Services
2007-04-10 11:18:32 712,832 ----a-w I:\WINDOWS\system32\aswBoot.exe
2007-04-09 16:28:58 22,584 ----a-w I:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-04-09 16:27:12 99,904 ----a-w I:\WINDOWS\system32\PnkBstrB.exe
2007-04-09 10:09:33 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\vlc
2007-04-09 10:02:53 -------- d-----w I:\Program Files\VideoLAN
2007-04-06 14:47:25 -------- d-----w I:\Program Files\Investintech.com Inc
2007-04-06 14:46:19 -------- d-----w I:\Program Files\ShoopedLife
2007-04-06 14:45:47 -------- d-----w I:\Program Files\Microsoft Games
2007-04-06 07:08:07 -------- d-----w I:\Program Files\Intel Corporation
2007-04-02 16:05:04 646,392 ----a-w I:\WINDOWS\system32\drivers\sptd.sys
2007-03-30 06:49:37 -------- d-----w I:\Program Files\GameSpy Arcade
2007-03-30 06:39:11 -------- d-----w I:\Program Files\LucasArts
2007-03-30 06:31:05 -------- d-----w I:\Program Files\MagicISO
2007-03-28 18:22:33 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\SecondLife
2007-03-28 17:37:36 -------- d-----w I:\Program Files\Free RM to MP3 Converter
2007-03-27 21:05:57 -------- d-----w I:\Program Files\mIRC
2007-03-27 19:08:05 -------- d-----w I:\Program Files\Common Files\SystemRequirementsLab
2007-03-27 19:08:05 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\System Requirements Lab
2007-03-27 17:01:37 -------- d-----w I:\Program Files\ATI Technologies
2007-03-27 15:05:47 -------- d-----w I:\Program Files\KLC
2007-03-25 11:00:55 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\MyPhoneExplorer
2007-03-23 16:49:47 -------- d-----w I:\Program Files\Windows Live Safety Center
2007-03-22 21:34:00 -------- d-----w I:\Program Files\RADVideo
2007-03-22 17:21:12 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\OpenSL
2007-03-17 13:43:01 292,864 ----a-w I:\WINDOWS\system32\winsrv.dll
2007-03-15 19:07:22 -------- d-----w I:\Program Files\Google
2007-03-15 18:31:04 -------- d-----w I:\Program Files\MSN Messenger
2007-03-15 18:31:04 -------- d-----w I:\Program Files\Messenger Plus! Live
2007-03-13 17:08:33 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\Media Player Classic
2007-03-13 16:59:08 -------- d-----w I:\Program Files\MyGlobalSearch
2007-03-12 14:13:19 -------- d-----w I:\Program Files\RM to MP3 Converter
2007-03-11 13:48:19 -------- d-----w I:\Program Files\WinEnhance
2007-03-10 17:27:00 -------- d-----w I:\Program Files\StuffPlug3
2007-03-10 12:00:16 -------- d-----w I:\Program Files\Borland
2007-03-10 11:59:46 -------- d-----w I:\Program Files\Compton's Home Library
2007-03-08 15:36:28 577,536 ----a-w I:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w I:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w I:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w I:\WINDOWS\system32\win32k.sys
2007-03-07 16:47:15 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\Opera
2007-03-07 16:47:13 -------- d-----w I:\Program Files\Opera
2007-03-07 16:44:08 -------- d-----w I:\Program Files\Winwap Technologies
2007-03-07 16:41:12 -------- d-----w I:\DOCUME~1\Dom2\APPLIC~1\GetRightToGo
2007-03-06 20:05:00 520,192 ------w I:\WINDOWS\system32\ati2sgag.exe
2007-03-02 20:57:04 307,200 ----a-w I:\WINDOWS\system32\atiiiexx.dll
2007-03-02 20:54:35 307,200 ----a-w I:\WINDOWS\system32\ATIDEMGX.dll
2007-03-02 20:53:36 265,728 ----a-w I:\WINDOWS\system32\ati2dvag.dll
2007-03-02 20:47:51 118,784 ----a-w I:\WINDOWS\system32\atipdlxx.dll
2007-03-02 20:47:42 110,592 ----a-w I:\WINDOWS\system32\Oemdspif.dll
2007-03-02 20:47:35 26,112 ----a-w I:\WINDOWS\system32\Ati2mdxx.exe
2007-03-02 20:47:30 42,496 ----a-w I:\WINDOWS\system32\ati2edxx.dll
2007-03-02 20:47:19 110,592 ----a-w I:\WINDOWS\system32\ati2evxx.dll
2007-03-02 20:46:12 446,464 ----a-w I:\WINDOWS\system32\ati2evxx.exe
2007-03-02 20:45:32 53,248 ----a-w I:\WINDOWS\system32\ATIDDC.DLL
2007-03-02 20:38:53 2,824,512 ----a-w I:\WINDOWS\system32\ati3duag.dll
2007-03-02 20:29:23 1,288,960 ----a-w I:\WINDOWS\system32\ativvaxx.dll
2007-03-02 20:21:15 5,398,528 ----a-w I:\WINDOWS\system32\atioglxx.dll
2007-03-02 20:17:37 258,048 ----a-w I:\WINDOWS\system32\atikvmag.dll
2007-03-02 20:16:23 17,408 ----a-w I:\WINDOWS\system32\atitvo32.dll
2007-03-02 20:11:44 348,160 ----a-w I:\WINDOWS\system32\ati2cqag.dll
2007-02-26 15:44:06 147,685 ----a-w I:\WINDOWS\system32\atiicdxx.dat
2007-02-05 20:17:02 185,344 ----a-w I:\WINDOWS\system32\upnphost.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4efb-9B51-7695ECA05670}=I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll [2004-09-08 22:38]
{2720E224-DE25-42FE-9EB9-F7EC7971F1E9}=I:\WINDOWS\system32\gebyv.dll []
{53707962-6F74-2D53-2644-206D7942484F}=I:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=I:\WINDOWS\system32\dla\tfswshx.dll [2005-03-16 05:33]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 21:33]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}=I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll [2003-09-06 19:31]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=I:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 15:56]
{BDF3E430-B101-42AD-A544-FADC6B084872}=I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll [2003-12-04 18:22]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="I:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04]
"ATIPTA"="I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE" [2005-04-14 21:05]
"AudioDrvEmulator"="I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25]
"Motive SmartBridge"="I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe" [2006-02-06 18:52]
"ccApp"="I:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 12:54]
"URLLSTCK.exe"="I:\Program Files\Norton Internet Security\UrlLstCk.exe" [2003-12-11 19:35]
"SunJavaUpdateSched"="I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"CTHelper"="CTHELPER.EXE" []
"CTxfiHlp"="CTXFIHLP.EXE" [2006-06-01 11:34 I:\WINDOWS\system32\CTXFIHLP.EXE]
"CTDVDDET"="I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00]
"VolPanel"="I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-07-11 11:34]
"UpdReg"="I:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"dla"="I:\WINDOWS\system32\dla\tfswctrl.exe" [2005-03-16 05:33]
"ISUSPM Startup"="I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"QuickTime Task"="I:\Program Files\QuickTime\qttask.exe" [2006-08-21 19:21]
"SigmatelSysTrayApp"="stsystra.exe" []
"Zone Labs Client"="I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-07-09 13:42]
"avast!"="I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-14 08:48]
"TkBellExe"="I:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-29 10:48]
"translitewebreadme"="I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe" []
"Windows Defender"="I:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="I:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00]
"@"="" []
"StartCCC"="i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" []
"DAEMON Tools"="I:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 11:48]
"Copy flap"="I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="I:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):49,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):49,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 15:13]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
Shell=Explorer.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="I:\WINDOWS\system32\systl.dll"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel wdigest
Notification Packages scecli

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\axyeaaaa]
I:\WINDOWS\system32\axyeaaaa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Copy flap]
I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Boonty Games"=dword:00000003
"AVG Anti-Spyware Guard"=dword:00000002

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HTTPFilter HTTPFilter
LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
NetworkService DnsCache
DcomLaunch DcomLaunch TermService
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService
Usnsvc usnsvc

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
ahbynqal



~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20061208-152615-563
O2 - BHO: (no name) - {CFAD2704-4CB4-4130-8FA1-48E168AEB34D} - I:\WINDOWS\system32\kuvtb.dll
backup-20061208-152615-865
O2 - BHO: (no name) - {CB3D25AA-4EDC-4A80-AA4E-BF51C578E456} - I:\WINDOWS\system32\zacrsm.dll
backup-20061208-152615-783
O2 - BHO: (no name) - {5EA79C18-E12F-4AED-9630-70DDD95DCFBc} - I:\WINDOWS\system32\zacrsm.dll
backup-20061208-152615-398
O2 - BHO: (no name) - {1AAA6917-0BD6-44A4-A4DA-8183B8D0E0A6} - I:\WINDOWS\system32\zacrsm.dll

Contents of the 'Scheduled Tasks' folder
I:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
I:\WINDOWS\tasks\MP Scheduled Scan.job
I:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Dominic.job
I:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-15 18:58:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-15 19:01:32 - machine was rebooted
I:\ComboFix-quarantined-files.txt ... 2007-05-15 19:01








HIJACK




Logfile of HijackThis v1.99.1
Scan saved at 19:07:23, on 5/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\WINDOWS\system32\ctfmon.exe
I:\WINDOWS\explorer.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\hijackthis\abc.bat

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2720E224-DE25-42FE-9EB9-F7EC7971F1E9} - I:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - I:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [translitewebreadme] I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Copy flap] I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

Edited by Bozotclown, 15 May 2007 - 01:11 PM.


#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 02:36 PM

Download Avenger from the link below:
http://swandog46.geekstogo.com/avenger.zip
Unzip/extract it to your desktop.

Start up Avenger.
Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens,copy and paste ALL the following bold blue text in the Quote box below:

Files to delete:
I:\WINDOWS\system32\vaghfvli.dll
I:\WINDOWS\system32\oxcyihhw.dll
I:\WINDOWS\system32\drvpit.dll
I:\WINDOWS\system32\pnrffhbl.dll
I:\WINDOWS\system32\drvsuz.dll
I:\WINDOWS\system32\foxuhzxs.dll
I:\WINDOWS\system32\systl.dll
I:\WINDOWS\system32\kuvtb.dll
I:\WINDOWS\system32\dlgfbsiv.dll
I:\WINDOWS\system32\haeonsox.dll
I:\WINDOWS\system32\kuvtb.dll.bak
I:\Program Files\Common Files\Yazzle1162OinUninstaller.exe

Folders to delete:
I:\Program Files\GameSpy Arcade
I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1
I:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
I:\Documents and Settings\All Users\Application Data\test ref trans lite

Then click on 'Done'.
Click the Traffic Light icon to start the program.
Then press OK at the prompts to reboot your PC.

Post the Avenger output.txt, which you can find at C:\Avenger\.txt into your next reply.

**************************************

Download SmitfraudFix (by S!Ri), to your desktop.
Double click on Smitfraudfix.cmd
Select option #1 Search, by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy and paste the content of that report into your next reply.
Also post a new Hijackthis log please.

Posted Image
Posted Image

#7 Bozotclown

Bozotclown
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 03:12 PM

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\nycymlhb

*******************

Script file located at: \??\I:\Program Files\pveiraqs.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at I:\Avenger

*******************

Beginning to process script file:

File I:\WINDOWS\system32\vaghfvli.dll deleted successfully.
File I:\WINDOWS\system32\oxcyihhw.dll deleted successfully.
File I:\WINDOWS\system32\drvpit.dll deleted successfully.
File I:\WINDOWS\system32\pnrffhbl.dll deleted successfully.
File I:\WINDOWS\system32\drvsuz.dll deleted successfully.
File I:\WINDOWS\system32\foxuhzxs.dll deleted successfully.


File I:\WINDOWS\system32\systl.dll not found!
Deletion of file I:\WINDOWS\system32\systl.dll failed!

Could not process line:
I:\WINDOWS\system32\systl.dll
Status: 0xc0000034

File I:\WINDOWS\system32\kuvtb.dll deleted successfully.
File I:\WINDOWS\system32\dlgfbsiv.dll deleted successfully.
File I:\WINDOWS\system32\haeonsox.dll deleted successfully.
File I:\WINDOWS\system32\kuvtb.dll.bak deleted successfully.
File I:\Program Files\Common Files\Yazzle1162OinUninstaller.exe deleted successfully.
Folder I:\Program Files\GameSpy Arcade deleted successfully.
Folder I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1 deleted successfully.
Folder I:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia deleted successfully.
Folder I:\Documents and Settings\All Users\Application Data\test ref trans lite deleted successfully.

Completed script processing.

*******************

Finished! Terminate.







SmitFraudFix v2.181

Scan done at 21:06:05.42, Tue 05/15/2007
Run from I:\Documents and Settings\Dom2\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

Process

I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\WINDOWS\system32\wuauclt.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\system32\cmd.exe

hosts


I:\


I:\WINDOWS


I:\WINDOWS\system


I:\WINDOWS\Web


I:\WINDOWS\system32


I:\WINDOWS\system32\LogFiles


I:\Documents and Settings\Dom2


I:\Documents and Settings\Dom2\Application Data


Start Menu


I:\DOCUME~1\Dom2\FAVORI~1


Desktop


I:\Program Files


Corrupted keys


Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="I:\\WINDOWS\\system32\\systl.dll"


Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


pe386-msguard-lzx32-huy32



DNS

Description: Intel® PRO/1000 PL Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{9067CDBF-4FE9-4DDE-94DB-3DA75CFF2764}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{9067CDBF-4FE9-4DDE-94DB-3DA75CFF2764}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{9067CDBF-4FE9-4DDE-94DB-3DA75CFF2764}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9067CDBF-4FE9-4DDE-94DB-3DA75CFF2764}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


Scanning for wininet.dll infection


End





Logfile of HijackThis v1.99.1
Scan saved at 21:08:55, on 5/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\WINDOWS\system32\ctfmon.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\WINDOWS\system32\wuauclt.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\WINDOWS\system32\wscntfy.exe
I:\hijackthis\abc.bat

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2720E224-DE25-42FE-9EB9-F7EC7971F1E9} - I:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - I:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [translitewebreadme] I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Copy flap] I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 15 May 2007 - 03:20 PM

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

O2 - BHO: (no name) - {2720E224-DE25-42FE-9EB9-F7EC7971F1E9} - I:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [translitewebreadme] I:\Documents and Settings\All Users\Application Data\test ref trans lite\Skip Setup.exe
04 - HKCU\..\Run: [Copy flap] I:\DOCUME~1\Dom2\APPLIC~1\THIRDF~1\Aim Sect.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - I:\Program Files\Flash2X\Flash Hunter\save.htm (file missing) (HKCU)
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll


Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#9 Bozotclown

Bozotclown
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 16 May 2007 - 11:48 AM

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 22:18:21 5/15/2007

+ Scan result:



I:\Documents and Settings\Joan\Local Settings\Temp\dvfjer.exe -> Downloader.Small.cyy : Cleaned.
I:\Documents and Settings\All Users\Application Data\svchost.exe -> Logger.Agent.or : Cleaned.
I:\QooBox\Quarantine\I\Program Files\Common Files\svchost.exe.vir -> Logger.Agent.or : Cleaned.
I:\QooBox\Quarantine\I\WINDOWS\svchost.exe.vir -> Logger.Agent.or : Cleaned.
I:\WINDOWS\system32\MSIEHelper.dll -> Logger.Small.ez : Cleaned.
:mozilla.170:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.134:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.135:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.136:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.137:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.141:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.142:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.165:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.172:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.279:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.493:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.72:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@reciperewards.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.7:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.8:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.923:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.924:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.9:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.381:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adbureau : Cleaned.
:mozilla.320:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.321:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.322:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.323:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.324:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.325:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.51:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.10:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.11:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.285:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.286:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.375:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.376:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.377:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.378:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.379:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq21.tmp -> TrackingCookie.Advertising : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq2B.tmp -> TrackingCookie.Advertising : Cleaned.
:mozilla.149:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.143:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq12.tmp -> TrackingCookie.Atdmt : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq2C.tmp -> TrackingCookie.Atdmt : Cleaned.
:mozilla.826:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq13.tmp -> TrackingCookie.Burstnet : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq2F.tmp -> TrackingCookie.Burstnet : Cleaned.
:mozilla.841:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq14.tmp -> TrackingCookie.Casalemedia : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq30.tmp -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.90:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq15.tmp -> TrackingCookie.Clickbank : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq33.tmp -> TrackingCookie.Clickzs : Cleaned.
:mozilla.121:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.125:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.126:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.130:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Co : Cleaned.
:mozilla.234:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Com : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq16.tmp -> TrackingCookie.Com : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq32.tmp -> TrackingCookie.Com : Cleaned.
:mozilla.76:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.77:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
I:\Documents and Settings\Dominic\Cookies\dominic@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
I:\Documents and Settings\Nyssa\Cookies\nyssa@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.18:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
I:\Documents and Settings\Dom2\Cookies\dom2@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.789:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq34.tmp -> TrackingCookie.Dealtime : Cleaned.
:mozilla.25:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq17.tmp -> TrackingCookie.Doubleclick : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq35.tmp -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.54:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.55:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.56:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.57:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.58:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.62:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq18.tmp -> TrackingCookie.Falkag : Cleaned.
:mozilla.45:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.46:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.47:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
I:\Documents and Settings\Dom2\Cookies\dom2@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq19.tmp -> TrackingCookie.Fastclick : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq36.tmp -> TrackingCookie.Fastclick : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned.
:mozilla.105:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.154:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.205:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.256:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.262:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.268:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.271:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.295:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.313:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.89:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.449:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.455:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.456:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.523:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.539:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.577:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.639:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.640:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.641:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.655:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.656:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.732:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.735:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.736:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.737:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.754:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.851:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.913:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A.tmp -> TrackingCookie.Hotlog : Cleaned.
:mozilla.195:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.196:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.47:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.48:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.504:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
I:\Documents and Settings\Nyssa\Cookies\nyssa@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.669:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.670:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.671:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.727:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.730:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.731:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.769:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.15:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.16:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
I:\Documents and Settings\Dom2\Cookies\dom2@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp -> TrackingCookie.Mediaplex : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
I:\Documents and Settings\Joan\Local Settings\Temp\Cookies\joan@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
I:\Documents and Settings\Dominic\Cookies\dominic@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.178:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.179:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.752:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.85:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.87:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.36:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.104:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.26:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.29:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.33:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.34:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C.tmp -> TrackingCookie.Pointroll : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq39.tmp -> TrackingCookie.Pointroll : Cleaned.
:mozilla.288:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.289:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.30:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.31:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D.tmp -> TrackingCookie.Questionmarket : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq3A.tmp -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.48:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Real : Cleaned.
I:\Documents and Settings\Dom2\Cookies\dom2@real[2].txt -> TrackingCookie.Real : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@realguide.real[1].txt -> TrackingCookie.Real : Cleaned.
:mozilla.809:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.810:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.811:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@www.res99[1].txt -> TrackingCookie.Res99 : Cleaned.
:mozilla.109:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.110:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.115:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.116:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.117:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.118:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.119:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.120:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.659:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.507:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.508:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.509:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.510:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.511:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.512:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp -> TrackingCookie.Serving-sys : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq3B.tmp -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.19:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.20:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.278:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.365:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.366:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.382:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.546:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.64:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.65:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.66:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.705:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.825:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.797:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E.tmp -> TrackingCookie.Spylog : Cleaned.
:mozilla.180:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.181:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.182:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.183:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.184:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.185:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.186:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.187:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.188:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.444:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.447:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.448:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq3C.tmp -> TrackingCookie.Tacoda : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq8.tmp -> TrackingCookie.Tacoda : Cleaned.
:mozilla.634:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.97:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.98:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.99:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F.tmp -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.51:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.68:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppqA.tmp -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.596:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.617:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
I:\Documents and Settings\Administrator\Cookies\administrator@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
I:\Documents and Settings\Joan\Cookies\joan@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq47.tmp -> TrackingCookie.Webtrends : Cleaned.
:mozilla.310:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.326:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq3E.tmp -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.663:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.664:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.49:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.50:I:\Documents and Settings\Nyssa\Application Data\Mozilla\Firefox\Profiles\vax553cf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.56:I:\Documents and Settings\Dominic\Application Data\Mozilla\Firefox\Profiles\af6d7bho.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.632:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.633:I:\Documents and Settings\Joan\Application Data\Mozilla\Firefox\Profiles\1h3jmd61.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq20.tmp -> TrackingCookie.Yieldmanager : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp -> TrackingCookie.Yieldmanager : Cleaned.
I:\Program Files\Yahoo!\YPSR\Quarantine\ppqB.tmp -> TrackingCookie.Zedo : Cleaned.
I:\QooBox\Quarantine\I\WINDOWS\system32\wintfj32.dll.vir -> Trojan.Agent.qt : Cleaned.
I:\WINDOWS\system32\dgxryaaa.exe -> Trojan.Delf.ndm : Cleaned.


::Report end











Logfile of HijackThis v1.99.1
Scan saved at 17:44:24, on 5/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\WINDOWS\system32\ctfmon.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\hijackthis\abc.bat

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - I:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: I:\WINDOWS\system32\systl.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 16 May 2007 - 12:57 PM

Copy and paste the following bold blue text in the Quote box below into Notepad.
Click on File(in the menu at the top)>Save as..Save as Type: 'All Files' File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktop and agree to merge it into the registry,then reboot.

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=-


Restart your pc,post a new Hijackthis log in your next reply.
Posted Image
Posted Image

#11 Bozotclown

Bozotclown
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 16 May 2007 - 03:17 PM

thanks.


Logfile of HijackThis v1.99.1
Scan saved at 21:13:13, on 5/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
I:\WINDOWS\System32\smss.exe
I:\WINDOWS\system32\winlogon.exe
I:\WINDOWS\system32\services.exe
I:\WINDOWS\system32\lsass.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\Windows Defender\MsMpEng.exe
I:\WINDOWS\System32\svchost.exe
I:\WINDOWS\system32\ZoneLabs\vsmon.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
I:\Program Files\Alwil Software\Avast4\ashServ.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\CTsvcCDA.EXE
I:\WINDOWS\eHome\ehRecvr.exe
I:\WINDOWS\eHome\ehSched.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
I:\WINDOWS\system32\svchost.exe
I:\Program Files\HHVcdV5Sys\VC5SecS.exe
I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
I:\Program Files\Alwil Software\Avast4\ashWebSv.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\Explorer.EXE
I:\WINDOWS\ehome\ehtray.exe
I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
I:\WINDOWS\CTHELPER.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
I:\WINDOWS\system32\dla\tfswctrl.exe
I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
I:\WINDOWS\stsystra.exe
I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
I:\Program Files\Common Files\Real\Update_OB\realsched.exe
I:\WINDOWS\system32\ctfmon.exe
I:\Program Files\Windows Defender\MSASCui.exe
I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
I:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe
I:\WINDOWS\system32\notepad.exe
I:\hijackthis\abc.bat

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - I:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - I:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - I:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - I:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - I:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_5_0.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - I:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] I:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] I:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
O4 - HKLM\..\Run: [AudioDrvEmulator] "I:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "I:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Motive SmartBridge] I:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [ccApp] "I:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] I:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "I:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTDVDDET] "I:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "I:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] I:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] I:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] I:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "I:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "I:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Zone Labs Client] "I:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] I:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "I:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "I:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] i:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [DAEMON Tools] "I:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Global Startup: Adobe Reader Speed Launch.lnk = I:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = I:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O8 - Extra context menu item: &Windows Live Search - res://I:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download &Flash Movies - I:\Program Files\Flash2X\Flash Hunter\save.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://I:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - I:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1165236715937
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1153937668828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - I:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - I:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - I:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - I:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - I:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PnkBstrA - Unknown owner - I:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - I:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVScan - Symantec Corporation - I:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - I:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - I:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v5 Security service (VC5SecS) - H+H Software GmbH - I:\Program Files\HHVcdV5Sys\VC5SecS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - I:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - I:\WINDOWS\system32\YPCSER~1.EXE

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:52 AM

Posted 16 May 2007 - 03:46 PM

Your log is clean :thumbsup:
If all's ok,please do the following:

Find and delete:
I:\NoLopBackups
I:\!KillBox
I:\Vundofix Backups
I:\Avenger
SmitFraudFix
NoLop.exe
fix.reg


Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users